Author Topic: Digi-key password update  (Read 8193 times)

0 Members and 1 Guest are viewing this topic.

Offline Psi

  • Super Contributor
  • ***
  • Posts: 10014
  • Country: nz
Re: Digi-key password update
« Reply #25 on: July 28, 2019, 01:11:27 pm »
I've not got an email yet, but it did forced me to change password when i tried to login today.

Also about 1 week ago i had weirdness happen with digikey. I actually made a thread on here but no one commented.

I ordered something and it never shipped.
The online chat system wouldn't work when i tried to contact them to see why.
I tried for a few days but same issue with online chat not working.

So i emailed them and didn't hear back at all.
But a day after that i logged in to check order history and noticed that the order had just shipped.
It had not shipped in the usual way that triggers emails and stuff and didn't show tracking info in usual place.

I clicked on the invoice PDF to read that and it had a manually added comment.

"21-JUL-2019 16:49 AA0AF RECD EMAIL FROM <NAME> CKING STATUS. IT APPEARS THIS ORDER PIGGY BACKED I WILL CK REPORT ON 7/22. ********** TRACKING NUMBER IS... "

I wonder what 'order piggy backed' might mean?
Greek letter 'Psi' (not Pounds per Square Inch)
 

Offline digsys

  • Supporter
  • ****
  • Posts: 2209
  • Country: au
    • DIGSYS
Re: Digi-key password update
« Reply #26 on: July 28, 2019, 02:30:26 pm »
AHHHH CRAP ! Just tried it myself after reading all this, and got the same ... entered new p/word, froze, tried again later with new p/word .. and all good !! .. EXCEPT !!!!
The damn shopping cart I built up this last 2 weeks is ALL GONE !! CRAP ! Now I got to remember what I ordered ..... siiigh
Hello <tap> <tap> .. is this thing on?
 

Online ataradov

  • Super Contributor
  • ***
  • Posts: 11364
  • Country: us
    • Personal site
Re: Digi-key password update
« Reply #27 on: July 28, 2019, 04:44:33 pm »
Does that mean you couldn't login with the old password (and had to do forgot password), or that you logged in with the old password and then it forced you to choose a new password and wouldn't let you set it to the old password.
It recognized the old password on a normal login form, but then redirected to the password change from, which did not accept the regular password.

It is possible, of course that the normal login form had a redirect and all passwords were already nuked. But then why even ask for it in a password change form?

The whole process is broken and was handled very inappropriately, IMO.
Alex
 

Online SiliconWizard

  • Super Contributor
  • ***
  • Posts: 14651
  • Country: fr
Re: Digi-key password update
« Reply #28 on: July 28, 2019, 04:51:44 pm »
Got the email, didn't feel like changing my pw, tried to log in, it logged in but immediately asked to change my password before I could continue.
I changed it.
Then logged in with the new pw.
Then got a "page not redirected correctly" message from Firefox.

Being used to getting this kind of behavior occasionally in Firefox due to old cookies, I deleted all cookies related to Digikey and tried again.
It worked.
 

Offline IanJ

  • Supporter
  • ****
  • Posts: 1649
  • Country: scotland
  • Full time EE & Youtuber
    • IanJohnston.com
Re: Digi-key password update
« Reply #29 on: July 28, 2019, 04:53:38 pm »
UK, FireFox on Win10.

Got the email....ignored it (virtually never click on emails!) and tried to login normally.....got the "change password" form which I did and it worked fine.

Ian.
Ian Johnston - Original designer of the PDVS2mini || Author of the free WinGPIB app.
Website - www.ianjohnston.com
YT Channel (electronics repairs & projects): www.youtube.com/user/IanScottJohnston, Twitter (X): https://twitter.com/IanSJohnston
 

Offline apelly

  • Supporter
  • ****
  • Posts: 1061
  • Country: nz
  • Probe
Re: Digi-key password update
« Reply #30 on: July 29, 2019, 06:05:41 am »
I was trying to find the couple of earlier posts that said "At least they're helping" or something. From their Tc&Cs:
Quote from: DigiKey
Your username and password are referred to as your "Identification." Your Identification must be accurate, current, and complete, and you may not provide false information to Digi-Key or impersonate another individual or entity. You are solely responsible for keeping your Identification confidential. You agree that you and your authorized representatives will be the only users of your Identification, and that you will be solely responsible for all activities on the Site using your Identification.
https://www.digikey.co.nz/en/terms-and-conditions

They have no reason to care if your password is strong. I still reckon something caused them to panic.

Australia does have mandatory disclosure rules, but I don't know if they're in effect yet, or how they work.

