I know there have been many of these threads on here, complaining about the hack, but has anything actually been done?
Is there anything that can actually be done apart from just finding another ISP?
I understand that IndigoVision is the one responsible for the breach, but i feel Crystal Web has not communicated how serious the hack actually was. In the list i'm looking at there are over 5000 Name, Email and Password combinations. Most of the passwords were auto-generated and therefore unique to Crystal web, but there are many passwords which are set by the user and could be shared with other accounts online (yes this is not the best personal security practice but not everyone is tech savvy.)
I believe Crystal Web has lied to their customers by saying no sensitive information has been leaked and they should inform all their customers who had custom set passwords to make sure that no other accounts online use the same email and password combination. I searched the list for my friends and saw their password which I know they use to log into their main email accounts. (and as most of you know if someone gains access to someone’s main email account they can then possible get banking details or other sensitive account details.)
further to this, why after being hacked and promising to focus on security do they then send my password as plain-text to my email address? How can they be hashing the password correctly if it is available in plain-text to send to me?
I am tempted to email everyone on the list and inform them to change their password.
What else can be done?
Is there anything that can actually be done apart from just finding another ISP?
I understand that IndigoVision is the one responsible for the breach, but i feel Crystal Web has not communicated how serious the hack actually was. In the list i'm looking at there are over 5000 Name, Email and Password combinations. Most of the passwords were auto-generated and therefore unique to Crystal web, but there are many passwords which are set by the user and could be shared with other accounts online (yes this is not the best personal security practice but not everyone is tech savvy.)
I believe Crystal Web has lied to their customers by saying no sensitive information has been leaked and they should inform all their customers who had custom set passwords to make sure that no other accounts online use the same email and password combination. I searched the list for my friends and saw their password which I know they use to log into their main email accounts. (and as most of you know if someone gains access to someone’s main email account they can then possible get banking details or other sensitive account details.)
further to this, why after being hacked and promising to focus on security do they then send my password as plain-text to my email address? How can they be hashing the password correctly if it is available in plain-text to send to me?
I am tempted to email everyone on the list and inform them to change their password.
What else can be done?