<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Elance Hit By Security Breach</title>
	<atom:link href="http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/</link>
	<description>Startup and Technology News</description>
	<lastBuildDate>Fri, 27 Nov 2009 05:34:54 -0800</lastBuildDate>
	
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Steffan</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-3113656</link>
		<dc:creator>Steffan</dc:creator>
		<pubDate>Sun, 22 Nov 2009 21:11:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-3113656</guid>
		<description>I tried and used this new service OutsourcingRoom. Their support team is rather professional, and there are no fees and no % taken... It doesn’t look like a scary service at all.:) Many people work there and in the days of economic crisis I think they do a great job giving freelancers the way to earn their living. There’re no shill posters and shady bids on OutsourcingRoom. I’m sure it will be the most popular freelance service in the near future.</description>
		<content:encoded><![CDATA[<p>I tried and used this new service OutsourcingRoom. Their support team is rather professional, and there are no fees and no % taken&#8230; It doesn’t look like a scary service at all.:) Many people work there and in the days of economic crisis I think they do a great job giving freelancers the way to earn their living. There’re no shill posters and shady bids on OutsourcingRoom. I’m sure it will be the most popular freelance service in the near future.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rori</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2972034</link>
		<dc:creator>Rori</dc:creator>
		<pubDate>Tue, 08 Sep 2009 17:16:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2972034</guid>
		<description>I am sorry, but my credit card information was stolen from elance. I&#039;ve got a statement from the bank with some unusual transactions, all from the USA and I live in the UK. Fortunately had no big money in it. Should contact elance now and ask.</description>
		<content:encoded><![CDATA[<p>I am sorry, but my credit card information was stolen from elance. I&#8217;ve got a statement from the bank with some unusual transactions, all from the USA and I live in the UK. Fortunately had no big money in it. Should contact elance now and ask.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Security Snafu: Elance Sends Private Messages All Over The Place &#124; Codedstyle</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2954898</link>
		<dc:creator>Security Snafu: Elance Sends Private Messages All Over The Place &#124; Codedstyle</dc:creator>
		<pubDate>Sat, 29 Aug 2009 11:13:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2954898</guid>
		<description>[...] professionals and contractors online, and once again it&#8217;s not good news but another security issue. A registered user of the service, Salma Jafri, tells us she has been receiving dozens of private [...]</description>
		<content:encoded><![CDATA[<p>[...] professionals and contractors online, and once again it&#8217;s not good news but another security issue. A registered user of the service, Salma Jafri, tells us she has been receiving dozens of private [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Far Edge &#187; Blog Archive &#187; Security Snafu: Elance Sends Private Messages All Over The Place</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2954061</link>
		<dc:creator>The Far Edge &#187; Blog Archive &#187; Security Snafu: Elance Sends Private Messages All Over The Place</dc:creator>
		<pubDate>Fri, 28 Aug 2009 20:17:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2954061</guid>
		<description>[...] independent professionals and contractors online, and once again it’s not good news but another security issue. A registered user of the service, Salma Jafri, tells us she has been receiving dozens of private [...]</description>
		<content:encoded><![CDATA[<p>[...] independent professionals and contractors online, and once again it’s not good news but another security issue. A registered user of the service, Salma Jafri, tells us she has been receiving dozens of private [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Security Snafu: Elance Sends Private Messages All Over The Place &#124; Trinitude Network</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2953980</link>
		<dc:creator>Security Snafu: Elance Sends Private Messages All Over The Place &#124; Trinitude Network</dc:creator>
		<pubDate>Fri, 28 Aug 2009 19:14:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2953980</guid>
		<description>[...] professionals and contractors online, and once again it&#8217;s not good news but another security issue. A registered user of the service, Salma Jafri, tells us she has been receiving dozens of private [...]</description>
		<content:encoded><![CDATA[<p>[...] professionals and contractors online, and once again it&#8217;s not good news but another security issue. A registered user of the service, Salma Jafri, tells us she has been receiving dozens of private [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Security Snafu: Elance Sends Private Messages All Over The Place &#124; Techdare</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2953915</link>
		<dc:creator>Security Snafu: Elance Sends Private Messages All Over The Place &#124; Techdare</dc:creator>
		<pubDate>Fri, 28 Aug 2009 18:15:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2953915</guid>
		<description>[...] professionals and contractors online, and once again it&#8217;s not good news but another security issue. A registered user of the service, Salma Jafri, tells us she has been receiving dozens of private [...]</description>
		<content:encoded><![CDATA[<p>[...] professionals and contractors online, and once again it&#8217;s not good news but another security issue. A registered user of the service, Salma Jafri, tells us she has been receiving dozens of private [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gaurav</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2953615</link>
		<dc:creator>Gaurav</dc:creator>
		<pubDate>Fri, 28 Aug 2009 14:29:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2953615</guid>
		<description>Didn&#039;t realize the thread is from July. The emails I got were last night. I guess most likely some code screw up?</description>
		<content:encoded><![CDATA[<p>Didn&#8217;t realize the thread is from July. The emails I got were last night. I guess most likely some code screw up?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gaurav</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2953613</link>
		<dc:creator>Gaurav</dc:creator>
		<pubDate>Fri, 28 Aug 2009 14:27:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2953613</guid>
		<description>There is more to it. I received numerous messages which appear to be daily summary for projects on elance none of them have anything to do with me.

