Sci-tech

Flipboard reveals data breach, which left users' details exposed

Flipboard reveals data breach, which left users' details exposed”

In its email, Flipboard said it is now resetting all customer passwords, regardless if users were impacted or not, out of an abundance of caution.

It is not known if these were the same users accessing the databases at different periods or two separate data breaches.

News aggregator Flipboard is the latest to succumb to a data breach, with the service noting that hackers gained unauthorized access to its databases containing users' account information. Findings from the investigation indicate an unauthorized person accessed and potentially obtained copies of certain databases containing Flipboard user information between June 2, 2018 and March 23, 2019 and April 21 - 22, 2019. Hackers were able to access databases containing usernames and passwords, as well as access tokens for some third-party services.

This allowed the hackers to view and potentially download user information such as user names, hashed and salted passwords, and for some users, their email addresses and digital tokens used to login to Flipboard using site credentials from Google, Facebook, and Twitter. For the users who haven't changed their password since March 14, 2012, the company protected their passwords using SHA-1 encryption.

The news aggregation app announced in a post that it had identified unauthorized access of some of its internal systems, which contained some Flipboard users' account information and credentials.

Additionally, Flipboard mentioned that it informed law enforcement about the unauthorised access and involved an external security firm to investigate the flaw.

The company also said its internal database contained digital tokens.

As a precaution, we have reset all users' passwords, even though the passwords were cryptographically protected and not all users' account information was involved. Those tokens are no longer valid and therefore can not be misused. The social news app also disconnected tokens used to connect to third-party accounts, replacing or deleting them as applicable. While the company says it didn't find evidence the tokens were used to break into the accounts users connected with their Flipboard profiles, it replaced and deleted all those tokens nonetheless.

Not all users' accounts were affected, Flipboard said, but it wasn't immediately clear how many were.

"We're still in the process of determining the total number", the company said.

Flipboard also says it implemented "enhanced security measures" to prevent a further breach in the future. "We do know that not all accounts were compromised".



Like this

loading...
loading...

Latest


30 May 2019
Disaster aid bill again blocked by 1 voter
Democrats held firm in demanding that Puerto Rico, a territory whose 3 million people are USA citizens, be helped by the measure. The bill now contains more money for Puerto Rico, about $1.4 billion, than Democrats originally sought.

30 May 2019
Group that raised money for border wall online wrapping up first project
He said municipal officials were not allowed access to the work site after learning the private wall would be built. Sunland Park City Manager Julia Brown told CNN the city's "cease and desist" order has nothing to do with politics.

30 May 2019
How Jenelle Evans' Marriage Is Impacting Her Custody Battle
All three of Jenelle Evans' kids have been removed from her custody amid her turbulent marriage to David Eason . A rep for Evans says that she is cooperating with the judge, and she is focused on getting her children back.

29 May 2019
Weather Service Confirms Seven Tornadoes Hit Indiana On Monday
The NWS in Pittsburgh confirmed an EF0 tornado touched down in the Penn Run area of Indiana County Tuesday afternoon. The Storm Prediction Center from NOAA's National Weather Service has been keeping a tally on the activity.

29 May 2019
Study finds world's rivers loaded with antibiotics waste
The study revealed that high-risk sites were typically adjacent to wastewater treatment systems and waste or sewage dumps. The two-day annual meeting of the Society of Environmental Toxicology and Chemistry ends on Tuesday.

29 May 2019
Alibaba may raise as much as $27.5 billion in Hong Kong listing
The second listing is aimed at boosting its liquidity and diversifying its funding channel, according to one of the sources. That made American companies to obtain approval from the government for doing business with that Chinese company.

29 May 2019
Special counsel Robert Mueller to deliver unexpected statement on Russian Federation investigation
But it underlines the disgraceful picture of Trump that can be found in the special counsel's voluminous report . He finished his report last month, and a heavily redacted version was released to the public.

29 May 2019
Roger Federer overpowers Oscar Otte in straight sets — ATP Roland Garros
Nadal eliminated German Yannick Hanfmann in straight sets on Monday in his first round matchup at the Grand Slam. The 67th-ranked Ukrainian player was set play ninth-seeded Elina Svitolina in the second round.

29 May 2019
Meghan Markle Won’t Meet With Trump During Upcoming State Visit
The former Suits star previously made her views of Trump known by calling him "divisive" in a 2016 interview. The Duchess gave birth to Archie Harrison Mountbatten-Windsor on May 6.

29 May 2019
Kushner meets Moroccan king on trip to press US peace plan
US Middle East envoy Jason Greenblatt has said Washington's peace plan has the "potential to unlock a prosperous future for the Palestinians".