• For more information on how to avoid pop-up ads and still support SkiTalk click HERE.

Garmin Ransomware attack?

Unpiste

Booting down
Skier
SkiTalk Supporter
Joined
Feb 15, 2016
Posts
587
Location
California
I've been trying to figure out the security impacts to end users. :huh: I should probably change my passwords for fun... I think my Garmin credentials can get people access to various newspapers, the Atlantic, a couple of libraries, and meal kit subscriptions? Lol
It's always a good idea to change any shared passwords.

Hopefully, if Garmin is doing everything right (and the password isn't guessable), no one will be able to figure out your password. Unfortunately we already know Garmin did at least one thing wrong.
 

RobSN

Out on the slopes
Skier
Joined
Nov 12, 2019
Posts
1,074
Location
Prescott Valley, AZ
Who were the dumb-asses that had stored passwords in plain text and didn't notice for like 5 years?
Dead right on that. My Garmin Connect password is one that I do use across sites that don't have financial data associated with them, but poo, poo, and thrice poo - now I have to go through all those sites changing the passwords. Bloody nuisance. My bigger worry is whether there are other sites that have damn fool recover your password questions that hackers might guess using information on Garmin Connect ...
 

tball

Unzipped
Skier
SkiTalk Supporter
Joined
Nov 12, 2015
Posts
4,371
Location
Denver, CO
Yup, just the email address. All the passwords are different. I'm taking small comfort in that.
Any idea of how they got into your Skype account if the passwords were different? Brute force?

Related, has there been confirmation Garmin stored user password in plain text or were easily decrypted?

I just confirmed my Garmin password is a strong computer-generated password. This is a great example of why it's crucial to use a password manager.

You can still upload files to Strava or Training Peaks manually.
DC Rainmaker has a nice post outlining how to upload workouts manually:

I'm afraid the longer this goes on, the longer it will go on.
 

Unpiste

Booting down
Skier
SkiTalk Supporter
Joined
Feb 15, 2016
Posts
587
Location
California
Dead right on that. My Garmin Connect password is one that I do use across sites that don't have financial data associated with them, but poo, poo, and thrice poo - now I have to go through all those sites changing the passwords. Bloody nuisance. My bigger worry is whether there are other sites that have damn fool recover your password questions that hackers might guess using information on Garmin Connect ...
This is why I hate security questions. (Especially United, which literally has about a dozen questions with a dozen or so preselected answers available for each.) Whenever possible, I just turn security questions into additional passwords by making the "answer" something nonsensical and completely unrelated to the question. (Even my United questions and answers are randomly selected.)

Unfortunately this requires near absolute trust in whatever method you use to keep track of passwords.


Related, has there been confirmation Garmin stored user password in plain text or were easily decrypted?

I don't think so. Though I think the more likely scenario, if any, would be that they were using a weak hash.
 
  • Like
Reactions: Ron

Pequenita

Making fresh tracks
Skier
Joined
Aug 5, 2017
Posts
1,625
I can't even truthfully answer half the security questions usually because they're so culturally skewed.
 

tball

Unzipped
Skier
SkiTalk Supporter
Joined
Nov 12, 2015
Posts
4,371
Location
Denver, CO
Connect is back up for me. Good for them. Hope they didn't pay the ransom.
 

Ron

Seeking the next best ski
SkiTalk Tester
Joined
Nov 8, 2015
Posts
9,282
Location
Steamboat Springs, Co


very interesting story. Anyone who tried to upload their Garmin over the past few days knows this. As of today, Monday, July 27th, the site is back up but I can't find any info on how this was resolved.
 
Thread Starter
TS
cantunamunch

cantunamunch

Meh
Skier
Joined
Nov 17, 2015
Posts
22,193
Location
Lukey's boat
Yeh, there's been a chat about it over here.


Also, I suspect you all in Colorado are on different servers. Witness:

Screenshot_20200727-112756.jpg
 
Last edited:
  • Like
Reactions: Ron

Ron

Seeking the next best ski
SkiTalk Tester
Joined
Nov 8, 2015
Posts
9,282
Location
Steamboat Springs, Co
Yup, just the email address. All the passwords are different. I'm taking small comfort in that.

Just changed my password. In CO the servers are back up.

The joy of MAC, generates secure passwords and then stores them for use across all devices.

@Unpiste I started doing the same thing a few years back. my mothers maiden name, first car I owned and dogs name are totally disconnected from any semblance to the question.
 

crgildart

Gravity Slave
Skier
Joined
Nov 12, 2015
Posts
16,497
Location
The Bull City
@Unpiste I started doing the same thing a few years back. my mothers maiden name, first car I owned and dogs name are totally disconnected from any semblance to the question.

But using the same nonsense answer across different accounts/places is also not good. Need different answers to the same questions to prevent a hacker from using one to access the others..
 

Unpiste

Booting down
Skier
SkiTalk Supporter
Joined
Feb 15, 2016
Posts
587
Location
California
But using the same nonsense answer across different accounts/places is also not good. Need different answers to the same questions to prevent a hacker from using one to access the others..
Unfortunately more so even than with passwords, since security question answers can usually be read, unlike passwords. (Phone support is usually able to see the answer when they ask you one of your security questions.)
 
  • Like
Reactions: Ron

Sponsor

Top