PSA: Don't Forget To Change Your Jalopnik Password


We know there’s more than a little overlap between TTAC and Jalopnik, the Gawker Media empire’s car blog, so we’d like to remind our readers who do have a commenting account at Jalopnik to change their password (since Gawker was apparently too “in shock” to warn users earlier). Gawker Media was attacked by a group of hackers known as Gnosis, and at least 200,000 Gawker user accounts have been hacked, exposing commenters’ login information and allowing some Twitter accounts to be taken over and used to send spam messages. The attack on Gawker was reportedly a response to the blog pioneer’s “outright arrogance,” and some have speculated that it was related to Gawkers antagonism of the famed hacker hangout 4chan; we reckon that Lotus was somehow behind it. To find out if your account has been compromised, surf over to Gawkercheck.com, or simply change your password at Jalopnik or any other Gawker Media site. Or, you could just delete your account and become a regular here at TTAC instead. Just saying…
Comments
Join the conversation
Since, in light of this incident, I'm not going to be commenting (or visiting) over there again, I'm going to go ahead and express my disgust here. This whole incident was mishandled from the beginning, and it's very clear that the people running Gawker really don't give a shit about their users. From their classifying us as "unimportant (...) peasants" ( http://static01.mediaite.com/med/wp-content/uploads/2010/12/GawkerBIG.png ) to the fact that the hackers apparently had access to the servers for at least a month before they determined what was going on, to the length of time it took them to let us "unimportant peasants" know about the data breach, everything about this situation indicates that they don't value their source of revenue at all. They were using DES encryption for their users' passwords, a standard that's going on 40 years old and which was cracked in freaking 1998. Especially now that the hackers have made all of the data they obtained publicly available, it's not a matter of if your Jalopnik password will be cracked, it's a matter of when. With the processing power available in modern computers, an individual's e-mail and associated password can be decrypted in a matter of hours-if not minutes or seconds. And, as if that weren't enough, these idiots apparently didn't even store any input beyond the 8th character; i.e. your password on Jalopnik could have been "supercalifragilisticexpialidocious", but all you would have had to type to log in is "supercal" because the remaining 26 characters were just discarded. Furthermore, their servers were on Linux kernels that were years out of date. You can argue back and forth about Linux vs. Windows security in a server environment all day long if you really want to, but Linux has security holes of its own (as evidenced by this attack) and running kernel versions that far out of date on anything interacting with the internet can only be considered moronic. I mean I thought that I was a lazy sysadmin because I forget my weekly backups sometimes but judging by this event the Gawker IT department evidently spends all of their time at work eating cheetohs and watching porn. There's no excuse for security this lax on a major website. And in spite of having outdated, halfassed security systems these idiots went out and antagonized 4chan and the hacking community in general. Essentially they were playing Russian roulette with their users' data-and their own, apparently-with a semiautomatic. Gawker can go to hell. Additional reading for those that care: http://blogs.forbes.com/firewall/2010/12/13/the-lessons-of-gawkers-security-mess/
Ed, we appreciate your help in spreading the word to all nine of our site’s 22,503 commenters who came over from your post to change their passwords.
TTAC's server says that yesterday, gawkercheck.com was the most clicked outgoing link on TTAC. Today, it trails in the #2 position behind pontiacsonline.com. And that's only because someone is ruining all the fun at Curbside Classic Clues.
Settle down, guys....I remember when these two sites were more complementary of each other (that's complementary with an "e" and maybe sometimes with an "i"). Jalopnik has gotten more off-beat, while TTAC has gotten VERY businessy. That divergence has been good, IMHO, and that's why they're the only two general auto sites I visit (well, at least until work blacklisted Jalopnik a few days ago. I guess I was spending too much time there...lol)