RockYou’s Data Breach Takes A Turn For The Worse With Class Action Suit

-RockYou Logo-

RockYou has come under fire recently after a SQL injection flaw resulted in a data breach which exposed over 32 million RockYou user emails and passwords. Rather than immediately solving the problem however, RockYou was complacent. As Nik Cubrilovic pointed out, “They have not taken steps to rectify the problems that caused the breach and have not addressed their users in a suitable or adequate manner. An appropriate response would have been to take the site down for a period of a few hours and enforce that users enter new passwords, which would be stored in a hashed or encrypted form.” Two weeks later a class action has been filed.

According to Wired, “RockYou, the popular provider of third-party apps for Facebook, MySpace and other social-networking services, is being hit with a proposed class-action accusing the company of having such poor data security that at least one hacker got away with 32 million e-mails and their passwords.” The suit claims that RockYou made “its unencrypted customer data ‘available to even the least capable hacker.’”

It’s a poor showing for a company which recently raised an additional $50 million in a Series D round. Good thing the company has cash though. They’ll now be able to afford a strong legal team to defend them in court. SQL injection attacks are things that beginner programmers learn about when protecting their system, making it clear that RockYou’s code was not sound.

It will be interesting to see if this suit amounts to anything. If someone puts their password in your form, you should make efforts to protect that user data, however it’s not clear how far one has to go to protect those users. Regardless of legal bearing, protecting users is critical for any company which intends to become as large as RockYou has become.

  Tags: , ,
  • OzgurDunyamcom
    Thank you for the information your provide.
    sesli chat
    SesliSohbet
    Sesli Sohbet
    Sesli Chat
    SesliChat siteleri
    sesli
  • Disqus is a great tool, I have it on many of my blogs already. It will only get better in the next few years..Disqus is a popular commenting platform...
  • very pleasure to visit this site. nice post. thanks for sharing.
  • Thanks for the post , i like your bloog
  • seslipanel
    That's not a good news from rockyou side ?
  • Well I guess we'll have to leave that to the authority. Personally, problems must be taken with good solution, but if you don't take it seriously then it will end up just like this.
  • Rock on man! That was really great! I love it.
  • Rockyou deserves the class action suit for not taking care of the problem. All the best.
  • That's not a good news from rockyou side. It's shocking man.
  • so sad for rock you. =(
  • It's a shame RockYou store that kind of info without a good encryption...
    Well, I used some of their softwares, so probably I'm hacked, too...

    Regards,
    Jogos
  • I think Rockyou deserves the class action suit for not taking care of the problem. Imaging Facebook does the same thing? That would be like billion dollar lawsuit right there.
  • Edmond
    Cripes.
    Imagine what would happen if a big time official there lost his USB drive - not only would the finder (or thief) get access to all the email addresses and passwords, but also to invaluable corporate information and data. Encryption is important - not just on databases but even on your own portable drives. The best bet would probably be to get an encrypted USB drive.
blog comments powered by Disqus

Upcoming Events

Smartphone Games Summit

September 24, 2010 | Hotel Nikko, San Francisco

Smartphone Games Summit Logo

The Smartphone Games Summit is a one-day conference focused on the emerging smartphone games space.

Social Ad Summit

October 1, 2010 | The New Yorker Hotel, New York City

Social Ad Summit Logo

Social Ad Summit is a full day conference held in New York City focused on strategic issues driving the growth of advertising on social platforms.