Flipboard is the latest company to fall foul of a data breach.
The news aggregation app announced in a post that it had identified unauthorized access of some of its internal systems, which contained some Flipboard users' account information and credentials.
For more than nine months, the unauthorized person had access to Flipboard's systems, potentially able to obtain copies of databases which hosted users' information.
It's unclear yet how many users were affected by the breach, but an investigation commissioned by the company revealed there was unauthorised access between June 2018 and April 2019.
While the information on these databases included their name, Flipboard username, and email address, the passwords were cryptographically protected with an algorithm called bcrypt.
The algorithm adds a unique, random set of characters called a salt, on top of the usual hashing of the password, in which it is scrambled to make it difficult to figure out. This makes the passwords very tough to crack, requiring significant computing power to do so.
Passwords which were set before Mar. 14, 2012 were hashed and salted with an algorithm called SHA-1, a once-widely used function now long obsolete in the realm of internet security.
Flipboard said all user passwords have been reset in light of the breach, despite only some users being affected by the incident.
The company also said its internal database contained digital tokens. These allowed Flipboard and a third-party to connect, for example when a user links their Flipboard account to social media platforms like Facebook or Twitter.
This allowed users to see content from these third-party accounts (i.e. making your Facebook News Feed readable on Flipboard), as well as comment on or share articles. The company said it had not seen unauthorized access to third-party accounts.
"We have not found any evidence the unauthorized person accessed third-party account(s) connected to users' Flipboard accounts. As a precaution, we have replaced or deleted all digital tokens," the post read.
"Importantly, we do not collect from users, and this incident did not involve Social Security numbers or other government-issued IDs, bank account, credit card, or other financial information."
Flipboard said it has already notified law enforcement of the incident, which it discovered on Apr. 23.
For users, they'll be prompted to change your password next time at login, and some will be prompted to reconnect to third-party services which were previously linked to Flipboard.
Copyright © 2023 Powered by
Flipboard reveals data breach, which left users' details exposed-山眉水眼网
sitemap
文章
5469
浏览
55
获赞
4639
This year's PSAT memes are here to anger the College Board
On Wednesday, high school students across the country took the PSAT and NMSQT (National Merit ScholaTikTok will reportedly sell to Oracle after Microsoft bid rejected
Oracle has beat out Microsoft to win the bid for TikTok's U.S. operations, according to a report byPersonal computers are once again shipping after an earlier pandemic
In the early stages of the COVID-19 pandemic, plenty of folks needed to buy computers — but th26 Years of The Elder Scrolls
It's been nearly a decade and two console generations since Skyrim came out in 2011. Since then, Bet12 unexpected ways algorithms control your life
Mashable’s series Algorithmsexplores the mysterious lines of code that increasingly control ouGMC revives gas
It may seem like an oxymoron that the massive, gas-guzzling GMC Hummer, once known as a symbol of ovYou can now watch YouTube with iPhone's Picture in Picture mode without a premium account
This is a pleasant surprise: YouTube's mobile website now allows Picture in Picture mode on an iPhonJudge won't let 'Fortnite' back into App Store as Apple fight crawls on
The battle royale between Epic Games and Apple is far from over. The ongoing debate over whether ForTrump tweeted a photo of Nancy Pelosi to insult her, and it backfired spectacularly
Trump's latest attempt to dunk on Nancy Pelosi really didn't work out. Democratic congressional leadChrissy Teigen accidentally leaks her email address on Twitter, styles it out
If you're an average Joe who accidentally tweets out their personal email address, chances are not aDyson introduces air purifier that destroys formaldehyde
Remember the terrible smell in ninth-grade biology when you dissected a frog? That's formaldehyde, aProposed tax on WhatsApp calls causes massive protests in Lebanon
After word got around in Lebanon that the government was planning to tax WhatsApp calls, thousands o21 Years of Hitman: How Stealth Action Got Perfected Over the Last 2 Decades
Coming off the highly anticipated release of Hitman 3, this latest installment has been very well re10 dogs who really loved their puppucinos
Forget the Dragonfruit Frappucino. Starbucks's best secret menu item is the puppuccino, and everyoneTrump complains about flushing, becomes the butt of Twitter jokes
The president made a bizarre claim that people flush their toilets "10 times, 15 times" per visit, a