×
  • remind me tomorrow
  • remind me next week
  • never remind me
Subscribe to the ANN Newsletter • Wake up every Sunday to a curated list of ANN's most interesting posts of the week. read more

Forum - View topic
NEWS: Report: 2.5 Million Funimation Accounts Compromised in Data Breach


Goto page Previous  1, 2, 3, 4

Note: this is the discussion thread for this article

Anime News Network Forum Index -> Site-related -> Talkback
View previous topic :: View next topic  
Author Message
Blanchimont



Joined: 25 Feb 2012
Posts: 3446
Location: Finland
PostPosted: Thu Feb 23, 2017 1:51 pm Reply with quote
myamine wrote:
Damn, I should have tipped off AAN about this way back when I found out about it. It was back in August when I found out the database was freshly dumped. If I remember correctly, the database contained emails, passwords(to some accounts), ip address, last login, usernames, and birthdays. Not sure exactly as I didn't see the raw dump. I just used Leaked Source and found my free account there.

I did email them, however, they just told me they were "looking into it".

So they DID know about it. But didn't disclose the breach to users. Only asked one month back to change passwords(according to comments in this thread). How many facepalms can you count?...

Luckily I don't have a Funi account, due to being in the wrong region. This reminds me it's high time to change my CR password once again, just in case...
Back to top
View user's profile Send private message
Shiroi Hane
Encyclopedia Editor


Joined: 25 Oct 2003
Posts: 7580
Location: Wales
PostPosted: Thu Feb 23, 2017 2:37 pm Reply with quote
I can confirm it does not affect the UK service (which initially had a completely separate userbase) since I registered there with a different email address to the two I have registered on the US site (both of which were affected).

Could be worse; when MVM's store was hacked I had fraudulent payments on two different cards (and they've never acknowledged the breach). I've been using Paypal exclusively there since.
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number My Anime My Manga
myamine



Joined: 13 Apr 2011
Posts: 6
PostPosted: Thu Feb 23, 2017 6:24 pm Reply with quote
Blanchimont wrote:
myamine wrote:
Damn, I should have tipped off AAN about this way back when I found out about it. It was back in August when I found out the database was freshly dumped. If I remember correctly, the database contained emails, passwords(to some accounts), ip address, last login, usernames, and birthdays. Not sure exactly as I didn't see the raw dump. I just used Leaked Source and found my free account there.

I did email them, however, they just told me they were "looking into it".

So they DID know about it. But didn't disclose the breach to users. Only asked one month back to change passwords(according to comments in this thread). How many facepalms can you count?...

Luckily I don't have a Funi account, due to being in the wrong region. This reminds me it's high time to change my CR password once again, just in case...


I dont know if they knew before my email, but once they got my email they should have at least force reset everyones password but till this day, I've never gotten an email telling me about the breach or pw reset.
Back to top
View user's profile Send private message
ペンネーム



Joined: 19 Nov 2014
Posts: 8
PostPosted: Thu Feb 23, 2017 7:14 pm Reply with quote
Things just got worse:

https://bugs.chromium.org/p/project-zero/issues/detail?id=1139

Sites using cloudflare, like Anime News Network, Crunchyroll and millions more, have been "bleeding" PII including usernames and passwords.

Congratulations! Your passwords and usernames are not safe here because they used a terrible product to try to protect from DDoS instead of investing in good technology and superior solutions.
Back to top
View user's profile Send private message
Suena



Joined: 27 May 2012
Posts: 289
PostPosted: Thu Feb 23, 2017 8:02 pm Reply with quote
This is why I give out a fake birthdate to most websites. All they really need is to know that I'm over 18 anyway. I also only ever used my Paypal account to purchase from them, which I have to log in to independently, so there's little risk of them swiping my payment info.

