First Gawker, then Twitter … who’s next? A hack that compromised the commenting system on Gawker during the weekend and then drove a Twitter spam attack could create a ripple effect across the Internet.
Gawker’s commenter database houses about 1.5 million usernames, e-mail addresses, and passwords. And those 1.5 million virtual identities are likely similar on sites across the web.
“That’s like the Armageddon scenario that everyone who lives in a virtual online world fears the most but feels they are powerless to steer clear of,” said Brad Shimmin, an analyst at Current Analysis. “If you ask 10 people how many passwords they maintain, I would guess eight of them would say one or two. The rest of them would be the nerds that have their software generate unbreakable passwords.”
All Your Eggs in One Basket?
It all started over the weekend. In a published statement, Gawker said the passwords in its database were encrypted — but “simple ones may be vulnerable to a brute-force attack.” Gawker advised its users to change their password on both Gawker and on any other sites where they use the same passwords.
The advice may have come too late for some — or perhaps it wasn’t heeded. By Monday morning, the hack spread to Twitter. Twitter initially thought a worm was running rampant through its site, sending tweets that talked about “acai berry.” But Twitter said on its @security feed that the spam was actually traced back to the Gawker incident. It seems some Gawker users and Twitter users have the same passwords.
“If you ask any security expert, they will tell you the same thing, but it is an unfortunate circumstance of human nature that we all strive for simplicity, and that simplicity creates these all the eggs-in-one-basket scenarios,” Shimmin said.
“The lesson is just how interconnected these different services…