The summaries have private messages for those projects, with project details, email/phone as signature.

Jason - Where can I email a screenshot?</description>
		<content:encoded><![CDATA[<p>There is more to it. I received numerous messages which appear to be daily summary for projects on elance none of them have anything to do with me.</p>
<p>The summaries have private messages for those projects, with project details, email/phone as signature.</p>
<p>Jason &#8211; Where can I email a screenshot?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Security Snafu: Elance Sends Private Messages All Over The Place</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2953564</link>
		<dc:creator>Security Snafu: Elance Sends Private Messages All Over The Place</dc:creator>
		<pubDate>Fri, 28 Aug 2009 13:34:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2953564</guid>
		<description>[...] professionals and contractors online, and once again it&#8217;s not good news but another security issue. A registered user of the service, Salma Jafri, tells us she has been receiving dozens of private [...]</description>
		<content:encoded><![CDATA[<p>[...] professionals and contractors online, and once again it&#8217;s not good news but another security issue. A registered user of the service, Salma Jafri, tells us she has been receiving dozens of private [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Developerholic</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2875669</link>
		<dc:creator>Developerholic</dc:creator>
		<pubDate>Fri, 24 Jul 2009 02:18:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2875669</guid>
		<description>I own an account in Elance so I was surprised that my info were in OutsourcingRoom.com which I do not remember signing up. I think I discovered this way back prior Elance has discovered an attack</description>
		<content:encoded><![CDATA[<p>I own an account in Elance so I was surprised that my info were in OutsourcingRoom.com which I do not remember signing up. I think I discovered this way back prior Elance has discovered an attack</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Far Edge &#187; Blog Archive &#187; Spammers Running Wild In Latest MySpace Phishing Attack</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2868181</link>
		<dc:creator>The Far Edge &#187; Blog Archive &#187; Spammers Running Wild In Latest MySpace Phishing Attack</dc:creator>
		<pubDate>Mon, 20 Jul 2009 18:39:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2868181</guid>
		<description>[...] breach revealing internal documents, while developer-outsourcing site Elance got hit by a hack as well that compromised some user [...]</description>
		<content:encoded><![CDATA[<p>[...] breach revealing internal documents, while developer-outsourcing site Elance got hit by a hack as well that compromised some user [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spammers Running Wild In Latest MySpace Hack</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2868049</link>
		<dc:creator>Spammers Running Wild In Latest MySpace Hack</dc:creator>
		<pubDate>Mon, 20 Jul 2009 17:29:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2868049</guid>
		<description>[...] This is only the latest in a long string of recent security attacks against major web services. Last week Twitter fell prey to a massive security breach revealing internal documents, while developer-outsourcing site Elance got hit by a hack as well. [...]</description>
		<content:encoded><![CDATA[<p>[...] This is only the latest in a long string of recent security attacks against major web services. Last week Twitter fell prey to a massive security breach revealing internal documents, while developer-outsourcing site Elance got hit by a hack as well. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alexander Kornbrust</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2867391</link>
		<dc:creator>Alexander Kornbrust</dc:creator>
		<pubDate>Mon, 20 Jul 2009 11:54:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2867391</guid>
		<description>Elance lost also creditcard numbers, The hacker already abused my card. Mastercard locked my creditcard yesterday.</description>
		<content:encoded><![CDATA[<p>Elance lost also creditcard numbers, The hacker already abused my card. Mastercard locked my creditcard yesterday.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2866419</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Sun, 19 Jul 2009 22:07:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2866419</guid>
		<description>CEO CyberBionic Systematics Dmitriy Okhrimenko about OutsourcingRoom and Elance

http://outsourcingroom.com/en/services/AboutOutsourcingRoom.aspx</description>
		<content:encoded><![CDATA[<p>CEO CyberBionic Systematics Dmitriy Okhrimenko about OutsourcingRoom and Elance</p>
<p><a href="http://outsourcingroom.com/en/services/AboutOutsourcingRoom.aspx" rel="nofollow"></a><a href='http://outsourcingroom.com/en/services/AboutOutsourcingRoom.aspx'>http://outsourc...urcingRoom.aspx</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roberto</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2864617</link>
		<dc:creator>Roberto</dc:creator>
		<pubDate>Sat, 18 Jul 2009 14:44:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2864617</guid>
		<description>I hope that the credit cards are kept safe. Again, why the fuss if they only took the more-less public data?
Smells bad to me...
I anyway did not work with elance the past 6 months, as the economy collapsed. People from India and China work basically for a &quot;thanks&quot;.
Now, is there a reason to keep my elance profile? Should I trust them? Heh....</description>
		<content:encoded><![CDATA[<p>I hope that the credit cards are kept safe. Again, why the fuss if they only took the more-less public data?<br />
Smells bad to me&#8230;<br />
I anyway did not work with elance the past 6 months, as the economy collapsed. People from India and China work basically for a &#8220;thanks&#8221;.<br />
Now, is there a reason to keep my elance profile? Should I trust them? Heh&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Anderson</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2864275</link>
		<dc:creator>Paul Anderson</dc:creator>
		<pubDate>Sat, 18 Jul 2009 05:51:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2864275</guid>
		<description>Soon we&#039;ll see our credit card info on rapidshare... :( Hate elance(</description>
		<content:encoded><![CDATA[<p>Soon we&#8217;ll see our credit card info on rapidshare&#8230; <img src='http://www.techcrunch.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  Hate elance(</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Grossman</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2864274</link>
		<dc:creator>Dan Grossman</dc:creator>
		<pubDate>Sat, 18 Jul 2009 05:51:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2864274</guid>
		<description>There are too many factors we&#039;re not aware about to speculate. But if I were a member there with stored payment information, I&#039;d be logging into online banking every day to watch for fraudulent charges.</description>
		<content:encoded><![CDATA[<p>There are too many factors we&#8217;re not aware about to speculate. But if I were a member there with stored payment information, I&#8217;d be logging into online banking every day to watch for fraudulent charges.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Grossman</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2864270</link>
		<dc:creator>Dan Grossman</dc:creator>
		<pubDate>Sat, 18 Jul 2009 05:49:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2864270</guid>
		<description>Passwords &quot;encrypted&quot; with a poor hash function (which is not encryption at all) are just as good as plain text. Grab an md5 dictionary and if they have a password that generates the same hash as yours, they can log in to any other site using the same type of hash to &quot;encrypt&quot; your password... as you.</description>
		<content:encoded><![CDATA[<p>Passwords &#8220;encrypted&#8221; with a poor hash function (which is not encryption at all) are just as good as plain text. Grab an md5 dictionary and if they have a password that generates the same hash as yours, they can log in to any other site using the same type of hash to &#8220;encrypt&#8221; your password&#8230; as you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Grossman</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2864268</link>
		<dc:creator>Dan Grossman</dc:creator>
		<pubDate>Sat, 18 Jul 2009 05:46:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2864268</guid>
		<description>Why would you say such a thing?

