Troy Hunt: 5 website security lessons courtesy of Stratfor.
This wasn’t intended to be a Stratfor-bashing post, rather it’s an opportunity to see the fate which awaits those who don’t take website security seriously. Call it a quick reality check if you will.
Insightful lessons to be learned from analyzing the Stratfor breach:
- There doesn’t need to be a reason for you to be hacked
- The financial abuse of your customers will extend long and far
- Your customers’ other online services will be compromised
- Saltless password hashes are a thin veneer of security
- Your dirty software laundry will be aired quickly
Regarding #3 above, Bellovin’s article about passwords is relevant.