I was prompted to change my Funi password the last time I logged in (a month or so ago). I hadn't logged into the site in several months at the time.
Back to top
View user's profile Send private message
leafy sea dragon



Joined: 27 Oct 2009
Posts: 7163
Location: Another Kingdom
PostPosted: Thu Feb 23, 2017 11:30 pm Reply with quote
^__^v wrote:
Perhaps keep track of only the sites (or usernames if nothing else) one is registered, and request (or manually change) a new password every time to login in? The suggestion is not full proof, but I guess it is better than nothing. Personally I'm not a fan of password keepers/managers.


Heh, my aunt does that, but for an entirely different reason than security: She hasn't quite grasped the concept of digital passwords, so she uses the "Forgot password?" link every time she wants to log in to something, then uses the new password given out on the e-mail.

nagpo wrote:
Honestly if you're still using streaming services you deserve this


Besides the fact that no one deserves to have their data compromised, is there something even better than streaming that has since come out that we alldon't know about?
Back to top
View user's profile Send private message
yuna49



Joined: 27 Aug 2008
Posts: 3804
PostPosted: Fri Feb 24, 2017 8:51 am Reply with quote
myamine wrote:
If I remember correctly, the database contained emails, passwords(to some accounts), ip address, last login, usernames, and birthdays.

Were the passwords in plain-text, or were they encrypted?
Back to top
View user's profile Send private message
yuna49



Joined: 27 Aug 2008
Posts: 3804
PostPosted: Fri Feb 24, 2017 9:07 am Reply with quote
ペンネーム wrote:
Sites using cloudflare, like Anime News Network, Crunchyroll and millions more, have been "bleeding" PII including usernames and passwords.

Let's calm down a bit first, okay? A particular set of circumstances had to exist for the exposure to occur.

Quote:
The greatest period of impact was from February 13 and February 18 with around 1 in every 3,300,000 HTTP requests through Cloudflare potentially resulting in memory leakage (that’s about 0.00003% of requests).

In order for the memory to leak the following had to be true:

The final buffer containing data had to finish with a malformed script or img tag
The buffer had to be less than 4k in length (otherwise NGINX would crash)
The customer had to either have Email Obfuscation enabled (because it uses both the old and new parsers as we transition),
… or Automatic HTTPS Rewrites/Server Side Excludes (which use the new parser) in combination with another Cloudflare feature that uses the old parser. … and Server-Side Excludes only execute if the client IP has a poor reputation (i.e. it does not work for most visitors).

That explains why the buffer overrun resulting in a leak of memory occurred so infrequently.


https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug/

So whether the use of Cloudflare by ANN or Crunchyroll leaked information is completely unknown, but pretty unlikely.

Funimation's behavior, on the other hand, is entirely despicable and could be, as Mark Gosdin suggests, in violation of some states' laws on consumer privacy. I use unique email addresses at every site I have an account on (one of the benefits of owning a domain) and haven't seen any fallout from this breach yet.
Back to top
View user's profile Send private message
maxwell3094



Joined: 28 Mar 2014
Posts: 148
PostPosted: Fri Feb 24, 2017 9:33 am Reply with quote
Its unlikely but the Cloudflare bug has been happening for a few months now and a lot of sites use it so its possible some people had their info for ANN leaked. Best to update your password here (and on any other site you use that uses Cloudflare) just to be on the safe side in the off chance that your password got leaked.

Though its worth noting that the earliest the Cloudflare bug started was in September and the article says Funi's breach happened last July so it was apparently totally unrelated and doesn't change that Funi are still total scum bags for not warning their users.
Back to top
View user's profile Send private message
Kadmos1



Joined: 08 May 2014
Posts: 13552
Location: In Phoenix but has an 85308 ZIP
PostPosted: Sat Feb 25, 2017 6:44 am Reply with quote
Their old motto of "You should be watching" is somewhat ironic now.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Anime News Network Forum Index -> Site-related -> Talkback All times are GMT - 5 Hours
Goto page Previous  1, 2, 3, 4
Page 4 of 4

 


Powered by phpBB © 2001, 2005 phpBB Group