Free shipping on orders over ¥5,000 Shop more >

[3D Printing Applications] Will Data Breach End the Thingsverse? Event Summary

3DMART |

[3D Printing Applications] Will Data Breach End Thingiverse? Thingiverse Summary

The Thingiverse platform from 3D printer manufacturer Makerbot was one of the first platforms to pioneer the sharing of 3D printed models. Since 2008, the site has offered more than 2 million free models and has consistently ranked first on the list of most popular 3D printed model platforms for many years.

The Thingiverse data breach in October 2021 exposed the private data of 228,000 users. Reports indicate that the Thingiverse data breach affected 228,000 accounts and exposed user data such as names, dates of birth, physical addresses, IP addresses, and encrypted passwords. This incident suggests that we should perhaps change these login details regularly.

A report by data breach notification service provider "Have I Being Pwned" states that Thingiverse's database, containing users' email addresses and personal information, was leaked as early as October 2020. Although this information had been circulating online for over a year, the data breach notification service provider only discovered evidence of Thingiverse's hacking in October 2021, by which time this information had already been widely circulating in the hacker community for some time.

Thigiverse responded to the incident on Twitter, claiming that fewer than 500 users were affected by the violation of using non-sensitive data, and that affected users have been notified.

However, data breach reports indicate that this is not the case. Many users who did not receive such notifications confirmed that they were part of a hacking incident. Users expressed frustration with Thingiverse and MakerBot for failing to protect their data, and were disappointed by the lack of remedial measures and the downplaying of the incident.

This isn't the first time Thingiverse has proven to be a vulnerable website. In early 2018, it was revealed that some users inadvertently mined cryptocurrency through embedded code in the model review section while browsing the platform. At the time, MakerBot claimed they had fixed this security flaw, so Thingiverse users didn't need to worry about data breaches or take additional measures to protect their computers. Thingiverse claimed they had banned violators, but the latest hack has proven otherwise.

Given the website's poor response to the second attack, many 3D printing creators called for people to leave Thingiverse, some users decided to delete their accounts because of the incident, and some artists also migrated their work to other 3D modeling platforms.

The Thingiverse hack caused a stir for two weeks until October 14, 2021, when MakerBot sent a spokesperson to issue the following statement.
"We have recognized and resolved the internal human error that led to the exposure of some non-sensitive user data by a small number of Thingiverse users. However, we have not found any suspicious Thingiverse accounts. We encourage Thingiverse users to update their passwords as a preventative measure to protect their privacy. We apologize for this incident and feel sorry for all the affected users. We are committed to protecting the valuable rights and assets of those involved through transparent and rigorous security management."

Did you enjoy this sharing? What are your thoughts on the privacy and security disaster at Thingiverse? Whether this latest breach will shake the site's position as the premier 3D modeling platform remains to be seen. Sandimar offers more than just 3D printing ; contact us today to learn more about our contract manufacturing services .

References
References