back to article Comcast resets 200k cleartext passwords, hacker claims breach

A hacker has tried to sell 200,000 valid cleartext Comcast credentials he claims he stole in 2013 from the telco's then-vulnerable mailserver. The telco has reset passwords for the affected accounts after news surfaced of the credentials being sold on the Python Market hidden marketplace. Of the total pool of 590,000 accounts …

  1. Notas Badoff

    Ebay'd?

    Old server hard disk bought from Ebay?

  2. Your alien overlord - fear me

    Does Talktalk offer an email service? Icing on the cake if they used this software :-)

  3. PassiveSmoking

    So they store the passwords as plain text.

    Quality service!

    Can we have a rule please? Anyone who uses SHA-1 or weaker for passwords gets publicly slapped.

    Anyone who uses plain text gets a kick in the balls.

    And that's per password.

    1. James O'Shea

      "Anyone who uses plain text gets a kick in the balls."

      m'girl Dido has balls?! That does tend to explain why she needs a shave...

  4. Anonymous Coward
    Anonymous Coward

    SOS, DD

    When I informed Comcast that their mail servers had been compromised, they told me it was my problem, not there's. Comcast has a litany of tech and criminal issues including their illegal blocking of legitimate international e-mail sent to U.S. Comcast customers. The illegal blockage of all e-mail from hundreds of legitimate international ISPs is not only outrageous it is illegal and constitutes consumer fraud as consumers are paying Comcast to deliver all legitimate e-mail. It's time that the FCC and FTC get off their fat asses and convict Comcast cable for their violations of law. Comcast should also be heavily fined for their negligence in having insecure servers that allowed hackers to steal e-mail and personal information.

  5. Mike 16

    Hmm, maybe that explains

    why my wife's Comcast email (the only busy one of the four we have, mostly for websites that insist) was curiously silent for about 24 hours a day or so back. Several folks asked her via various other channels if she had received the email they had sent. Test email we sent from gmail etc. showed up, so it wasn't just the Comcast DNS throwing a wobbly again. If only it was possible to get internet connectivity in my neighborhood from someone who wasn't incompetent or a crook (Inclusive OR, of course).

    OTOH, we weren't told about any such password reset, and the previous password still works. OTOOH, it's not like we're still using the one from 2013.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like