Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

See all MNHQ comments on this thread

Due to a security breach we are resetting all passwords across Mumsnet

729 replies

RebeccaMumsnet · 12/04/2014 17:32

Following the recent security breach related to Heartbleed we are reseting the passwords of all users.

On Saturday 12 April, we will remove all passwords from our system and to use the site, you'll need to reset your password by clicking on the password reset link.

Type in your email address and click the 'Request reset' button and you will receive a mail to your Mumsnet registered email account. (You will need to click on the link in the mail within 30 minutes of receiving it, without changing the device you're using i.e swapping from phone to laptop, or you'll need to request a further reset).

If you do not receive a mail, please check you spam folder. The password reset mail will come to the email you used when you first registered with Mumsnet.

If you don't receive or can't access your reset mail, please [email protected] for help.

We are very sorry for all the fuss. We want to assure you that we followed all the published steps to protect members' security as soon as we became aware of the heartbleed security risk, but it seems that the breach occurred prior to that risk becoming known.

Most importantly, if you use the same password here as elsewhere, we strongly recommend you change your password on the other sites too.

Thanks,

Justine & the MNHQ team

OP posts:
Heartbleed · 17/04/2014 01:36

doors*

Heartbleed · 17/04/2014 01:36

I did suggest KeePassX as an opensource alternative. But I guess you have a point.

So we will use KeePassX for now. Firstly the password you use as your key for the database file will not be stored in plain text. It will be hashed and salted and only the hash sum with the salt will be stored and used to check if the password you enter is correct.

As for keyloggers. On the physical side just make sure that you have good physical security on your home and drros which lead to your computer. If you are feeling really causious, check all ports for any keyloggers before you boot up. As for software keyloggers, ensure that your OS is upto date, and that any ant-virus/malware programs you have are always kept up to date and you do regular scans.

The encryption that programs such as KeePass use has been vetted by cryptographers and hs proven to be strong.

But on a note about LastPass. Here is a goof page about it along with a great video by a HIGHLY rewnowned security expert talking about LastPass: blog.lastpass.com/2010/07/lastpass-gets-green-light-from-security.html

confuddledDOTcom · 17/04/2014 01:21

I like what RoM does (not a player but know people who do) they have an onscreen keyboard and recommend you use a combo of keystrokes and clicking the onscreen keys to enter your password.

Also like my Blizz authenticator.

Some of my gamer friends type their password in wrong and then use the mouse to correct it so psswrd and you click back to make it Password1. Helps with keylogging at least.

RStallman · 17/04/2014 01:10

It doesn't matter how complex the password is when it gets leaked in plaintext or obtained via keylogger. There were plenty of people running WPA with 64 character long passwords who were surprised by the WPS sidechannel attack, which rendered password strength useless. Having one password to act as a skeleton key to open all doors could be very dangerous in the wrong situation. And I won't even start at how ridiculous recommending closed source encryption software is.

It is too late for this conversation, you can continue it without me. My bed calls.

Heartbleed · 17/04/2014 00:56

I am not the attacker, nor am I trying to pretend to be him. I am just someone who is interested in netsec.

True, it is a single point of failure. But that is if it fails. If you use a sufficently strong password to encrypt the database then you will be fine. If you are unsure about LastPass's closed source nature, try KeePassX. Same thing (little less usability, not a good browser implementation) but open source so you can have more confidance that the actual manager is secure.

But, the encryption standards LastPass uses for it's database is strong, throurley tested in the industry and implemented well. As I said before. Use a strong passphrase (see link on how to do that in my first post) and you are fine.

cerealqueen · 17/04/2014 00:50

I can't log in on iPad with details verified on the regular site? Though to be honest, the lack of pages on talk drives me bonkers also, so no real loss!

RStallman · 17/04/2014 00:47

Who is this heartbleed character, is he trying to pretend he is responsible for this?

He talks nothing like the messages posted at the time of the intrusion. Also, LastPass is seen by a lot of people in the security industry as a terrible idea - single point of failure.

Heartbleed · 17/04/2014 00:25

"I wonder when the cybercrime division will turn their attention to the much more important hacking here."

I don't think this is nearly as big of an issue. There are going to bethousands of sites that are vunrable due to Heartbleed. The cybercrime' devision will have more important stuff to do. If they do do anything in the first place that is.

noblegiraffe · 16/04/2014 23:43

Well it's not the heartbleed hacker who stole Canadian taxpayer details, because he has just been arrested.

I wonder when the cybercrime division will turn their attention to the much more important hacking here.

Solo · 16/04/2014 22:59

Err..who is this ^ person? Confused is it the fungus? (fungi)

Heartbleed · 16/04/2014 21:14

I would like the Mumsnet admins to comment on why the TLS Cert was re issued 2 days AFTER they got users to change their passwords? That means that users updated their password while the server was still running a potentially vunerable certificate.

Heartbleed · 16/04/2014 20:53

Alrighty

PirateJones · 16/04/2014 20:51

And I am not American

Are you saying my awful generalisation based on one word is wrong? NEVER!

Heartbleed · 16/04/2014 20:49
Heartbleed · 16/04/2014 20:48

I guess I did come off a bit strong. But netsec is important to me and should be to you. I hope this is a lesson to everyone who reuses passwords. Install something like LastPass, use a unique, long (30+ chars) passphrase for the database and you are done (use this method for coming up with you passphrase: xkcd.com/936/). Generate passwords with a click of a button that can have as much entropy as you want. All of it is stored for you so you don't have to remember the passwords.

Done.

This 'Heartbleed' bug has been preasent for over 2 years and is NOT the only security flaw in TLS (Transport Layer Security - otherwise known as SSL).

P.S. As for the spelling error, oops. And I am not American.

Maryz · 16/04/2014 20:37

This reply has been deleted

Message withdrawn at poster's request.

PirateJones · 16/04/2014 20:31

oh i know, i was aiming more for American = unpleasant.

That’s why the word retard has re-entered the language after being phased out years ago along with spastic, Americans.

confuddledDOTcom · 16/04/2014 20:30

You can still be American and unpleasant...

PirateJones · 16/04/2014 20:23

You sound pleasant
He's American.

confuddledDOTcom · 16/04/2014 20:22

Pleasant and intelligent.

VelmaD · 16/04/2014 20:21

Typse? Retarded? You sound pleasant Hmm

Heartbleed · 16/04/2014 20:13

This reply has been deleted

Message deleted by MNHQ. Here's a link to our Talk Guidelines.

confuddledDOTcom · 16/04/2014 19:55

Glad I'm not the only one who thought it was funny. It didn't sound like Justine but I could imagine something being posted as a joke so at the most I would have thought it was Justine/MNHQ having a laugh with us if I had seen it before it was caught.

BoffinMum · 16/04/2014 18:59

God almighty, that rogue post was vair funny and at least they had bothered to read the site Grin

I am just imagining all the kicking off while people were still in bath towels. So very MN. GrinGrin

DoctorTwo · 16/04/2014 16:46

Instead of using a patched OpenSSL why not use PFS, as Ixquick and Startpage do? Or would it be too much of an arseache?