We'll see, I guess.
« Last Edit: July 29, 2019, 06:08:24 am by apelly »
 

Offline lowimpedance

  • Super Contributor
  • ***
  • Posts: 1249
  • Country: au
  • Watts in an ohm?
Re: Digi-key password update
« Reply #31 on: July 29, 2019, 06:45:24 am »
AHHHH CRAP ! Just tried it myself after reading all this, and got the same ... entered new p/word, froze, tried again later with new p/word .. and all good !! .. EXCEPT !!!!
The damn shopping cart I built up this last 2 weeks is ALL GONE !! CRAP ! Now I got to remember what I ordered ..... siiigh

 I was able to 'resume cart' on a part I had in my shopping cart before the password reset.
Go to your orders status and history and you should see the last cart pending, clicking on the web ID will give a box where you can resume the cart or delete it etc.
The odd multimeter or 2 or 3 or 4...or........can't remember !.
 

Offline digsys

  • Supporter
  • ****
  • Posts: 2209
  • Country: au
    • DIGSYS
Re: Digi-key password update
« Reply #32 on: July 29, 2019, 09:54:43 am »
Quote from: lowimpedance
  I was able to 'resume cart' on a part I had in my shopping cart before the password reset.
Go to your orders status and history and you should see the last cart pending, clicking on the web ID will give a box where you can resume the cart or delete it etc.
Ahh yep. Well aware of that, been using DigiKey for years. The last cart was empty. Maybe, they did a roll-back, and I was just unlucky. They definitely seemed to have screwed something up.
Hello <tap> <tap> .. is this thing on?
 

Offline rbm

  • Regular Contributor
  • *
  • Posts: 230
  • Country: ca
Re: Digi-key password update
« Reply #33 on: July 29, 2019, 10:33:58 am »
I also got the same notification and attempted a login whereupon I was forced to change my password.  I noticed that the site which accepts credentials and authenticates them is different than what I have stored in my password manager.  So, I believe the update that Digikey performed changed the authentication mechanism.  That would explain the request for password change.  I don't believe it to be a result of a hack or pen test finding; more likely it's a change to federated login because the country specific nature of the login mechanism that Digikey used before is now gone (i.e. I used to authenticate to www.digikey.ca and now I authenticate to auth.digikey.com).
« Last Edit: July 29, 2019, 10:38:55 am by rbm »
- Robert
 

Offline digsys

  • Supporter
  • ****
  • Posts: 2209
  • Country: au
    • DIGSYS
Re: Digi-key password update
« Reply #34 on: July 29, 2019, 11:49:37 am »
Quote from: rbm
... I don't believe it to be a result of a hack or pen test finding; more likely it's a change to federated login because the country specific nature of the login mechanism that Digikey used before is now gone (i.e. I used to authenticate to www.digikey.ca and now I authenticate to  auth.digikey.com).
Fair enough, definitely seems the most likely  .. beats me as to where my basket went ... maybe I'm getting old faster than I thought :-)
Edit: Just checked again and it's back ??? I did delete cookies first ... unsure why that'd be why??? All good again, move along :-)
Edit2: <sheepish grin> ok, found the culprit. I have a few accounts on the login page .. for different contracts / tax groups. After reading the first posts, and expecting a breach, I selected the "wrong" account .. which btw isn't indicated once you're logged in. oops
« Last Edit: July 30, 2019, 12:06:08 am by digsys »
Hello <tap> <tap> .. is this thing on?
 

Offline T3sl4co1l

  • Super Contributor
  • ***
  • Posts: 21828
  • Country: us
  • Expert, Analog Electronics, PCB Layout, EMC
    • Seven Transistor Labs
Re: Digi-key password update
« Reply #35 on: July 29, 2019, 11:29:48 pm »
Worked fine here.

Tim
Seven Transistor Labs, LLC
Electronic design, from concept to prototype.
Bringing a project to life?  Send me a message!
 

Offline Andreas

  • Super Contributor
  • ***
  • Posts: 3271
  • Country: de
Re: Digi-key password update
« Reply #36 on: July 30, 2019, 04:54:12 am »
Got the email....ignored it (virtually never click on emails!) and tried to login normally.....got the "change password" form which I did and it worked fine.

The same here in DE.

With best regards

Andreas
 

Offline MrBlueJones

  • Newbie
  • Posts: 1
  • Country: tw
Re: Digi-key password update
« Reply #37 on: August 09, 2019, 04:29:00 pm »
Although I did not lose nor use my credit card in the last few weeks, someone managed to take of my card 8000 USD.
This credit card is also stored on the Digikey website.
When today I want to order a few components, I am forced to reset my password. But it did not (or did not want to) recognize my old password that I was using for years. I had to use the 'password reset' feature.
Anybody else who got surprise bills from Visa who also have their creditcard info on Digi-Key webiste?
I suspect their website has been hacked and sensitive information leaked. Why would they otherwise force all users (apparently) to reset their passwords?
 

Offline wrljet

  • Newbie
  • Posts: 2
  • Country: us
Re: Digi-key password update
« Reply #38 on: August 11, 2019, 08:40:43 pm »
I got the email, too, and thought it might be a scam.
Went to Digi-Key website using my old bookmark and tried to log in.

It said I needed to change the password before it ever let me in.
And it refuses to accept any password I've tried as meeting their requirements.

 

Offline orion242

  • Supporter
  • ****
  • Posts: 746
  • Country: us
Re: Digi-key password update
« Reply #39 on: August 12, 2019, 12:31:04 pm »
Their site has been down all weekend and still DOA now.

