We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

TalkTalk website hit by cyber-attack

Options
145791049

Comments

  • MacMickster
    MacMickster Posts: 3,646 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    On a message posted on its website, TalkTalk states: "We are continuing to work with leading cybercrime specialists and the Metropolitan Police to establish exactly what happened and the extent of any information accessed.

    "We would like to reassure you that we take any threat to the security of our customers' data very seriously. We constantly review and update our systems to make sure they are as secure as possible and we’re taking all the necessary steps to understand this incident and to protect as best we can against similar attacks in future. Unfortunately cyber criminals are becoming increasingly sophisticated and attacks against companies which do business online are becoming more frequent."

    And yet customer data is held unencrypted. Ludicrous!
    "When the people fear the government there is tyranny, when the government fears the people there is liberty." - Thomas Jefferson
  • alleycat`
    alleycat` Posts: 1,901 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Not a talktalk customer but If they are anything like Sky I'd bet the details of previous customers are still available and were also taken.

    My old Sky login still works, it just says i have no associated services.

    It still shows all my details in the way it did when i was a true paying customer.

    I also wonder if talk talk have actively excluded all their old "but details still exist" customers from the total volume to try make it look better.

    Not sure how you make 4 million look "better" but PR people do like to spin.

    If they "lost" that data as well are they intending to let those people know also?
    I'd suspect not....
  • Oblivion
    Oblivion Posts: 20,248 Forumite
    Part of the Furniture 10,000 Posts Photogenic
    I think in the light of this fiasco, the government should compel all ISPs to declare whether personal data is held in encrypted form and if not, to make sure it is immediately.
    ... Dave
    Happily retired and enjoying my 14th year of leisure
    I am cleverly disguised as a responsible adult.
    Bring me sunshine in your smile
  • GingerBob_3
    GingerBob_3 Posts: 3,659 Forumite
    TalkTalk:


    "We would like to reassure you that we take any threat to the security of our customers' data very seriously...."


    Have you noticed how whenever someone, or some organisation, tells you they take something "very seriously" it means the exact opposite: they don't take it seriously, otherwise they wouldn't be having to lie to you that they do!


    Always be very wary of the "take something very seriously" remark.
  • Oblivion
    Oblivion Posts: 20,248 Forumite
    Part of the Furniture 10,000 Posts Photogenic
    I had to laugh when Dildo Harding made this comment ... "I'm a customer myself of TalkTalk, I've been a victim of this attack." And she's the Chief Executive. Oh well that makes it all right then.


    Keep digging that hole lady!
    ... Dave
    Happily retired and enjoying my 14th year of leisure
    I am cleverly disguised as a responsible adult.
    Bring me sunshine in your smile
  • Many reports in press about this and was thinking about switching next week. TT said 'offering a year's free credit monitoring' so do they want more access to your bank account as well!
    Regards

    Mark
  • Oblivion wrote: »
    I think in the light of this fiasco, the government should compel all ISPs to declare whether personal data is held in encrypted form and if not, to make sure it is immediately.

    Encrypted data can, in the main, be decrypted. One way encryption is possible, and passwords are routinely stored this way (you only have to check that the encrypted password stored in the database matches the encrypted version of the password just entered), but that is hopeless for things that the user might wish to see and edit, e.g. address details, or things that need to be used after being stored, e.g. card details.

    If the site has been compromised to the extent that data has been stolen, then it's fair to assume that the decryption keys used on the site to read any encrypted data have also been stolen. Having the data encrypted would add nothing in the circumstance.
    Proud member of the wokerati, though I don't eat tofu.Home is where my books are.Solar PV 5.2kWp system, SE facing, >1% shading, installed March 2019.Mortgage free July 2023
  • stojio
    stojio Posts: 107 Forumite
    Oh great.
    We just literally switched to TT and our services went live with them yesterday! Well that's just my luck at the moment!
    Can't remember giving my date of birth at any time during sign up though?
    Fingers crossed, no notification from TT yet either, but will be checking my bank from now on, and changing passwords - when I can actually get on the site!!!

    i've just switched as well, services go live soon. Bah.
  • alleycat`
    alleycat` Posts: 1,901 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    I imagine even if TalkTalk now decide they want or "need" to actually hash the passwords and other data they probably can't just go ahead and do that.

    If they did it would break pop/imap services, their "customer portal", Radius, ftp services and various other aspects that rely on the password and other data to be stored as it currently is.

    Recompiling/testing/development on those systems would be time consuming and not a quick fix.

    Hashed passwords are still pretty easy to guess using things like rainbow tables. People tend to use predictable / repeating / cack passwords which means normal hashing methods can be pretty "weak".

    Adding a "Salt" would help in slowing down that sort of attack but it's all a bit late now.

    On the positive side:-

    I bet it's got plenty of other ISP's (and their ilk) frantically running around working out if they are as vulnerable right now.
    It might, for values of might, end up saving someone else.
  • Does anyone know of a way I can migrate from Talktalk full LLU and keep my existing phone number? Is that simple?
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.6K Spending & Discounts
  • 244K Work, Benefits & Business
  • 598.8K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.3K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.