Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

See all MNHQ comments on this thread

3 social networking sites have been hacked and 8 million passwords published. So, I ask you MNHQ

32 replies

QuintessentialShadows · 07/06/2012 23:34

Are we safe?

Are you encrypting, are you salting and hashing, etc?

Are your algorythms up to scratch, and can you tango the hackers away?
Are we firewalled and ringfenced, or are we in a bell tent in a gale?

I would hate to see Justine make announcements such as LinkedIn and Eharmony, and Last.fm has had to do.....

OP posts:
New posts on this thread. Refresh page
QuintessentialShadows · 08/06/2012 15:20

Dating site eharmony and last.fm. Last.fm has said that they will NOT email out instructions, members should visit their blog for instructions.

OP posts:
Harr1etJ0nes · 08/06/2012 13:51

Where else has been hacked then?

QuintessentialShadows · 08/06/2012 11:17

For those of you using LinkedIn, Scammers are now sending fake emails purporting to be from linked in. Be careful before you click any linked in, scrutinize the email sender, etc.

LinkedIn released a statement saying they would send emails out to all the users whose security was breached, with instructions how to reset their passwords.

Surprise surprise, some people are now literally "flooded" by emails from linkedin, taking you to sites where you can buy viagra, etc. The problem of course is that when you click the links, you think "ah viagra, this was a spoof", but there might be a little script downloaded to your computer which will register your pc with a botnet. SO as always, be vigilant.

End of Customer Services Announcement.

OP posts:
tharsheblows · 08/06/2012 10:58

Snorbs, it's in your registration details.

Increasingly I rely on passphrases - am saying this so I can link to the xkcd comic here. You can make them so they're effectively unhackable by brute force methods.

Snorbs · 08/06/2012 10:53

Yikes! So rather than simply using hashes, you're either using reversible encryption (not a good idea for passwords) or you're simply storing passwords in plaintext (really not a good idea for passwords).

Either way, that's an, um, brave design decision. Bordering on the courageous in fact.

Good luck with the "let's make sure we follow industry best practises for security" project!

Tech · 08/06/2012 09:49

Yes that is possible.

Snorbs · 08/06/2012 09:45

At present your passwords are retrievable (by you) but we will change that over the next week or so to add another level of protection.

Sorry, are you really suggesting that it's possible for me to retrieve my password from mumsnet? Ie, not just a link to reset it, but to actually see what the password is?

BIWItheBold · 08/06/2012 09:33

.... but I have changed my password, anyway

BIWItheBold · 08/06/2012 09:32

Hmm - yes, they could also access my Twitter account I suppose. Good luck with that one!

Tech · 08/06/2012 09:29

Hi Biwi, one potential problem is that lots of people use the same password for the lots of accounts (kids names anyone?) So people who have access to your email address and linked in password from linked in will probably try those details to log in to various other places including your email itself.

FormerlyTitledUntidy · 08/06/2012 09:26

Told you they'd send Tech :)

BIWItheBold · 08/06/2012 09:22

I'm a bit bemused as to how useful my Linked-in account might actually be to someone, unless they are especially interested in my qualifications and what books I'm reading right now!

Trills · 08/06/2012 09:20

That's right. :) Well done.

Tech · 08/06/2012 09:18

Hi, A couple of things: Our downtime last night was because of an ongoing capacity issue which we are working on fixing. It wasn't anything more sinister than that.

As regards the other points, our servers are in secure data centres behind firewalls and with constant monitoring against intrusion and attack. We have an ongoing project to ensure we are in compliance with industry "best practises" around data security. At present your passwords are retrievable (by you) but we will change that over the next week or so to add another level of protection.

Of course TSSDNCOP (is that right?) in detail, but please be assured this is something we take seriously.

Just to reiterate, for your own security, it's definitely worth using different passwords for your various online accounts. You definitely shouldn't use the same password for your email and your banking and your MN-ing. (You absolutely shouldn't re-use your email or bank passwords for anything else at all of course.)

If you want to change your MN password, you can use our reset link here.

Ladymuck · 08/06/2012 00:27

Not sure that my MN password is that much of an issue.

When MN first started the passwords were just your RL surname. Took us an alarmingly long time to realise that once we'd made RL contact with another MNer we could guess their password Grin.

FormerlyTitledUntidy · 08/06/2012 00:23

Well I have the same password for everything except banking and so does dp, so I'd be pretty fucked really. Have changed it now :)

QuintessentialShadows · 08/06/2012 00:18

I agree though. I only use my banking password for banking and nothing else, for example.

OP posts:
D0G · 08/06/2012 00:18

This reply has been deleted

Message withdrawn at poster's request.

tharsheblows · 08/06/2012 00:15

Oh shit, huge apologies for preachiness! I was something I was thinking about, so right there in my head.

tharsheblows · 08/06/2012 00:14

Generally it's a bad sign if you get your current password back (rather than a new password or a link to reset) when you do the "I forgot my password" thing.

And don't use the same password on sites that you think might be less secure as ou do on sites that you need not to be hacked. If someone hacked my mn account, they'd only be able to access a few other sites that I really don't care about. I mean that in the "being hacked would suck and might embarrass me but no real harm done" way. I know ideally to use a separate password on each site and I do for important stuff!

giraffesCantFitInThePalace · 08/06/2012 00:10

my password is cuntworms, no one will never guess that!

....oh.....oops! Wink

cocolepew · 08/06/2012 00:09
Northernlurker · 08/06/2012 00:08
cocolepew · 08/06/2012 00:05

One of the Linkedin passwords was I wish I was dead.

All the Mn ones will be fanjo, fruitshoot, Boden and norks.

TeamEdward · 08/06/2012 00:03

This reply has been deleted

Message withdrawn at poster's request.

Swipe left for the next trending thread