Mozilla Store Suffers Breach

One of the most visible ways to show your love for Firefox and all things Mozilla — at least in the offline world — is by sporting some of the wide range of Mozilla swag. The primary source of those items, however, is unavailable today, after the organization's online store was hit by a security breach.

According to a posting on The Mozilla Blog, Mozilla learned yesterday that the company operating the organization's U.S. storeGatewayCDI — experienced a security breach. Mozilla immediately closed the shop as a precaution, and although it is run by a different group, closed the International Mozilla Store as well. Current visitors to either shop receive the message that "The Mozilla Store has been closed for maintenance."

According to Mozilla's post, an investigation is under way to determine the cause and extent of the break-in — the organization has committed not to reopen the shop until concerns about privacy and security can be assuaged. The International Store will presumably undergo a precautionary audit and, given that it is operated by a separate entity, be reinstated on its own schedule. The Mozilla Community Store, which — as its name suggests — sells merchandise created by members of the Mozilla community, is operated by a third unrelated company, and remains open.

According to Mozilla, they encouraged GatewayCDI to immediately contact affected customers directly to advise them of the issue and potential consequences. Interestingly, though the breach was discovered and disclosed yesterday, at least some customers — your editor included — were not notified of the incident by GatewayCDI until late this afternoon.

According to their emailed notice, GatewayCDI doesn't believe any credit card data was compromised in the attack, but has confirmed that at least some customer's usernames and passwords were breached. Notified users are strongly encouraged to change their username/password as a precaution — users would do well to do so for all their Mozilla-related accounts, particularly if they use the same username/password in multiple places. Though it is currently impossible to do so as the site is offline, the company indicated it will notify users when the store is operational again — hopefully without waiting twenty-four hours or more to do so.

______________________

Justin Ryan is a Contributing Editor for Linux Journal.

Webcast
How to Build an Optimal Hadoop Cluster to Store and Maintain Unlimited Amounts of Data Using Microservers

Realizing the promise of Apache® Hadoop® requires the effective deployment of compute, memory, storage and networking to achieve optimal results. With its flexibility and multitude of options, it is easy to over or under provision the server infrastructure, resulting in poor performance and high TCO. Join us for an in depth, technical discussion with industry experts from leading Hadoop and server companies who will provide insights into the key considerations for designing and deploying an optimal Hadoop cluster.

Learn More

Sponsored by AMD

White Paper
Private PaaS for the Agile Enterprise

If you already use virtualized infrastructure, you are well on your way to leveraging the power of the cloud. Virtualization offers the promise of limitless resources, but how do you manage that scalability when your DevOps team doesn’t scale? In today’s hypercompetitive markets, fast results can make a difference between leading the pack vs. obsolescence. Organizations need more benefits from cloud computing than just raw resources. They need agility, flexibility, convenience, ROI, and control.

Stackato private Platform-as-a-Service technology from ActiveState extends your private cloud infrastructure by creating a private PaaS to provide on-demand availability, flexibility, control, and ultimately, faster time-to-market for your enterprise.

Learn More

Sponsored by ActiveState