12306 user data leak off the security of the offline robbery ticket is questioned

Source: Internet
Author: User
Keywords passwords security Mass 12306
Today, the vulnerability report platform clouds released a "high" hazard level vulnerability report said 12306 of the user data a large number of leaks, causing many netizens worry, have landed 12306 change password. And in response to the crisis, 12306 through micro-letter and other channels issued a notice said, "has been carefully audited, the disclosure of information all contain the user plaintext password." I site database all user passwords are multiple encryption of the non-plaintext conversion code, the Internet leaked user information through other websites or channels outflow. At present, the public security organs have been involved in investigation. "After the announcement, the third party grabbed the ticket software instantly became the focus of attention, triggered a lot of users guess, even for security considerations no longer use." In this respect, network security experts said that a large number of users of the database leak, mainly because the user data is centralized on a server or a cloud system, and the browser based on the ticket software for users to login convenience, will prompt the user whether to save the login username and password, and automatically upload the server to store the user's 12306 account information, so can not rule out the leak is a third-party robbery software caused by the ticket. It is understood that the current Third-party grab ticket software is mostly browser, and very browser for some reason most of the use of plaintext password storage, because the browser needs to password and other user information uploaded to the server or cloud, which causes if the software provider of the server or the system is hacked, the user database will be leaked, As a result, a large number of user privacy data leaked serious problems. In addition, this year also appeared offline ticket-grabbing, users not only need to submit 12306 user names and passwords, but also to provide their own identity card information and mobile phone number and other privacy information, and this information is leaked will cause more serious consequences. According to the reporter investigation, the current third party grab ticket software, in addition to Baidu guards Rob ticket treasure is the security client software, whether it is 360 or cheetah, these third-party grab ticket software is mostly based on the browser. In this respect, Baidu guards Rob ticket Bao related responsible person said, Baidu guards Rob ticket treasure itself is a security software, the user's key data are kept in the local, that is, the user's computer, does not have the cloud synchronization function, so there will be no user 12306 accounts, passwords, identity cards and other sensitive information collection and leakage of the problem. At present, the progress of the situation is still in the attention stage. But also here to remind everyone, to rob ticket success more to pay attention to safety, as soon as possible to amend the 12306 password, has been booked, wary of their own votes by others malicious return. If 12306 of the password is their own common password, also pay attention to the prevention of other important account. (Source: Southern Network)
Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.