Notices
The Basement Non-Honda/Acura discussion. Content should be tasteful and "primetime" safe.

PSA: Change Your Amazon Password

Thread Tools
 
Old 01-31-2011, 02:40 PM
  #1  
94civicEX
I got worms.
Thread Starter
 
94civicEX's Avatar
 
Join Date: Jul 2000
Location: Utah
Posts: 32,238
Likes: 0
Received 0 Likes on 0 Posts
Default PSA: Change Your Amazon Password

http://www.wired.com/threatlevel/201...sword-problem/

An Amazon.com security flaw allows some customers to log in with variations of their actual password that are close to, but not exactly, their real password.

The flaw lets Amazon accept as valid some passwords that have extra characters added on after the 8th character, and also makes the password case-insensitive.
For example, if your password is “Password,” Amazon.com will also let you log in with “PASSWORD,” “password,” “passwordpassword,” and “password12345.”
Wired has been able to confirm the flaw, which was first reported on Reddit. It appears to affect only older Amazon.com accounts, which have not had their passwords changed in the past several years.

Amazon did not respond to a request for comment.

Observers on Reddit speculate that Amazon was using the unix crypt() function to encrypt older passwords, in addition to converting them to uppercase, before storing them in its servers. While encrypting stored passwords is a wise idea, crypt() truncates longer passwords, discarding anything after the 8th character. (It’s also relatively easy to crack, as Gawker Media recently found out when its crypt()-encrypted database of user passwords was published by hackers.)1
Since newer passwords are not affected by the flaw, Amazon appears to have corrected the problem for new passwords — but without updating the older, stored passwords.

The fix is straightforward for those with older passwords: Simply log on to Amazon.com, and change your password. You can even then change your new password back to your old password, and you’ll magically be safer than you were before.
__________________
99 Integra GSR
06 TSX

duck squad member #00003
Old 01-31-2011, 02:48 PM
  #2  
b00gers
 
b00gers's Avatar
 
Join Date: Jun 2001
Location: oakland, ca
Posts: 58,578
Likes: 0
Received 0 Likes on 0 Posts
Default

I noticed this for Myspace a couple years ago :reechy:

My Amazon Prime account isnt affected...but my regular one is.

Thanks.
__________________
.
Old 01-31-2011, 03:54 PM
  #3  
jconeab
got the nuts
 
jconeab's Avatar
 
Join Date: May 2006
Location: emerald city
Posts: 4,939
Likes: 0
Received 0 Likes on 0 Posts
Default

Good find, I don't really use Amazon too much but good to know.
Old 01-31-2011, 05:09 PM
  #4  
dj02
click click
 
dj02's Avatar
 
Join Date: Jul 2005
Location: cali
Posts: 23,651
Likes: 0
Received 0 Likes on 0 Posts
Default

done and done, ive been using my amazon quite a bit lately damm one click on my phone :0
Old 01-31-2011, 05:15 PM
  #5  
LABARINTH
Better Than Canada!
 
LABARINTH's Avatar
 
Join Date: Dec 2002
Location: Baltimore, MD
Posts: 10,821
Likes: 0
Received 0 Likes on 0 Posts
Default

I always type my password twice for good measure.
Old 01-31-2011, 05:50 PM
  #6  
LT
The deer had to die!
 
LT's Avatar
 
Join Date: Jun 2002
Location: Fussa, Japan
Posts: 39,835
Likes: 0
Received 0 Likes on 0 Posts
Default

Mine is 9 characters long utilizing both lower and upper-case letters, numbers, and symbols. Quite hard to break.
Old 02-01-2011, 05:37 AM
  #7  
spanky
I go duffy on dem bitches
 
spanky's Avatar
 
Join Date: Mar 2001
Location: Gonzales, Louisiana
Posts: 28,247
Likes: 0
Received 0 Likes on 0 Posts
Default

I just tried and mine doesn't seem to be affected by this but I needed to change it anyway since it's an old one.
Old 02-01-2011, 05:54 AM
  #8  
Draconius
BAZINGA!
 
Draconius's Avatar
 
Join Date: Aug 2004
Location: San Diego, CA
Posts: 21,613
Likes: 0
Received 0 Likes on 0 Posts
Default

doubled mine and signed me in. Changing now




All times are GMT -8. The time now is 02:44 PM.