Mozilla site exposed encrypted passwords
- 29 December, 2010 11:12
- Comments
A database of inactive Mozilla usernames and passwords was exposed on the Internet earlier this month, the Mozilla Foundation disclosed on Tuesday.
The database, which contained 44,000 inactive user accounts for the addons.mozilla.org site, was inadvertently placed on a public-facing Web server, wrote Chris Lyon, the Mozilla director of infrastructure security, in a blog posting.
Lyon stressed that the exposure "posed minimal risk to users." The organization erased all the passwords, which were encrypted. It also accounted for every download of the database.
Current users of addons.mozilla.org are not affected, because the organization upgraded its procedure for encrypting passwords in April 2009, Lyon stated.
Mozilla security officials were first notified of the exposure on December 17, through the organization's web bounty program, which allows volunteers to submit security-related bugs.
The Foundation notified all the account holders by e-mail on December 27 of the exposure.
- Bookmark this page
- Share this article
- Got more on this story? Email TechWorld
- Follow TechWorld on twitter
-
Philip's 'smart' lightbulbs hit Australia
-
Philip's 'smart' lightbulbs hit Australia
-
Bitcoin finding its feet at first Silicon Valley conference
-
Australia lags Mongolia in Internet speeds
-
Salesforce.com to buy Clipboard, shutting down service












Recent comments
19 hours, 51 minutes ago
22 hours, 27 minutes ago
1 day, 12 hours ago
5 days, 21 hours ago
1 week ago
1 week ago
1 week, 3 days ago
1 week, 4 days ago
1 week, 4 days ago
1 week, 4 days ago