I know a wonderful lawyer who taught the most interesting business law classes at university then gave me personal recommendations to grad school.

And another great lawyer who&#039;s a wonderful mother, balancing her home time and work as a lawyer, and recently defended a small site owner against a big company that wanted to take their domain for trademark infringement, when there was not even a semblence of similarity!</description>
		<content:encoded><![CDATA[<p>Why would you say such a thing?</p>
<p>I know a wonderful lawyer who taught the most interesting business law classes at university then gave me personal recommendations to grad school.</p>
<p>And another great lawyer who&#8217;s a wonderful mother, balancing her home time and work as a lawyer, and recently defended a small site owner against a big company that wanted to take their domain for trademark infringement, when there was not even a semblence of similarity!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Anderson</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2864255</link>
		<dc:creator>Paul Anderson</dc:creator>
		<pubDate>Sat, 18 Jul 2009 05:26:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2864255</guid>
		<description>I thing Elance sold the database...</description>
		<content:encoded><![CDATA[<p>I thing Elance sold the database&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Anderson</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2864254</link>
		<dc:creator>Paul Anderson</dc:creator>
		<pubDate>Sat, 18 Jul 2009 05:23:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2864254</guid>
		<description>I found the phones database of Elance...
Look to the twitter!

https://twitter.com/denparker
Download it - http://rapidshare.com/files/257056929/phones.zip.html</description>
		<content:encoded><![CDATA[<p>I found the phones database of Elance&#8230;<br />
Look to the twitter!</p>
<p><a href="https://twitter.com/denparker" rel="nofollow"></a><a href='https://twitter.com/denparker'>https://twitter.com/denparker</a><br />
Download it &#8211; <a href="http://rapidshare.com/files/257056929/phones.zip.html" rel="nofollow"></a><a href='http://rapidshare.com/files/257056929/phones.zip.html'>http://rapidsha...phones.zip.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stuart</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2864136</link>
		<dc:creator>Stuart</dc:creator>
		<pubDate>Sat, 18 Jul 2009 02:47:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2864136</guid>
		<description>@Shamit Khemka

&gt; even the passwords were encrypted so the 
&gt; theives cant do jack s**t with the data

Actually, they can indeed do s**t with the data.  And probably are doing s**t with it.

This topic is covered in most books on cryptography, but you can also read a very quick overview on wikipedia (see &quot;Password cracking&quot;).

Depending on their system design, it may not even require cryptanalysis to recover at least some of those passwords (e.g., if any of the hashes can be found in the variety of rainbow tables out there).

