HipChat has reset all its users’ passwords after what it called a security incident that may have exposed their names, email addresses and hashed password information.
In some cases, attackers may have accessed messages and content in chat rooms, HipChat said in a Monday blog post. But this happened in no more than 0.05 percent of the cases, each of which involved a domain URL, such as company.hipchat.com.
HipChat didn’t say how many users may have been affected by the incident. The passwords that may have been exposed would also be difficult to crack, the company said. The data is hashed, or obscured, with the bcrypt algorithm, which transforms the passwords into a set of random-looking characters. For added security, HipChat “salted” each password with a random value before hashing it.
Source: NW Security 1