Company Behind Foxit PDF Reader Announces Security Breach (zdnet.com) 17
An anonymous reader quotes a report from ZDNet: Foxit Software, the company behind the Foxit PDF reader app, said today that hackers breached its servers and have made off with some user information. ZDNet learned of the breach from a Foxit customer who shared a copy of the email the company is sending out to affected users, asking them to choose new passwords when logging in the next time.
According to this email, the security breach impacted the company's website, and, namely, information stored in the My Account section. Foxit web accounts are how the company manages its existing customers and is where users can access trial software, download purchased products, and access order histories. Foxit said hackers managed to access MyAccount data such as email addresses, passwords, real names, phone numbers, company names, and IP addresses from which users logged into their accounts. Due to the presence of IP addresses in the data hackers managed to access, this is believed to be a breach of Foxit's backend infrastructure, rather than a credential stuffing attack. The email did not mention if passwords were either hashed or salted. However, Foxit said it did invalidate all passwords for customers who it believed were impacted by the breach.
What's also unknown is when exactly the security incident took place. It could've happened this week, last month, or in previous years.
According to this email, the security breach impacted the company's website, and, namely, information stored in the My Account section. Foxit web accounts are how the company manages its existing customers and is where users can access trial software, download purchased products, and access order histories. Foxit said hackers managed to access MyAccount data such as email addresses, passwords, real names, phone numbers, company names, and IP addresses from which users logged into their accounts. Due to the presence of IP addresses in the data hackers managed to access, this is believed to be a breach of Foxit's backend infrastructure, rather than a credential stuffing attack. The email did not mention if passwords were either hashed or salted. However, Foxit said it did invalidate all passwords for customers who it believed were impacted by the breach.
What's also unknown is when exactly the security incident took place. It could've happened this week, last month, or in previous years.
Do people still use Foxit (Score:2)
I loved Foxit it was a great reader on Windows, but with browsers supporting PDF surely it has lost its relevance. Adobe reader is not the nightmare it once was. I was going to mention Evince which I love as a PDF reader, but the windows version seems no more.
Re: (Score:1)
Yes, I still use Foxit. Better than some vuln exploited in the browser leaking shit.
Re: (Score:2)
Re: (Score:2)
Adobe reader is not the nightmare it once was.
It's still a nightmare, but Foxit has evolved and bloated to the point where it's just as bad. I remember when Foxit was a small, lightweight reader without all the bloat and vulns of Acrobat, but now it's just as slow, bloated, and buggy. There's lots of alternatives, I use STDU Viewer which loads and displays the document I want in less time than Bloatobat takes just to rummage around in its plugins before it's even started. Not saying it's the perfect viewer, just that bloated monstrosities like Acrob
"new passwords when logging in" (Score:4, Insightful)
Re: (Score:2)
Re: (Score:2)
Re: (Score:1)
read the summary. the website was hacked, not the reader itself
Re: (Score:2)
The question is, why does anyone need to log into a website just to download a PDF reader?
Re: (Score:1, Informative)
Because people are still using proprietary software. No idea why, really.
Re: (Score:2, Insightful)
Many scummy companies are doing this. I recently picked up a Bluetooth padlock because I saw it at the shop and it was only a few bucks, so I decided to check it out. Turns out that in order to use it you have to not only create an account on their server but the app for it *requires* all sorts of ridiculous permissions like network, contacts, location and camera just to run, and it has to be able to phone home every time you want to unlock the thing or it just won't unlock via Bluetooth (you're SOL if your
Re: (Score:2)
Will Not disuade me from Foxit as my defualt (Score:1)