It is best to look at the vendor&#039;s claims of security with a wary eye.  In this case, I believe that Elance is understating the risk.  Consider your password on Elance to have been compromised and change it on any sites that you may have re-used that password on.</description>
		<content:encoded><![CDATA[<p>@Shamit Khemka</p>
<p>&gt; even the passwords were encrypted so the<br />
&gt; theives cant do jack s**t with the data</p>
<p>Actually, they can indeed do s**t with the data.  And probably are doing s**t with it.</p>
<p>This topic is covered in most books on cryptography, but you can also read a very quick overview on wikipedia (see &#8220;Password cracking&#8221;).</p>
<p>Depending on their system design, it may not even require cryptanalysis to recover at least some of those passwords (e.g., if any of the hashes can be found in the variety of rainbow tables out there).</p>
<p>It is best to look at the vendor&#8217;s claims of security with a wary eye.  In this case, I believe that Elance is understating the risk.  Consider your password on Elance to have been compromised and change it on any sites that you may have re-used that password on.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: shady</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2864128</link>
		<dc:creator>shady</dc:creator>
		<pubDate>Sat, 18 Jul 2009 02:40:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2864128</guid>
		<description>that&#039;s fun, OutsourcingRoom.com database comes not from elance - i know it for sure as i have used different emails for elance and scriptlance (sl was hacked on 4th and they have no balls to issue emails about it, they just switch off forum and keep silence), so basically OutsourcingRoom.com have data from sl database as they spaming me utilizing email dedicated to sl, not generic one i&#039;ve used for elance. 
heck it looks like a war, 2 freelance sites hacked within a month.</description>
		<content:encoded><![CDATA[<p>that&#8217;s fun, OutsourcingRoom.com database comes not from elance &#8211; i know it for sure as i have used different emails for elance and scriptlance (sl was hacked on 4th and they have no balls to issue emails about it, they just switch off forum and keep silence), so basically OutsourcingRoom.com have data from sl database as they spaming me utilizing email dedicated to sl, not generic one i&#8217;ve used for elance.<br />
heck it looks like a war, 2 freelance sites hacked within a month.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stuart</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2864114</link>
		<dc:creator>Stuart</dc:creator>
		<pubDate>Sat, 18 Jul 2009 02:31:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2864114</guid>
		<description>&gt; that contained protected versions of user 
&gt; passwords, in an unreadable format called a 
&gt; one-way hash.

The story evolves.  The site now says &quot;passwords were protected with encryption.&quot;

Maybe Elance is naive about encryption and password hashes.  Passwords that have been &quot;encrypted&quot; through a one-way hash are not necessarily &quot;secure&quot; -- There are a number of factors that affect how easy/difficult it is to recover the original passwords.  In the absence of additional information about their system design regarding password hashing methods, it is difficult to determine the risk.  However, it is interesting to note that Elance is requiring all users to change their passwords.  That is a veiled clue to users.  It would be helpful if Elance was more specific and to-the-point:

Elance users should consider their passwords to have been compromised.

If the password you used on Elance has been used on other web sites, your other web site accounts are at risk, and you should absolutely change your passwords on those sites, and strongly consider using unique passwords for each site [reference this weeks&#039; Twitter/TC debacle].</description>
		<content:encoded><![CDATA[<p>&gt; that contained protected versions of user<br />
&gt; passwords, in an unreadable format called a<br />
&gt; one-way hash.</p>
<p>The story evolves.  The site now says &#8220;passwords were protected with encryption.&#8221;</p>
<p>Maybe Elance is naive about encryption and password hashes.  Passwords that have been &#8220;encrypted&#8221; through a one-way hash are not necessarily &#8220;secure&#8221; &#8212; There are a number of factors that affect how easy/difficult it is to recover the original passwords.  In the absence of additional information about their system design regarding password hashing methods, it is difficult to determine the risk.  However, it is interesting to note that Elance is requiring all users to change their passwords.  That is a veiled clue to users.  It would be helpful if Elance was more specific and to-the-point:</p>
<p>Elance users should consider their passwords to have been compromised.</p>
<p>If the password you used on Elance has been used on other web sites, your other web site accounts are at risk, and you should absolutely change your passwords on those sites, and strongly consider using unique passwords for each site [reference this weeks' Twitter/TC debacle].</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bart</title>
		<link>http://www.techcrunch.com/2009/07/16/elance-hit-by-security-breach/comment-page-1/#comment-2864088</link>
		<dc:creator>Bart</dc:creator>
		<pubDate>Sat, 18 Jul 2009 02:09:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.techcrunch.com/?p=83967#comment-2864088</guid>
		<description>Just got that email actually, do you think there&#039;s no possibility of those hackers getting financial data?</description>
		<content:encoded><![CDATA[<p>Just got that email actually, do you think there&#8217;s no possibility of those hackers getting financial data?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
