Thread: Business Security Breaches at Moniker
View Single Post
Old 10-10-2014, 11:49 AM  
InfoGuy
80/20 Rule
 
InfoGuy's Avatar
 
Industry Role:
Join Date: Apr 2010
Location: Los Angeles
Posts: 3,050
Those clowns at Moniker don't even follow their own advice. They weakened the strength of my password when they reset it by only using the first three types of characters.

Quote:
As part of this process, you will be required to reset your account password while adhering to stronger minimum password requirements.

You will now need to use a more secure password combination at least eight characters in length and including three of these four attributes:

* Lowercase characters
* Uppercase characters
* Numerical digits
* Special characters
And let's not forget that this isn't Moniker's first time to do a system wide password reset due to account security concerns. On June 19, 2013, Moniker sent out an email with the subject "Security Notice: Service-wide Password Reset".

Quote:
Moniker?s Operations & Security team has discovered and blocked suspicious activity on the Moniker network that appears to have been a coordinated attempt to access a number of Moniker user accounts.

As a precaution to protect your domains, we have decided to implement a system-wide password reset. Please read the below instructions to create a new password. You will not be able to access your Moniker account until these steps are taken.

In our security investigation, we have found no evidence that domains have been lost or transferred out. We also have no evidence that any confidential or credit card information has been compromised.

While our password encryption measures are robust, we are taking additional steps to ensure that your personal data and domains remain secure. This means that, to be absolutely sure of the security of your account, we are requiring all users to reset their Moniker account passwords.
Please reset your password by following the directions below.

1) Go to Moniker.com and click the ?Sign In? button in the upper right hand corner of the home page. Select the ?Forgot Your Password? link.

2) You will be directed to a page to ?Retrieve? your Moniker Account Password. When prompted, enter your account number and click ?Submit?.

3) You will be directed to a page that displays the message below. You will receive an email from Moniker. Please follow the instructions in this email to complete the password reset.

As recent events with other large services have demonstrated, this type of activity is becoming more common. We take our responsibility to keep your domains and personal data safe very seriously, and we're constantly enhancing the security of our service infrastructure to protect our customers. We feel it is also important to be clear that we view this as attempted illegal activity and have taken steps to report this to the appropriate authorities.

There are also several important steps that you can take to ensure that your data on any website, including Moniker, is secure:
? Avoid using simple passwords based on dictionary words
? Never use the same password on multiple sites or services
? Never click on 'reset password' requests in emails that you did not request

Thank you for taking the time to read this email. We sincerely apologize for the inconvenience of having to change your password, but, ultimately, we believe this simple step will result in a more secure experience. If you have any questions, please do not hesitate to contact Moniker Support. Our support team is standing by to assist at 800-688-6311 or outside the U.S. and Canada: 954-607-1294.

Drake Harvey
Chief Operations Officer
Moniker.com
Moniker has acknowledged in their latest emails that domains were fraudulently transferred out, so it's quite possible that personal and credit card info may have also been compromised. It wouldn't surprise me to get that announcement next week.
InfoGuy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote