Please or to access all these features

Due to a security breach we are resetting all passwords across Mumsnet

83 replies

RebeccaMumsnet · 12/04/2014 17:32

Following the recent security breach related to Heartbleed we are reseting the passwords of all users.

On Saturday 12 April, we will remove all passwords from our system and to use the site, you'll need to reset your password by clicking on the password reset link.

Type in your email address and click the 'Request reset' button and you will receive a mail to your Mumsnet registered email account. (You will need to click on the link in the mail within 30 minutes of receiving it, without changing the device you're using i.e swapping from phone to laptop, or you'll need to request a further reset).

If you do not receive a mail, please check you spam folder. The password reset mail will come to the email you used when you first registered with Mumsnet.

If you don't receive or can't access your reset mail, please [email protected] for help.

We are very sorry for all the fuss. We want to assure you that we followed all the published steps to protect members' security as soon as we became aware of the heartbleed security risk, but it seems that the breach occurred prior to that risk becoming known.

Most importantly, if you use the same password here as elsewhere, we strongly recommend you change your password on the other sites too.

Thanks,

Justine & the MNHQ team

RowanMumsnet · 24/04/2014 10:37

Hello

Great to see we've helped haul some of you back into the liferaft; apologies to those who are still struggling.

It's still best to sort individual difficulties by mailing us at [email protected]. Our mail backlog, while still bigger than we'd like it to be, is reducing now and hopefully we'll be able to work with those of you who have thornier problems for whatever reason.

We can't merge accounts, but hopefully with a bit of elbow grease we can help people get back into their old ones.

DawnMumsnet · 18/04/2014 12:42

@VeryStressedMum

Definitely hasn't logged me out of my phone, but still no reset email its been over 2 hours now and before it was 5 hours after i requested it. No idea why i haven't been logged out on my phone. Just a few days before mumsnet asked us to change the passwords i noticed I was logged out when i hadn't logged myself out so i logged back in using my usual password, this happened twice. I'd really like my reset email mnhq??????

Hi VeryStressedMum

Sorry for all the faff - just letting you know that we've mailed you a fresh password reset link now. Please email [email protected] if you don't receive it, we're determined to sort this out for you!

KateSEggMumsnet · 16/04/2014 16:00

Hi folks

We've created a page explaining exactly how events unfolded: Mumsnet and Heartbleed as it happened

RowanMumsnet · 15/04/2014 17:24

@MrsUggy

This wouldn't prevent an attacker stealing the session id (the rootsess cookie) and posting messages as another users and reading a users 'inbox' (all the non https pages basically).

I don't see any good reason why one wouldn't just make the site 100% HTTPS.

Tech's take on this is that the theft of rootsess cookies is practically quite difficult/rare (eg the hacker would have to be sharing an insecure wireless connection with a Mumsnet user in the act of exchanging information with the server), so it's outweighed by the very real effects sitewide https would have on user experience, especially slower browsing. It would also make it difficult for us to operate sub-domains like Mumsnet Local on the same server.

KateSEggMumsnet · 15/04/2014 15:00

@MrsUggy

With regards to not using HTTPS throughout the site, this means that an attacker can steal the users session cookie.

I highlighted the issues with HTTPS (or the general lack of it on mumsnet) back in 2011. It took years to add even HTTPS and then not everywhere.

sigh

Hi MrsUggy - we've actually just introduced https on every page that requires you to enter your log in details.

KateSMumsnet · 15/04/2014 13:30

@Lucked

Never logged out, never changed my password (link won't work). I definitely haven't had a forced log out.

Curiouser and curiouser - are you using the app or the site?

JustineMumsnet · 15/04/2014 12:58

@JustineMumsnet

[quote TigerSmoke] our passwords are encrypted but the heartbleed bug allowed access to live login pages

I haven't actually logged in for months (lurker supreme); does that mean I am safe? I.e. does "live login pages" refer to profiles that have been logged in more recently than I have logged into mine?

Thank you.

I hesitate to post because I'm not 100% on this, but I think it might mean you're safe - then again it's possible something (eg to do with cookies) means you're not. I will check with Tech, but want to reiterate that there's no evidence this hack was done with anything other than the intention to raise awareness at this stage.[/quote]

Hi again TigerSmoke,
As said, whilst it’s impossible to say how many usernames and passwords were accessed via Heartbleed, we have checked and we re-booted all our servers 57 days ago which would have wiped the memory, so we're confident that anyone who hasn't logged in since then wouldn't have been affected. Hope that helps.

JustineMumsnet · 15/04/2014 12:54

@nsld

nsld The bigger concern with this is that if Mumsnet has removed all passwords and is telling people to reset passwords on other sites then this probably means that the passwords where stored in an unencrypted format or the encryption keys for the password files where stored with them.

Either way its a monumental security error on the part of the site, even with full admin rights the passwords should not be viewable and the database of those passwords should be properly secured.

Given the magnitude of the breach have you reported it to the ICO yet?

No, that's not right, our passwords are encrypted but the heartbleed bug allowed access to live login pages (temporarily until we patched the site). We have no way of knowing how many login pages were accessed but obviously more than one was.

===

So if the passwords are encrypted as you say why do a mass delete?

The key questions are:

1: Has someone copied the user list from the site along with the passwords?

2: How good is the level of encryption used?

3: Where the encryption keys compromised?

4: Do you have no form of server logging to see whats happening?

5: Why do you not force https for all connections to your site? As I write this I can see that the connection to your servers is unencrypted.

Hiya,
NobleGiraffe has actually answered a lot of your questions very ably already but by way of further reassurance:

Our passwords are stored in encrypted form in the database, but like most other sites our login form sends the username and password in plain text, wrapped in an encrypted SSL envelope to avoid eavesdropping in transit. When they arrive at our server, the envelope is decrypted. The Heartbleed bug allowed access to this data as it arrived at our server.

The hackers did not copy passwords from the database, they obtained them from the web server’s RAM via Heartbleed - two very different scenarios.

It’s impossible to say how many usernames and passwords were accessed via Heartbleed, but what we can say is that we re-booted all our servers 57 days ago, so we're confident that anyone who hasn't logged in since then wouldn't have been affected by this.

The Heartbleed bug has in fact made us revisit our use of https (SSL) across the site. Previously we only used it on the login page. However we are now in the process of using https on all pages where the user’s password is entered.

We agree that this is best practice and improves the security of the site overall (but let's be clear, not following this practice had no bearing on this security breach).

KateSMumsnet · 15/04/2014 11:02

To folks who can't reset, but are able to post here.

Anyone who hadn't reset their password before 13:49 (ish) yesterday would have been forcibly logged out, so you had to reset, else you wouldn't have been able to log in.

Sooo, if you're able to post here, you must have been able to reset your password, hurrah!

However, if you didn't reset your password before yesterday, and you haven't been forcibly logged out, and have just stayed logged in, something has gone wrong - so please shout!

KateSMumsnet · 15/04/2014 10:47

@Maryz

Justine, can I ask whether you thanked or banned the person who did the demonstration -caszko I think - both in your name, and on the "Justine's thread" thread.

I think we were all lucky it was brought to our attention, even if it might have been simpler for them to just contact you. Doing it this way we've all had a boot up the arse for internet safety in general.

And no, it wasn't me. I'm a technowuss Sad

Hm, the lady doth protest too much methinks Wink

Things are all still a bit up in the air (understatement of the century), and we can't be sure whether people who appear to take credit for the hacking were genuine or not, so we're not making any hasty decision.

We do totally see what you mean though, and it does seem that it was done to highlight the problem, rather than to be overtly malicious.

KateSMumsnet · 15/04/2014 10:39

@sunbathe

Kate - no. Still logged in!

Ah, sorry we've confused ourselves here. The forced log out would have only happened to those who hadn't done their password reset after the passwords were wiped. So we're guessing you must have done yours sunbathe!

KateSMumsnet · 15/04/2014 10:35

@TheDetective

Is there any way I can find out my old password. I think I know what it was - but I can't quite remember. I've not had to log in for a while.

I really need to know what it was - because I then need to work out if I need to change some other passwords.

Please help!

Hullo TheDetective - we're afraid that since we've wiped everyone's password from our data base, we can't tell you what you password was. In any case, due to data protection, we can't send out people's passwords, and it would be the same even without Heartbleed.

We suggest that to be on the safe side, it might be an idea to change your password for the sites you're worried about.

KateSMumsnet · 15/04/2014 10:23

@VivaLeBeaver

Was it a MN regular who hacked us? I'm guessing it was as the fake Justine message seemed to be by someone who knows MN.

We honestly don't know Viva! Sorry we're giving such vague answers, but anything we do find out we'll pass onto you guys.

KateSMumsnet · 15/04/2014 10:10

@mumtotoby

Can I ask what information they stole other than passwords?

The bug allowed people to see information that you submit via the log in page, which means your username or email, plus your password.

Beyond that, we really don't know what the hackers have done with this information. We realise that must be frustrating to hear, and if we knew any more we'd certainly tell you. But the fact is we can't be sure.
However, we have no reason to suspect, and no evidence to suggest that anyone's account has been used for anything other than to flag up the security breach.

KateSMumsnet · 15/04/2014 10:01

@NearTheWindymill

But what about when we were being logged out before 5.45pm?

Thank you for responding though. So do you mean they can't have got hold of my r/l name and dc's names and dates of birth etc.?

We're afraid we can't definitely say what the hackers have or haven't got, which is why we're advising folks who use the same password for Mumsnet as other stuff to change them.

