On TV.com: PSYCH Is Canceled ? Sike!
BNET Business Network:
BNET
TechRepublic
ZDNet

March 17th, 2009

Comcast responds to passwords leak on Scribd

Posted by Dancho Danchev @ 12:28 pm

Categories: Botnets, Browsers, Data theft, Hackers, Malware, Passwords, Phishing, Spam and Phishing

Tags: Security, Comcast, CMCSA, Scribd, Passwords Management, Dancho Danchev

Comcast has responded to the recently found list of passwords hosted at the popular social publishing site Scribd. Originally claimed to be a list consisting of 8000 passwords for Comcast customers, the company now states that not only are 4000 of the passwords duplicates, but also, that only 700 of them belong to active Comcast customers.

Perhaps the result of a phishing campaign that apparently took place a long time ago, this incident highlights several important issues. For instance, the professor at Wilkes University that originally came across the list — copies of it are still available online — is disturbed by the fact that he’s using this very same leaked password everywhere else - “That isn’t just my password for Comcast, it’s my password for everything that is not tied to my credit card,”. Bad password management practices are clearly in place, but how relevant are these best practices in a situation where the host is already compromised by malicious software? A rhetorical question.

In a recently released Gartner document entitled “Consumers Don’t Want to Change the Ways They Manage Online Passwords” the analysts try to raise awareness on the fact that users continue using the same (weak) passwords across different web sites. And whereas the document is reasonably emphasizing on the well known insecure practice, it excludes a simple truth - that a password’s strength and diversity of different passwords across web sites, becomes irrelevant practice once a host gets compromised.

Comcast is in a process of notifying the affected customers. Looks like phishing as usual, with an odd choice for hosting the collected data on behalf of the campaigners.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 2 Talkback(s)
RE: Comcast responds to passwords leak on Scribd
"That isn?t just my password for Comcast, it?s my password for everything"

The only thing worse than using the same password for everything is publicly revealing that you do. ... (Read the rest)
Posted by: rkillings Posted on: 03/18/09 You are currently: a Guest | | Terms of Use
Comcast throttles so passwords are useless  BALTHOR | 03/17/09
RE: Comcast responds to passwords leak on Scribd  rkillings | 03/18/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads