If you have signed in to StoreFeeder and been taken to a page headed Your password is not unique instead of straight to your dashboard, the password you use for StoreFeeder has been found in a public list of passwords exposed in previous data breaches.
What does this message mean?
This means your password has appeared somewhere in a public database of passwords leaked in past data breaches. The warning does not mean that StoreFeeder has been breached, and it does not mean that your StoreFeeder username and password combination has been leaked.
What we are checking is whether the password itself has previously appeared in lists of passwords obtained from data breaches across the internet.
For example, passwords such as:
* password
* password1
* arsenal
* password123
have appeared many times in previous breaches. If somebody used one of those passwords in StoreFeeder, we would warn them even if their StoreFeeder account had never been compromised.
The same applies to more complicated passwords. If the password you are using has appeared in a previous breach, it may simply mean that somebody else happened to use the same password on another website that was subsequently breached. There is no information linking that password back to your StoreFeeder account.
This is important because attackers build large lists of previously leaked and commonly used passwords and use them when attempting to gain access to other systems. A password that has appeared in one of these lists is therefore considered weaker, even if you personally have never shared it with anyone.
So to be clear, this warning is not the result of a StoreFeeder data breach and does not indicate that your StoreFeeder or customer data has been accessed.
Does StoreFeeder send my password to a third party?
StoreFeeder performs this check securely and does not send your passwordanywhere. The purpose of the warning is simply to highlight that the password is known to exist in breached password lists and recommend that you replace it with something unique.
What are my options?
You have two, and both are shown on the page:
- Change my password: takes you to the Change Password screen. Once you have set a new password, you carry on into StoreFeeder as normal. You will not be asked to sign in again.
- Skip for now: signs you in and takes you to your dashboard, exactly as before. The message will appear again the next time you sign in, until you change your password.
You are never locked out of your account. This is a recommendation, not a restriction.
How do I change the entered password to something else?
- On the Your password is not unique page, click Change my password.
- Enter your current password, then your new password twice.
- Click Submit.
- You will receive a confirmation email, and you will be returned to the part of StoreFeeder you were signing in to.
If you would rather come back to it later, you can change your password at any time from your user menu. If you have clicked Change my password but want to go back without changing it, use the Back link you will still be signed in.
Your new password must meet StoreFeeder’s password rules and cannot be a password you have used recently. It also cannot be a password that appears in the breach data if you choose one that does, it will be rejected and you will be asked to pick a different one.
Does this change how I sign in?
No. Everything else about signing in works exactly as it did before:
- If you use two-factor authentication, you will enter your authentication code first, as usual. The password message appears afterwards.
- Remember this device for 30 days still works in the same way.
- Password resets, account switching and signing out are unchanged.
Which users does this apply to?
All StoreFeeder users. Anyone whose password appears in the breach data will see the message, whichever account or permission level they use.
What should I use instead?
We strongly recommend changing your password if you see this message. When choosing a new one:
- Make it long, length matters more than symbols.
- Make it unique to StoreFeeder. Never reuse a password from another site.
- Avoid variations of an old password (for example adding a number or a
!to the end); if the original is in the breach data, the variation is one of the first things an attacker will try. - Consider using a password manager so you do not have to remember it.
If you use a shared or team login, change it once and let everyone who uses it know the new password or, better, ask your account administrator to set up individual logins.
If you see this message and are unable to change your password, or you are concerned that your account may have been accessed by someone else, contact StoreFeeder support straight away.
Comments
0 comments
Please sign in to leave a comment.