Comcast passwords leaked onto the Web
A list of 700 usernames and passwords for Comcast customers was removed from document-sharing Web site Scribd on Monday, two months after it was posted there.
Scribd removed the list of what initially looked like thousands of passwords and usernames after being contacted by Brad Stone at The New York Times. Stone wrote that he was contacted by a Comcast customer who happened across the list after doing a search on his own e-mail address on search engine Pipl.
Comcast spokeswoman Jennifer Khoury told The New York Times that the list was probably compiled from phishing or some other related type of attack and not from inside Comcast.
Comcast is freezing the e-mail accounts of customers whose data was exposed and is contacting them, she said.
"We have scrubbed the list that was on ScribD and have found that about 700 names are user ID's that are for Comcast customers, not 8,000," a Comcast spokesman said in an e-mail later. "The other names on the list are either not customers, duplicates or older inactive accounts (no e-mail address currently)."
Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor. 





- by shadowkeeper_24 April 3, 2009 12:25 PM PDT
- I never realized how many people are so short sited as to blame a company for their own short commings. <br />
<br />1. if this was a security risk with comcast, there would be no duplicate entries.
<br />2. If this was a security risk with comcast, there would be no inactive accounts. not in the number that is there. These email accounts where gotten over a period of time. Not all at once.
<br />3. In response to some others who have no clue about technology. Any large company like comcast or any other company, is required by law to have all information encrypted. the only peole who have things in plain text are regular people.
<br />4. To the person who asks if comcast has even checked to see if it is a leak. Well once the passwords get entered int the system. they are encrypted. there is no access to pull passwords back out. That is how it works with all major companies that have to follow FCC regulations.
<br />5. People who left comcast because of this. Well hope you live in the dark ages, because. every large company out there follows the same FCC guidlines as comcast because it is required by everyone. So if you have problem with one company in this sence, you might as well have problems with all companies out there that work in the communication industry as well as any transactional facility.
<br />
<br />So lets entertain the idea of it was something inside comcast that got this information. it would have to be a high lvl employee, who has the access to password storage system, who also knows the encryption algorithm, and since the encryption algorithm is one way not two way, he wil have to be a high lvl programmer to hack the ecryption algorithm-at this point, military would have hired him and he wouldn't be working here. - ok going on, he would copy all the active accounts he can see, be way over 8,000, wouldn't have any inactive accounts unless he is an idiot, but wait, he hacked the system he isn't that dumb. Then for some reason add many invalid and duplicate email accounts for the fun of it. Why would he do that.
<br />
<br />Lets entertain a phishing scam going on for a year+. only gets people that go to it, hence 8000. A person who gets scammed once usually get scammed twice, hence duplicate email accounts. People use fake emails at times not trusting a site, hence invalid email accounts. inactive email accounts, probably some of the first people to get scammed.
<br />
<br />Which of these two are more likely to be the correct answer. The simpler of the two and the easier of the two. <br />
<br />From the looks of it therer will be a few short sited people on here who will be scammed in the future and then blame other people for there short sitedness
<br />
<br />P.S. I don't agree with some things about Comcast or other Big Companies, But I am an IT specialist and hate to see people get scammed and then blame the incorrect party instead of taking the necessary measures to not get scammed.
- Like this Reply to this comment
-
(20 Comments)