UPDATED 15:53 EDT / AUGUST 04 2014

Mozilla Developer Network accidentally exposes thousands of e-mails, password hashes

mozilla-developer-network-logoLast Friday, Mozilla reported the accidental release of the e-mails of 76,000 Mozilla Developer Network (MDN) users to the public alongside the encrypted passwords of 4,000 users. The disclosure happened due to the failure of a data sanitization process at the MDN site starting on June 23rd and lasting a period of 30 days.

Mozilla is a free software community best known for developing and supporting the Firefox web browser.

According to a blog post outlining the issue, Mozilla engineers removed the accidentally disclosed database dump file immediately upon discovering the issue. Also the failing data sanitization process has been disabled to prevent further disclosure.

“The encrypted passwords were salted hashes and they by themselves cannot be used to authenticate with the MDN website today,” wrote Stormy Peters, Director of Developer Relations, and Joe Stevensen, Operations Security Manager.

However, MDN users could have re-used passwords on other sites or services (a practice discouraged heavily by the security community) and this would leave them vulnerable to exposure on those services.

Notices have been sent to all users affected by the breach recommending that they change any similar passwords they have been using.

Mozilla engineers have not seen any evidence that the accidentally disclosed information had been accessed and no malicious reports have surfaced. It is still better to be safe than sorry in the case of a breach.

Peters and Stevensen emphasized in the security transparency blog post that the MDN team is taking a further look at the processes that led to this exposure and the principles in place to reduce harm to users. Users or parties who have any questions may reach out to security@mozilla.org for further information.


A message from John Furrier, co-founder of SiliconANGLE:

Support our open free content by sharing and engaging with our content and community.

Join theCUBE Alumni Trust Network

Where Technology Leaders Connect, Share Intelligence & Create Opportunities

11.4k+  
CUBE Alumni Network
C-level and Technical
Domain Experts
15M+ 
theCUBE
Viewers
Connect with 11,413+ industry leaders from our network of tech and business leaders forming a unique trusted network effect.

SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.