17 January 2012

Zappos Customer Accounts Hacked | The password reset process

There has been a lot of news recently about the intrusion of the Zappos.com customer data whereby hackers gained access to data including "the name, e-mail address, billing and shipping addresses, phone number, the last four digits of your credit card number (the standard information you find on receipts), and/or your cryptographically scrambled password (but not your actual password)."

Zappos, now part of Amazon, responded with an email to all of the 24 million plus account holders with the above information. They also went on to say that they have "...expired and reset your password so you can create a new password."

Now, at first glance this seems like a great sequence of events but I'm now wondering what my password was for Zappos because I didn't save that password any where. This leads me to now question if I used the password on another website. It would be great if I used a different password on every site I have but with over 250+ logins to accounts it's damn near impossible to have a different one to them all.

Let's just hope that I can somehow obtain the old password either from the standard password reset process via the website or I at least hope they still have the hash of the password I used for the site. The hacker has it so I hope Zappos still does. I have yet to go through the password reset processes as they aren't allowing access outside the US currently.

[Update 2012-01-17 22:55]

I contacted Zappos via their passwordchange@ address they indicated earlier today to let them know what I said above. They came back to me rather quickly which is fantastic considering the number of enquiries they must be receiving.

I asked them if they could send me that hashed version of my stolen password. The one they told me was compromised via their email. I said I no longer knew which one I used, I use many, but like most, I re-use some here and there.

I was told:

Thank you for your response to our earlier email. We would like to extend our sincerest apologies for the inconvenience this may have caused and we truly understand the severity of the situation.

Unfortunately, we do not have access to any of your previous passwords, so we are unable to have this re-sent to you. However, if you attempt to reset your password to a previously used password, the system will decline the attempted password reset. So, if this occurs, this may serve as a strong indication to you that this might be the password in question.

I emailed back stating that if you're checking against old passwords then you must still have the password hash. I can't access your website at all to reset it, could you talk to a developer and get this for me please. I was shocked to receive this:

As indicated in the previous email, your old password has been reset and expired; therefore what it may have been is no longer of importance. We recommended that you update subsequent online accounts if you consistently use a similar password as an added precaution. This link below will take you to our website and allow you to create a new password in order for you to access your Zappos.com Account: zappos.com/passwordchange

Knowing what password I used at Zappos will unlock the mystery to which of the 250+ other accounts I need to change my passwords on.

I'm waiting for a reply back from my explanation of how critically important knowing my old password is and the fact that I can't access and reset my password on their site. Hopefully there's some time for them to address this on their today. Mine is over for now. I'm going to sleep. More to follow.

21 September 2011

Kate Burns leaves AOL - goviral execs to lead Europe business


Announced today that Kate Burns is leaving as SVP Europe of AOL. René Rechtman and Jimmy Maymann will be taking her place.

05 August 2011

AOL Summer Party in London starring Cokeboy and Titgirl

Just last night, Thurs 4 Aug, there was what you might think your typical media agency party going on in Shoreditch, London hosted by AOL. There were a few DJs lined up like Jamie XX, Ben Bridgewater and Josh Silver playing tunes like Gold Dust and Bigger than Hip Hop.

It was all looking like a great evening of music, drinks and media talk. Part of the evening included a photo booth that was set up to take photos of those that went into a booth. I suspect most people thought that the only record of these photos would be the ones printed out then and there. Little did they know there would be an online album (pass: Shoreditch) shared with all those that attended.

These bright young people decided it would be a good idea to get their (what appears to be) bag of coke out and have a few snorts in front of the camera. There's the main photo floating around which you can find here whilst it's still up - #cokeboy

In addition to these bunch, towards the end of the night it appears it started to get a bit hot in the venue. There's more than a few that stated to get their kit off and show off for all to see. #titgirl

20 July 2011

Spotify is Removing Songs from My Playlists

Spotify has been growing for a few years now and it's finally reached the US market. I've been using Spotify for quite some time now and even created a Spotify Drinking Game some time ago. For a while I upgraded to the Premium offer for £9.99 so I could listen on my Android phone. I've since cut back on some costs and I'm back to the Open plan.

The other day I went on the hunt for some music to add to a new playlist. I stumbled upon some continus mix tracks that last from 60-80 minutes for a single track. I added them to my Continuous Mix Sets playlist and enjoyed them for a day or so. All is good...

I've since came back a few days later and all of a sudden the tracks I were listening to only days before are no longer available for listening. I wonder now if this is down to licencing issues or perhaps a further limitation Spotify is placing on users due to the lack of advertising one would be exposed to when listening to a track of such a length.

I've reached out to Daniel Ek (Co-Founder) and Andreas Ehn (CTO) of Spotify via a Google+ post asking them about this and looped in tech evangelist Robert Scoble to get his opinion. Wonder if they'll have a reply at all, doubtful (Robert quite possibly though). What do you think; licencing issue or Spotify further tightening the reigns on free use?

16 July 2011

Kittens on DJ Decks - First Viral Video of Google+

If you haven't seen it already check out the video featuring Catboy Slim, Armin van Purren and Deadmeow5.




The newest social network Google+ has recently launched just the other week. If you're not on it yet you most certainly have heard of it. It's currently loaded with lots of Tech people and as such the discussions are mostly focused around topics related to Google+ itself or other tech related items. Adding some cats in the mix only helps broaden the audience and bring the platform to the mainstream.

This video, I believe, can hold the honour as the first viral video spread from a Google+ post. It's managed to make it's way to the Mashable home page as well as numerous places all around the web like RedditBoingoingBuzzhunt and others.

It's spread so quickly that YouTube stats can't even keep up with it yet. It's holding numerous hounours right now and at only 1,800 or so views it's clearly not keeping up.