KateSMumsnet · 15/04/2014 09:46

@sunbathe

I haven't been logged out - should I have been?

I was forcibly logged out of Fitbit, for example, should that have happened to me on MN?

This should have happened, has it happened yet?

JustineMumsnet · 14/04/2014 22:18

@TigerSmoke

our passwords are encrypted but the heartbleed bug allowed access to live login pages

I haven't actually logged in for months (lurker supreme); does that mean I am safe? I.e. does "live login pages" refer to profiles that have been logged in more recently than I have logged into mine?

Thank you.

I hesitate to post because I'm not 100% on this, but I think it might mean you're safe - then again it's possible something (eg to do with cookies) means you're not. I will check with Tech, but want to reiterate that there's no evidence this hack was done with anything other than the intention to raise awareness at this stage.

JustineMumsnet · 14/04/2014 22:16

@NearTheWindymill

So when the system was logging us out on Saturday does that mean it was the logged out one's accounts that had been hacked then please?

Can you confirm that it was only the password/user names that were hacked and that our personal data was not accessed please.

No, it doesn't NTWM, we logged everyone out on Saturday to require everyone to reset their password. I'm afraid we have no way of knowing which users' accounts were hacked, if any, beyond the handful of names that were used to post on here/published on pastebin.

And we have no way of knowing whether any of that info was used to access pms, profiles etc. All we can say is that the hackers were keen to let us know about the breach and there is no evidence of any accounts being used maliciously, save really for mine and even that fake post from my account could be seen as more of a heads up than a malicious act.

JustineMumsnet · 14/04/2014 21:48

@PuppysMum1

Sorry daft question, what if I can't recall my MN password? I have reset it but it would be good to know what my old password was just to know which other sites I need to change my password on.

Any possibility of finding out my old password? Just need to know whether to panic!!

No, sorry PuppysMum1, we can't help on that one - we encrypt the passwords so that not even MNHQ staff can find out what they are. Best bet is to change your password everywhere which has sensitive info.

JustineMumsnet · 14/04/2014 21:46

@nsld

The bigger concern with this is that if Mumsnet has removed all passwords and is telling people to reset passwords on other sites then this probably means that the passwords where stored in an unencrypted format or the encryption keys for the password files where stored with them.

Either way its a monumental security error on the part of the site, even with full admin rights the passwords should not be viewable and the database of those passwords should be properly secured.

Given the magnitude of the breach have you reported it to the ICO yet?

No, that's not right, our passwords are encrypted but the heartbleed bug allowed access to live login pages (temporarily until we patched the site). We have no way of knowing how many login pages were accessed but obviously more than one was.

JustineMumsnet · 14/04/2014 21:42

@CecyHall

Can I ask a question? (And I don't want this to come across as nasty or anything) but when posters were concerned over the threat of heartbleed early on and were reassured by tech that all was ok and nothing would happen was this BS/did tech really not know what was going on when they should have/something that tech couldn't have possibly known at that time?

It just feels like everyone was saying no problem, all is ok when people were concerned and then all of a sudden- problem.

Sorry if this has been covered elsewhere.

Hi CecyHall (how are you?).
You're right we did think things were ok because we'd seen the details of the heartbleed security risk soon after it was announced and had implemented the recommended patch/fix - so Tech was confident that we were secure. Unfortunately in the time between publication of the risk and implementing the fix - about a day - someone had been in and scraped some user data. This only became fully apparent when some accounts were hacked on Saturday in order to post a message about giving us a heads up about Heartbleed.

At that point, obviously, we became aware that we had a problem and decided the only sensible course of action was to force a password change and shout about the associated password risk as loudly as possible.

Hope that makes sense.

RebeccaMumsnet · 14/04/2014 13:14

Hi all,

Tech have extended the amount of time you are allowed to click on the emailed link for. You now have 48 hours but only for links sent this afternoon onwards.

Please do click to resend.

We are still ploughing through your mails, apologies it is taking some time but if you have mailed in, please hang fire and we will get back to you.

Thanks all for being so patient.

RowanMumsnet · 13/04/2014 17:15

@InspirationFailed

Sorry to be a pain - I can't access PMs

I get this message Confused

Oh dear! Are you on the mobile site? Anyone else having trouble reading their PMs on there?

RowanMumsnet · 13/04/2014 17:06

@MinecraftAteMyWorld

I changed my password earlier on my phone but have not been asked to on my laptop. Should I change it?

No you should be OK by the sounds of it

RowanMumsnet · 13/04/2014 16:51

@cozietoesie

Is Tech still sane?

Poor Tech - this comes after a week of them struggling with poor broadband in the office as well (because of a third-party problem, not Tech's fault)

Watch this thread for updates

Tap "Watch" to get all the latest updates