So this morning brought a "We've been hacked!" email from CoveritLive with the assurance " We regret any inconvenience that this password change process may cause you". Frankly, an enforced password change is a small price to pay... hopefully that's the full extent of it.
From: CoveritLive Date: 14 January 2012 01:22
Subject: Important CoveritLive Password Notification
CoveritLive recently discovered that certain proprietary data files were accessed without authorization starting on or about January 7, 2012. We have not yet determined if, or to what extent, CoveritLive account information (i.e., user names, email addresses and/or passwords) was accessed. We do know, however, that no financial account information has been compromised.
Our investigation is ongoing, and, as a precautionary measure, we will implement required password resets for all active CoveritLive accounts. We plan for this process to begin Saturday January 14, 2012 at 12 AM EDT (5 AM GMT). The next time you log in after the process has begun, you will be asked to change your password before you will be allowed into your account. NOTE: we do not anticipate that you will experience a disruption in your event if you are using CoveritLive while the change is invoked.
Your password and all account passwords are encrypted as a standard CoveritLive information security practice, and we have no evidence that an unauthorized individual has actually retrieved, or is using such data. However, out of an abundance of caution we recommend that if you registered for CoveritLive using an email address and password combination that you use for other online accounts, you should immediately create unique passwords or new login credentials for those other sites and accounts.
We take this matter very seriously and will continue to work to ensure that all appropriate measures are taken to protect your personal information from unauthorized access. We also would like to take this moment to remind you of a couple of tips that should always be followed:
- Do not open emails from senders you do not know. Be especially cautious of "phishing" emails, where the sender tries to trick the recipient into disclosing confidential or personal information.
We regret any inconvenience that this password change process may cause you. Please do not hesitate to contact us at firstname.lastname@example.org if you have any questions.
- Do not share personal or sensitive information via email. Legitimate companies will not attempt to collect personal information outside of a secure website.