4/10/13
Adobe has just disclosed that one of their servers has been hacked.
While their investigations are still ongoing, Adobe has shared a few details on what they believe could have been accessed and obtained in the hack ââ'¬â€ and itââ'¬â"¢s a big one.
It seems that the hackers got access to encrypted data for as many as 2.9 million customers. While Adobe stresses that the data is encrypted and that they ââ'¬Å"do not believe the attackers removed decrypted credit or debit card numbersââ'¬Â, that data ââ'¬â€ encrypted or not ââ'¬â€ is definitely not something they want out in the wild.
Adobe has yet to disclose how that data was encrypted, so itââ'¬â"¢s currently unclear just how secure it is.
Meanwhile, it also appears that the hackers may have been able to access the source code for at least three of Adobeââ'¬â"¢s products: Acrobat, ColdFusion, and ColdFusion Builder. This goes hand in hand with a report from Brian Krebs this morning, who noted that he and a fellow researcher had discovered at least 40GB of Adobe source code available on a hacking groupââ'¬â"¢s private server.
Beyond the obvious business implications of having your otherwise locked down source code floating around in the wild, there are potentially massive security concerns here. Once youââ'¬â"¢ve got the source code for an application in hand, it becomes much easier to dig up the stealthy lilââ'¬â"¢ security screw ups that might otherwise go unnoticed. Combine this new potential for big zero-day exploits with the many, many millions of Adobe Acrobat (Adobeââ'¬â"¢s official PDF reader) installs around the world, and this all starts to get pretty worrisome.
My comments:
There are two aspects to the hack:
1 Customer account data leaked
This shows once more that itââ'¬â"¢s the paying customers that get punished. Pirates not giving their credit card data are safe.
2 Source code for Acrobat (reader) leaked, greatly facilitating exploits
This is very worrisome to many users. But again, theyââ'¬â"¢re partly to blame, because there are lighter and more secure free alternatives that knowledgeable users prefer.
Adobe has just disclosed that one of their servers has been hacked.
While their investigations are still ongoing, Adobe has shared a few details on what they believe could have been accessed and obtained in the hack ââ'¬â€ and itââ'¬â"¢s a big one.
It seems that the hackers got access to encrypted data for as many as 2.9 million customers. While Adobe stresses that the data is encrypted and that they ââ'¬Å"do not believe the attackers removed decrypted credit or debit card numbersââ'¬Â, that data ââ'¬â€ encrypted or not ââ'¬â€ is definitely not something they want out in the wild.
Adobe has yet to disclose how that data was encrypted, so itââ'¬â"¢s currently unclear just how secure it is.
Meanwhile, it also appears that the hackers may have been able to access the source code for at least three of Adobeââ'¬â"¢s products: Acrobat, ColdFusion, and ColdFusion Builder. This goes hand in hand with a report from Brian Krebs this morning, who noted that he and a fellow researcher had discovered at least 40GB of Adobe source code available on a hacking groupââ'¬â"¢s private server.
Beyond the obvious business implications of having your otherwise locked down source code floating around in the wild, there are potentially massive security concerns here. Once youââ'¬â"¢ve got the source code for an application in hand, it becomes much easier to dig up the stealthy lilââ'¬â"¢ security screw ups that might otherwise go unnoticed. Combine this new potential for big zero-day exploits with the many, many millions of Adobe Acrobat (Adobeââ'¬â"¢s official PDF reader) installs around the world, and this all starts to get pretty worrisome.
Code:
http://techcrunch.com/2013/10/03/ado...kely-accessed/
My comments:
There are two aspects to the hack:
1 Customer account data leaked
This shows once more that itââ'¬â"¢s the paying customers that get punished. Pirates not giving their credit card data are safe.
2 Source code for Acrobat (reader) leaked, greatly facilitating exploits
This is very worrisome to many users. But again, theyââ'¬â"¢re partly to blame, because there are lighter and more secure free alternatives that knowledgeable users prefer.