??

Withdraws from their parametric search starting to set in.
 

Offline Bud

  • Super Contributor
  • ***
  • Posts: 6947
  • Country: ca
Re: Digi-key password update
« Reply #40 on: August 12, 2019, 01:01:01 pm »
Why would they otherwise force all users (apparently) to reset their passwords?
It may happen in normal course of business depending on how a company stores users passwords. One of the ways is to store not passwords themselves, be it encrypted, but hash of the password. Hash is theoretically one way function, i.e. passwords cant be recovered from hash. However this creates a problem when the company needs to change password protection scheme , i.e. to a stronger hash function, or perform system upgrades that require re-encrypting the password database. Guess what, you cant re-calculate new hash from the existing one, so the only way is to force customers to create new passwords. I've seen it numerous times back in my work in IT.
Facebook-free life and Rigol-free shack.
 
The following users thanked this post: rs20

Offline madires

  • Super Contributor
  • ***
  • Posts: 7859
  • Country: de
  • A qualified hobbyist ;)
Re: Digi-key password update
« Reply #41 on: August 12, 2019, 01:37:19 pm »
What I consider a tad strange or unprofessional is the issue with the old password. It was accepted by the standard login, but not by the PW change form which followed immediately after the login. Some didn't have this problem, some did and were forced to reset their old PW. In most cases it's possible to detect the hashing method from the stored hash and that method would be used to verify the user's old PW. This way a smooth transition to a new hashing algorithm is straight forward and doesn't break anything.
 

Offline Bud

  • Super Contributor
  • ***
  • Posts: 6947
  • Country: ca
Re: Digi-key password update
« Reply #42 on: August 12, 2019, 01:55:29 pm »
Mostly true and is a good intent but depends on the infrastructure and details of implementation. In many cases it can only be "Either Or" and not feasible to run in parallel old and new systems. As usual, the evil is in the details.
Facebook-free life and Rigol-free shack.
 

Offline rbm

  • Regular Contributor
  • *
  • Posts: 230
  • Country: ca
Re: Digi-key password update
« Reply #43 on: August 15, 2019, 10:35:48 pm »
Although I did not lose nor use my credit card in the last few weeks, someone managed to take of my card 8000 USD.
This credit card is also stored on the Digikey website.
That's speculation.  It is quite possible your account information was compromised long ago at some place other than Digikey and only recently has it been sold, and fraudulently used.  It is a falsehood that people believe the last place they used their card was the place where it was compromised.  There's many ways your account details could have been exposed without you being aware of it (or the merchant whose system was compromised where you used your card).
- Robert
 

Offline wrljet

  • Newbie
  • Posts: 2
  • Country: us
Re: Digi-key password update
« Reply #44 on: August 16, 2019, 02:33:53 pm »
I finally managed to get back in, after a lot of swearing.

It turned out I had used part of a common dictionary word in the new passwd, and that is no longer allowed.
I suggested to their tech support they might explain the passwd minimum requirements on the actual form.
 
The following users thanked this post: grantb5

Offline bombledmonk

  • Regular Contributor
  • *
  • Posts: 90
  • Country: us
Re: Digi-key password update
« Reply #45 on: August 22, 2019, 05:30:32 pm »
I know there's been lots of speculation on here and this is a delayed response, but this was part of a part of a year+ long project to upgrade the authentication system.  It was not in response to a breach, just a symptom of switching the system storing passwords and a suboptimal communication plan. 

Offline jmelson

  • Super Contributor
  • ***
  • Posts: 2777
  • Country: us
Re: Digi-key password update
« Reply #46 on: August 22, 2019, 07:31:48 pm »
It turned out I had used part of a common dictionary word in the new passwd, and that is no longer allowed.
I suggested to their tech support they might explain the passwd minimum requirements on the actual form.
Yeah, the way things are going, sites in general are going to require a 256-character password, it must contain all ASCII characters at least once, must not contain any words in any human language, and be changed daily!

Jon
 

Offline rbm

  • Regular Contributor
  • *
  • Posts: 230
  • Country: ca
Re: Digi-key password update
« Reply #47 on: August 23, 2019, 06:51:09 am »
Better to have multi-factor authentication (MFA) and thwart the problems with single factor password auth.  Problem is that there is no universal standard for MFA, which ends up being a PITA for end-users.
- Robert
 

Offline 3roomlab

  • Frequent Contributor
  • **
  • Posts: 828
  • Country: 00
Re: Digi-key password update
« Reply #48 on: September 04, 2019, 07:49:56 am »
o my

i could see octopart, mouser, RS etc etc

but ...
digikey is down?
 

Online PA0PBZ

  • Super Contributor
  • ***
  • Posts: 5143
  • Country: nl
Re: Digi-key password update
« Reply #49 on: September 04, 2019, 08:07:32 am »
digikey is down?

No problem here, what happens if you just try 204.221.76.76 ?
Keyboard error: Press F1 to continue.
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf