IEEE Mistake Exposes Tens of Thousands of Member Names and Passwords
September 26, 2012 9:12 AM
comment(s) - last by
No public acknowledgment of the leak offered
The Institute of Electrical and Electronics Engineers (IEEE) reportedly made a massive mistake that left nearly 100,000 usernames and passwords of members of the organization exposed on a public server. A plain text list of username and password combinations was publicly available on a FTP server for over a month before being discovered. The plain text list was discovered last week by teaching assistant in the computer science department at the University of Copenhagen.
Considering the huge number of technology experts who are members of the IEEE and who work for the organization, this is a massive and hugely embarrassing security fault. The usernames and passwords of members weren't the only pieces of information exposed on the publicly accessible FTP site. In addition, over 100 GB of Web server log files from ieee.org and spectrum.ieee.org were publicly available because server administrators hadn't set access controls.
Those logs reportedly showed 376 million HTTP requests and 411,308 of those included both usernames and passwords.
reports that most of the compromised accounts belonged to employees at Apple, Google, IBM, Oracle, and Samsung. However, some of the user names and passwords exposed also belong to researchers from NASA, Stanford University, and other universities and organizations.
reports that the IEEE has yet to publicly admit the data was leaked and hasn't been returning calls for comment. Teaching assistant Radu Dragusin said, "One simple and stupid mistake: public access to logs. The other, more troublesome, keeping passwords in plain text, which seems to be more on how they architect their login system." He also noted that, "While the first issue [log files] is clearly solved, I doubt the second is."
This article is over a month old, voting and posting comments is disabled
9/26/2012 2:29:56 PM
Let’s all go back to paper and pen and save everything in fireproof cabinets and briefcases with combination locks only known to 3 people at a time.
9/26/2012 2:43:35 PM
meh. It sickens me that large organizations have such poor security.
"If you look at the last five years, if you look at what major innovations have occurred in computing technology, every single one of them came from AMD. Not a single innovation came from Intel." -- AMD CEO Hector Ruiz in 2007
Google's Gleaming Glass HQ Gets Mountain View Snub, LinkedIn Gets the Love
May 7, 2015, 6:58 AM
Tech's Tax Day Fortunate Few: Qualcomm, Xerox, GE, et al. Pay Little or No Taxes
April 15, 2015, 11:30 AM
LinkNYC Terminals to Blanket New York City With Free WiFi, Free Calls, and Ads
November 17, 2014, 6:50 PM
Microsoft is Open-Sourcing Most of .NET, Adding OS X and Linux Support
November 12, 2014, 8:27 PM
Home Depot Lost 53 Million Emails, Blames Windows, Buys Execs New Macs
November 9, 2014, 5:00 PM
Former NSA Lawyer: If Google, Apple Encrypt User Data, They’ll Wither on the Vine Like Blackberry
November 6, 2014, 12:15 PM
Most Popular Articles
Say Goodbye to Data Plans - Sprint and T-Mobile offer Unlimited Data
August 22, 2016, 6:12 AM
Lenovo vs. Asus vs. HP - Best Laptop Under $500.00
August 19, 2016, 4:00 AM
Uber - Everyone's Autonomous Car Driver?
August 20, 2016, 6:01 AM
Get Ready to wait in line – iPhone 7 due September.
August 18, 2016, 7:15 AM
5 Healthy and Creative ways to add Fiber to your Diet By Monique C. Bethell, Ph.D.
August 18, 2016, 7:43 AM
Latest Blog Posts
Coming Soon - Drones and Airports
Aug 24, 2016, 12:40 PM
SolarCity’s Gigafactory: A Milesone in Emerging Technology by Lily Emamian - 15 August 2016
Aug 15, 2016, 6:30 AM
Sceptre Airs 27", 120 Hz. 1080p Monitor/HDTV w/ 5 ms Response Time for $220
Dec 3, 2014, 10:32 PM
Costco Gives Employees Thanksgiving Off; Wal-Mart Leads "Black Thursday" Charge
Oct 29, 2014, 9:57 PM
"Bear Selfies" Fad Could Turn Deadly, Warn Nevada Wildlife Officials
Oct 28, 2014, 12:00 PM
More Blog Posts
Copyright 2016 DailyTech LLC. -
Terms, Conditions & Privacy Information