Christopher Bouzy
A
thread 1/2
⛔️📢I have released a statement regarding a security incident that we were notified about earlier this morning.

You can also read the full statement here: https://help.spoutible.com/support/solutions/articles/150000174284-important-security-update
10:03 AM - Feb 04, 2024
Avatar Avatar Avatar
0
92
310
Christopher Bouzy
A
thread 2/2
Today at 1 PM EST, we will discuss this incident and address your concerns.

Join us here: https://spoutible.com/pod/65bf8cdc375c78dce9844973
10:03 AM - Feb 04, 2024
6
89
Blair Houghton
A
It says decrypted passwords weren't exposed. What about encrypted ones?

And "scraped" implies this was done via http.
In response to Christopher Bouzy.
10:20 AM - Feb 04, 2024
1
0
Apple Freak
A
In response to Blair Houghton.
Yep, the password hash (basically a one-way encrypted form) was leaked. These hashes weren't salted (salts being a way to make it harder to figure out what the original password was), so combined with weak presets and short max passwords, it's entirely possible they can be decrypted easily enough.
11:19 AM - Feb 05, 2024
2
0
Apple Freak
A
In response to Apple Freak.
Likewise, the data was obtained through one of the interfaces that this app uses for the Pods feature, meaning this information was sent to any user that hovered over another user's profile pic (even if it was otherwise invisible to the user).
11:21 AM - Feb 05, 2024
0
0
Blair Houghton
A
In response to Apple Freak.
"These hashes weren't salted..."

(Shakes head in 1987 security mode...)
01:25 PM - Feb 05, 2024
0
1

 

{{ notificationModalContent }} {{ promptModalMessage }}