Amazon Forces Password Reset For Some Users - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
IoT
Software // Information Management
Commentary
11/26/2015
11:06 AM
Larry Loeb
Larry Loeb
Commentary
50%
50%

Amazon Forces Password Reset For Some Users

Amazon told an unknown number of customers that their passwords could have been potentially exposed to a third party, but claimed it has corrected the issue.

8 iPhone Security Apps To Keep Your Data Safe
8 iPhone Security Apps To Keep Your Data Safe
(Click image for larger view and slideshow.)

In time for the busiest online shopping season of the year, Amazon has forced the reset of a number of user passwords because of a security concern, according to a ZDNet report.

The email sent to affected users in the US and UK said that Amazon had "recently discovered that your [Amazon] password may have been improperly stored on your device or transmitted to Amazon in a way that could potentially expose it to a third party. We have corrected the issue to prevent this exposure," according to ZDNet. The email added that there was "no reason" to think that a breach had occurred, but the company was issuing a temporary password out of an "abundance of caution."

The report also noted since the emails were sent to users' account message center on Amazon.com and Amazon.co.uk, the messages are authentic.

(Image: Tuomas Kujansuu/iStockphoto)

(Image: Tuomas Kujansuu/iStockphoto)

This concern from Amazon indicates that it would be prudent to reset your Amazon password, even if the email has not been sent to you

The e-commerce giant recently added two-factor authentication for US customers. Perhaps the reasons behind the email sent to affected users sped up the decision to make that new authorization service active.

Amazon has not yet responded for requests for comments on this story.

This type of incident is nothing new to Amazon, which has sent out similar force-reset password emails to affected users in the past, with some cases dating back to 2010.

[ Read Comcast Resets 200,000 Compromised Email Passwords, But Questions Remain. ]

Keith Graham, the CTO of SecureAuth, which sells its access control products to major enterprise customers and has a technology partner relationship with Amazon Web Services, told InformationWeek in an email that, "Amazon force-resetting some of its users' accounts due to fears of a password leak is yet another indication organizations need an innovative approach to authentication that goes beyond the traditional username and password tactic."

Graham added, "While the early days of cumbersome two-factor authentication cast a shadow on the technology, times have very much changed for the better. Advances in adaptive authentication have brought to market a number of options that help users stay both secure and productive by layering multiple methods, such as device recognition, analysis of the physical location of the user, or even by using behavioral biometrics to continually verify the true identity of the end user. By layering adaptive authentication techniques, organizations like Amazon can further strengthen their defenses against cyber adversaries."

**New deadline of Dec. 18, 2015** Be a part of the prestigious InformationWeek Elite 100! Time is running out to submit your company's application by Dec. 18, 2015. Go to our 2016 registration page: InformationWeek's Elite 100 list for 2016.

Larry Loeb has written for many of the last century's major "dead tree" computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek. He has written a book on the Secure Electronic Transaction Internet ... View Full Bio
We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
larryloeb
50%
50%
larryloeb,
User Rank: Author
11/30/2015 | 11:06:24 AM
Re: Re
I personally like to hunt them down and destroy their hardware with an axe.

But, that's just me.

<g>
larryloeb
50%
50%
larryloeb,
User Rank: Author
11/30/2015 | 10:56:53 AM
Re: Re
Yes, I agree with your last sentence. it makes it harder to gain entry.
larryloeb
50%
50%
larryloeb,
User Rank: Author
11/30/2015 | 10:39:13 AM
Re: Re
Ok but that allows a mitm with the carrier as the point of failure. Like if a Stingray device was in use. Not that it's likely you understand, but possible. I just don't think any security method can always be relied on, even something like MFA
larryloeb
50%
50%
larryloeb,
User Rank: Author
11/30/2015 | 9:54:32 AM
Re: Re
Sure if they have a device that can use something like Google Authentcator. The problem is that not everyone has such a device.
larryloeb
50%
50%
larryloeb,
User Rank: Author
11/30/2015 | 9:08:05 AM
Re: Re
Yes a good idea as well
larryloeb
50%
50%
larryloeb,
User Rank: Author
11/27/2015 | 7:23:47 PM
Re: Re
That would be a very good idea.
InformationWeek Is Getting an Upgrade!

Find out more about our plans to improve the look, functionality, and performance of the InformationWeek site in the coming months.

Slideshows
11 Things IT Professionals Wish They Knew Earlier in Their Careers
Lisa Morgan, Freelance Writer,  4/6/2021
News
Time to Shift Your Job Search Out of Neutral
Jessica Davis, Senior Editor, Enterprise Apps,  3/31/2021
Commentary
Does Identity Hinder Hybrid-Cloud and Multi-Cloud Adoption?
Joao-Pierre S. Ruth, Senior Writer,  4/1/2021
White Papers
Register for InformationWeek Newsletters
Video
Current Issue
Successful Strategies for Digital Transformation
Download this report to learn about the latest technologies and best practices or ensuring a successful transition from outdated business transformation tactics.
Slideshows
Flash Poll