Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Expert Comments on MySpace and Tumblr Hit by ‘Mega Breach’
News & Analysis

Expert Comments on MySpace and Tumblr Hit by ‘Mega Breach’

ISBuzz TeamBy ISBuzz TeamJune 2, 2016Updated:May 8, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Following the news that hundreds of millions of hacked account details from social networks MySpace and Tumblr have been advertised for sale online, IT security experts from MIRACL, AlienVault and ESET provide commentary and advice:

Brian Spector, CEO at MIRACL:

brian-spectoreicThis incident provides us with another reminder of just how vulnerable passwords are to being hacked. The tendency for people to choose a password for life means that setting up a cursory account on a site like MySpace could threaten all the private information that they store and access on the Web each day.

But the bigger problem here is that the convention never changes. Until we consign passwords to the history books, data breaches will continue to feature in our news feeds. Passwords don’t scale for users, they don’t protect individual services and they are vulnerable to a myriad of attacks. Customers are usually advised to change passwords when a breach like this occurs, but that won’t protect users from database hacks. The only way to move forwards is to distribute trust across multiple points with rigorous authentication technologies, thus eliminating the single point of compromise.

Javvad Malik, Security Advocate at AlienVault:

Javvad MalikIs it likely that many people are still using the same password after several years?

Yes, and this is what lies at the heart of the matter. Password re-use or the tendency for people to set a ‘life password’ is common. The challenge is selecting different passwords for each site someone uses. Users should ask themselves:

  1. When a website announces a breach, how confident am I that I haven’t used that password elsewhere?
  2. If I have used that password elsewhere, I should go and change it immediately.
  3. If a website offers two-factor or two-step authentication, I should enable it.
  4. What’s stopping me from using a password manager?”

Should major websites start forcing a 3 month password change like they do in enterprise environment? 

“Absolutely not. In fact, frequent password changes are being advised against by the likes of CESG. One of the problems with forcing regular changes besides the inconvenience, is that users will inevitably begin to choose easier-to-remember (and hence guess) passwords.

What we are seeing though, is the likes of Microsoft introducing into Azure features that stop users from setting a password that has appeared in a leak . This kind of measure – on  behalf of the service provider can go a long way in nudging people towards choosing better passwords.

Mark James, Security Specialist at ESET:

mark-jamesIs there a link between the LinkedIn, Tumbler and Myspace data leaks?

“It’s very interesting to see these older hacked databases coming to light, it may indeed be linked to the same collective or just data previously collected and offered for sale now. Either way it still poses the same security risk, unfortunately the average user will wait for something to happen before they take action on an account. I would advise you review all your passwords used in online activity and ensure they are all unique, if not make it so.”

Can we trust companies to adequately protect our data?

“The problem is we have to if we want to use their services, whilst we hope and trust they will look after it we need to understand we should also take adequate measures to ensure we do as much as we can to help them do just that; it’s our data after all. Most companies will do all they can to protect our data, it’s in their interest to keep it safe but we have to accept the fact there are some simple tasks we can do to keep our credentials not only safe but difficult to reuse in case we are breached on one site.”

Are passwords still fit for purpose?

“Yes, a good well thought out unique password that utilises the correct complexities is a great start to protecting your data, there are many other options on top of that but you need the base right to build your security from. Many companies will now offer a second form of protection to back up your traditional username and password along with alerts for you, the user, whenever you log in from a different platform or device.

Using 2FA is a great way to boost the security of your account, Tumblr make this available but ultimately it’s down to the user to actually turn it on and use it and for some the extra added steps stop people from actually doing so. These days we want ease, we want speed, we want everything to happen quicker and with less steps and adding a process that makes things harder often stops people from using that feature even though it may actually increase their security.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}