<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Delivering Unhappiness</title>
	<atom:link href="http://www.veracode.com/blog/2012/01/delivering-unhappiness/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.veracode.com/blog/2012/01/delivering-unhappiness/</link>
	<description>Application security testing, analysis, and metrics</description>
	<lastBuildDate>Tue, 15 May 2012 22:16:53 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: På den säkra sidan &#8211; Utgåva 06 &#124; SAFESIDE-bloggen</title>
		<link>http://www.veracode.com/blog/2012/01/delivering-unhappiness/comment-page-1/#comment-14626</link>
		<dc:creator>På den säkra sidan &#8211; Utgåva 06 &#124; SAFESIDE-bloggen</dc:creator>
		<pubDate>Thu, 19 Jan 2012 23:26:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=3119#comment-14626</guid>
		<description>[...] hos Zappos (CS) http://www.veracode.com/blog/2012/01/delivering-unhappiness/ http://isc.sans.edu/diary.html?storyid=12406 [...]</description>
		<content:encoded><![CDATA[<p>[...] hos Zappos (CS) <a href="http://www.veracode.com/blog/2012/01/delivering-unhappiness/" rel="nofollow">http://www.veracode.com/blog/2012/01/delivering-unhappiness/</a> <a href="http://isc.sans.edu/diary.html?storyid=12406" rel="nofollow">http://isc.sans.edu/diary.html?storyid=12406</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Security&#8217;s Rough Ride &#171; psilva&#039;s blog</title>
		<link>http://www.veracode.com/blog/2012/01/delivering-unhappiness/comment-page-1/#comment-14596</link>
		<dc:creator>Security&#8217;s Rough Ride &#171; psilva&#039;s blog</dc:creator>
		<pubDate>Tue, 17 Jan 2012 22:10:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=3119#comment-14596</guid>
		<description>[...] Delivering Unhappiness [...]</description>
		<content:encoded><![CDATA[<p>[...] Delivering Unhappiness [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Eng</title>
		<link>http://www.veracode.com/blog/2012/01/delivering-unhappiness/comment-page-1/#comment-14587</link>
		<dc:creator>Chris Eng</dc:creator>
		<pubDate>Tue, 17 Jan 2012 15:35:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=3119#comment-14587</guid>
		<description>@Dan: For the record, my guess is unsalted hash too. :)</description>
		<content:encoded><![CDATA[<p>@Dan: For the record, my guess is unsalted hash too. :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan</title>
		<link>http://www.veracode.com/blog/2012/01/delivering-unhappiness/comment-page-1/#comment-14580</link>
		<dc:creator>Dan</dc:creator>
		<pubDate>Tue, 17 Jan 2012 03:43:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=3119#comment-14580</guid>
		<description>You&#039;re not really informed, even if they said salted hashes, you should still take their advice and change your passwords, immediately, everywhere (that you care about).


It was urgent enough to the people on the inside of Zappos for them to make the business call to inconvenience all of their customers.  I imagine that, as a matter of good corporate governance, they didn&#039;t take this step lightly.


Would you do the same actions that they are doing if you knew that the passwords were managed properly?  Maybe it&#039;s just me, but I would totally minimize my press releases if I knew I had nice secure bcrypted passwords.  i.e., &quot;You might want to change your passwords sometime in the next year or so if you think a major government might want access to your accounts... Otherwise, check out these cool new shoes...&quot;  ;)

My guess is either crypt or md5/no salt.</description>
		<content:encoded><![CDATA[<p>You&#8217;re not really informed, even if they said salted hashes, you should still take their advice and change your passwords, immediately, everywhere (that you care about).</p>
<p>It was urgent enough to the people on the inside of Zappos for them to make the business call to inconvenience all of their customers.  I imagine that, as a matter of good corporate governance, they didn&#8217;t take this step lightly.</p>
<p>Would you do the same actions that they are doing if you knew that the passwords were managed properly?  Maybe it&#8217;s just me, but I would totally minimize my press releases if I knew I had nice secure bcrypted passwords.  i.e., &#8220;You might want to change your passwords sometime in the next year or so if you think a major government might want access to your accounts&#8230; Otherwise, check out these cool new shoes&#8230;&#8221;  ;)</p>
<p>My guess is either crypt or md5/no salt.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Eng</title>
		<link>http://www.veracode.com/blog/2012/01/delivering-unhappiness/comment-page-1/#comment-14577</link>
		<dc:creator>Chris Eng</dc:creator>
		<pubDate>Tue, 17 Jan 2012 01:34:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=3119#comment-14577</guid>
		<description>@Dan: Valid point regarding &quot;how much they really cared&quot; pre-loss. But still, people should know how urgent the situation is. Call it amateur risk assessment if you want, but to me it&#039;s making informed decisions.  Do people need to change their passwords immediately on every site where they&#039;ve used that email/password pair?  Probably not.  How long do they have?  Depends on the answer to my question.</description>
		<content:encoded><![CDATA[<p>@Dan: Valid point regarding &#8220;how much they really cared&#8221; pre-loss. But still, people should know how urgent the situation is. Call it amateur risk assessment if you want, but to me it&#8217;s making informed decisions.  Do people need to change their passwords immediately on every site where they&#8217;ve used that email/password pair?  Probably not.  How long do they have?  Depends on the answer to my question.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan</title>
		<link>http://www.veracode.com/blog/2012/01/delivering-unhappiness/comment-page-1/#comment-14576</link>
		<dc:creator>Dan</dc:creator>
		<pubDate>Tue, 17 Jan 2012 00:17:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=3119#comment-14576</guid>
		<description>&quot;This detail is critical, because it indicates how easy it will be for attackers to recover the original passwords&quot;

This detail is critical because it gives us a gauge into how much Zappos really cared - pre-loss.

But to paraphrase Ranum...  (http://www.inforisktoday.co.uk/interviews.php?interviewID=1154)

If a company tells you that they&#039;ve been hacked and that you should change your password, you should change your password.

Any amateur risk assessment at this point is foolhardy.</description>
		<content:encoded><![CDATA[<p>&#8220;This detail is critical, because it indicates how easy it will be for attackers to recover the original passwords&#8221;</p>
<p>This detail is critical because it gives us a gauge into how much Zappos really cared &#8211; pre-loss.</p>
<p>But to paraphrase Ranum&#8230;  (<a href="http://www.inforisktoday.co.uk/interviews.php?interviewID=1154" rel="nofollow">http://www.inforisktoday.co.uk/interviews.php?interviewID=1154</a>)</p>
<p>If a company tells you that they&#8217;ve been hacked and that you should change your password, you should change your password.</p>
<p>Any amateur risk assessment at this point is foolhardy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James Dorrian</title>
		<link>http://www.veracode.com/blog/2012/01/delivering-unhappiness/comment-page-1/#comment-14574</link>
		<dc:creator>James Dorrian</dc:creator>
		<pubDate>Mon, 16 Jan 2012 21:43:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=3119#comment-14574</guid>
		<description>Perhaps a premature assessment on my part, but it seems their action is bold and decisive, which is exactly what is necessary in the event of a breach.</description>
		<content:encoded><![CDATA[<p>Perhaps a premature assessment on my part, but it seems their action is bold and decisive, which is exactly what is necessary in the event of a breach.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

