I can imagine this is just an unbelievably annoying and frustrating thing for you and FXpansion. Thanks for keeping us updated.
I'm also assuming that you store our passwords in salted hashes and not as plaintext. You do do that don't you?
------------------------------
Even if hackers have our username and password table, we're covered, right? All they'll see is the hash values. Only the most grossly incompetent of developers would actually store passwords as plaintext in the database, right? Right?
-------------------------------
http://www.codinghorror.com/blog/2007/0 ... ectly.html
------------------------------
Hashing the passwords prevents plaintext exposure, but it also means you'll be vulnerable to the astonishingly effective rainbow table attack I documented last week. Hashes alone are better than plain text, but barely. It's not enough to thwart a determined attacker.
-------------------------------
This site has two zip files of the 10,000 most used passwords with one by frequency. This information is freely available. Crackers use lists built up by security breaches such as these (not implicating you here) to create lists with millions. In fact any hacker worth his salt will be using lists of millions, so these files are just for purposes of demonstration.
http://xato.net/passwords/more-top-worst-passwords/
4.7% of users have the password password;
8.5% have the passwords password or 123456;
9.8% have the passwords password, 123456 or 12345678;
14% have a password from the top 10 passwords
40% have a password from the top 100 passwords
79% have a password from the top 500 passwords
91% have a password from the top 1000 passwords
From Coding Horror again:
------------------------
You might think it's relatively unimportant if someone's forum password is exposed as plain text. After all, what's an attacker going to do with crappy forum credentials? Post angry messages on the user's behalf? But most users tend to re-use the same passwords, probably because they can't remember the two dozen unique usernames and passwords they're forced to have. So if you obtain their forum password, it's likely you also have the password to something a lot more dangerous: their online banking and PayPal.
-------------------------------------
I pretty much guarantee that most people who have received this spam are using a password from that list of the top 10,000. Download it and see. And of those people that are, a certain proportion of them will use the same password for paypal and online banking. So if your database was breached and you didn't store our passwords as hashes that were salted, and if people use the same password for their paypal as well as their FXpansion account, we are looking at a POTENTIALLY extremely serious situation.
Of course, no one will see any money disappear out of their accounts any time soon. You won't even get any more spam for a little while. Give it a few weeks and then it will come trickling in. There is no doubt about that - our email addresses are on a big list that is going to be sold. Remember, we are gold. We buy when we so easily could steal. And then we buy again. You wouldn't steal a handbag
Then after a little while again, those that got caught using the same password for their paypal etc. as their FXpansion account and didn't change it/know about this issue (old no longer used email address), will start to find money stolen from their account. POTENTIALLY. Let's not scaremonger here, and also let's now play down a POTENTIALLY very serious issue.
Now I'm not saying it was your database that was breached. And I'm sure you do salt our hashed passwords (you do don't you?), so really there is nothing to worry about apart from identity theft, with not just our real names and addresses but our telephone no.s etc... POSSIBLY.
So it would be really good to know if it was your database that was hacked and what information they got. Did they get our home address, telephone no. if so?
Did they get our passwords because you stored them as plain text? There have been quite a few examples of companies you would expect as not to be so stupid as to do this, as they exist in the security realm for one and have hundreds of thousands of customers for another. But no, they were that naive and their hundreds of thousands of user's passwords have now been added to the cracker's brute force or dictionary list.
Anyway, this is probably all just a storm in a teacup and no need to worry. Until we find out the full scale of the attack - who orchestrated it and whose database was hacked into and what information did they get.
Thanks for keeping us updated SKoT. It's good that you keep us informed and take our very real security worries seriously.
cheers.