Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

See all MNHQ comments on this thread

That really wasn't well handled was it MNHQ?

189 replies

ASorcererIsAWizardSquared · 14/08/2015 11:37

Yes, this is a telling off.

Your communication over the Calm Down Jeffrey incident was atrocious.

I find it shocking that you can be sat there, posting to us that all is well and under control when we can see, in front of our very own eyes, that someone was hacking MNHQ posts and editing them, and also posting under posters names and editing other posts as well as deregging and banning other users who insulted them.

The response from you was seriously lacking, on top of your coquettish rubbish about not putting 50p in the meter when you went down over night.

Its not on.

You have a duty to your posters when these things are happening to keep us all informed, we're not stupid and we deserve to be treated with a little more respect. Not fobbed off with half truths and blatant lies.

OP posts:
New posts on this thread. Refresh page
3CheekyLittleMonkeys · 20/08/2015 19:46

This reply has been deleted

Message withdrawn at poster's request.

Baconyum · 20/08/2015 19:13

If you don't have trustworthy tech and you aren't communicating effectively with your users, you don't have a site.

Once this is all over and the site is properly locked down, I would urge MNHQ to get the absolute best security advice they can, and to get a proper communication plan in place.

This is not a hobbyists' site; this is a multimillion-pound business and it needs to act like it because it has a duty to its posters and to its advertisers not to be so complacent in future.

I agree so much with the whole of this post but especially this!

To them saying give MNHQ a break, they themselves have admitted they didn't tighten up security after the last time which they claimed they'd do so that was a blatant lie!

Justine herself has said they stopped online so as to support vulnerable users, but its these users in particular that have been let down. I'm thinking especially of those that may have put very sensitive personal information on pm's!

Iwasworried · 20/08/2015 10:29

Right. Hi all. I used to post as TheTruth but I deregged last Weds because I was really unhappy with the tech situation and had a bad feeling about it (never thought I'd be proved right quite so spectacularly).

I've reregged with a new username and email address etc because I wanted to add my voice to this thread.

The Heartbleed thing was a bit worrying but fair enough, a lot of sites got caught out by that. But in recent months I've been getting repeated security warnings when browsing MN on my phone. I posted a thread about it a while back (www.mumsnet.com/Talk/site_stuff/2384659-Continual-security-warnings?messages=100&pg=1) which was inconclusive. Nobody from tech came on to engage with us directly and so it felt a bit like a game of Chinese whispers, with the mods passing messages back and forth to tech and asking for more screenshots and that was about it.

So I had a niggling feeling something wasn't right. I've used other forums before and never had any of this kind of thing.

The "upgrade" to the mobile site happened, with really poor communication and troubleshooting. That made me wonder quite what the tech strategy was, because there was clearly either a lack of experience on the tech side or a poorly thought out communications approach - it was hard to tell which.

Then came the "improvement" to Watched Threads earlier this month which again was handled really badly. At the time I posted this, all of which still stands in my opinion:
(www.mumsnet.com/Talk/site_stuff/2441116-Heads-up-Improvements-to-watched-threads-coming)

Hi MNHQ, I see you're still getting a pasting for this. The AIBU thread has just died because it's full.

There are a lot of seriously skilled professional women on here who work in comms and user experience so I won't pretend to be the best expert you can find on how to handle this. I'm sure there are plenty of site users who would be all too willing to advise you on both your tech and user strategies. But...
Here's what I'd suggest as a v basic starting point:

- hold your hands up and admit this was a bad move. Preferably someone as senior as possible. Get them online to talk to everyone and make them feel like you care what they think.

- deal with the immediate issue. Whether you keep the current set up or revert to the old one or do something new. Make an effort to have Mn people ok one talking to users about what they would like, then announce your decision well in advance of implementation and then be around to pick up issues and queries when it is implemented. And when a small minority of people are inevitable dissatisfied with some aspect of it, be gracious and engaged with them and make them feel like you're talking to them and not just ignoring them.

- get whoever is doing your tech to start a thread setting out what their general approach is, what their priorities are at the moment and what that means in practice, in terms of aspects of the site which might change in the coming months.
Invite contributions and views, both on your plans and on the wider question of what Mn users would like to change.

- before you start a particular part of that work, start at least one thread giving people notice of the change - at least a couple of weeks - and asking for views on it. If you're going to use people's email addresses for anything then use it for this - send them an email telling them of the change and giving them the chance to comment.

Thee are other things I could suggest but those would be a good start and and a lot of other collaborational vibes would flow from them in my personal opinion.

(nobody from MNHQ replied to that post btw).

The Census happened, and in my response I said I was very worried about the tech side of the site and I urged MNHQ to get expertise in to help them.

Then last week came the DDOS attack. I saw the shenanigans on Weds and felt really, really worried (www.mumsnet.com/Talk/site_stuff/2446968-Site-outage-update).
So I asked MNHQ to dereg me.
I've been watching the events of the last couple of days unfold with great concern.

It gives me no pleasure at all to come back on the site to say this, but I wanted to do so because I feel really strongly that this is just the latest and most spectacular of a long series of tech/communication issues which all add up to a big problem for MNHQ. To date it has felt from this user's perspective that site changes and communication thereof are treated like a necessary but minor issue - when actually they should be absolutely primary. If you don't have trustworthy tech and you aren't communicating effectively with your users, you don't have a site.

Once this is all over and the site is properly locked down, I would urge MNHQ to get the absolute best security advice they can, and to get a proper communication plan in place.

This is not a hobbyists' site; this is a multimillion-pound business and it needs to act like it because it has a duty to its posters and to its advertisers not to be so complacent in future.

00100001 · 20/08/2015 09:42

The Tech Team work for Mumsnet, sure. But the person responsible for network security is the person who allowed poor passwords and had holes in the network security

Arkkorox · 20/08/2015 09:36

It would be a very sad day if MN was beaten by this Sad

CoteDAzur · 20/08/2015 09:29

"You'll know if I pearl clutching because I'm fucking fabulous at it."

Honey Grin

HoneyDragon · 20/08/2015 09:28

And the tech team work for whom? Barbara Streisand? Mickey Mouse?

dorophone · 20/08/2015 09:28

I spend an inordinate amount of time on MN

I've felt that there has been something tangibly 'wrong' with the site for about 10 days before the first DDoS attack - lots of minor irritations/loss of functions [pre-dating the upgrade/highlighting fiasco which I think was possibly a significant distraction as much of what I was experiencing was being reported and largely dismissed in site stuff]

Plus over the last couple of weeks I'd noticed a wave of new quite stylised faux-naif OPs in AIBU and Chat that have a very inauthentic quality and some very strange isolated postings on the less active boards that were going unanswered.

I'm not sure if this is the same thing as Maryz has described or not.

HoneyDragon · 20/08/2015 09:27

I get that Alan. I'm not without sympathy or support for HQ either, we don't don't know what the ratio is between hacker skills and poor security, but we've got to hope it was a very good hacker. If Mnet face any fines due to lax security than there may not be a Mnet for people to tell me to fuck of from Sad

00100001 · 20/08/2015 09:25

The poor staff passwords were the Tech Teams fault!

00100001 · 20/08/2015 09:24

The fact that users had the same passwords for other accounts than MN is definitely not MNs fault.

What is their fault is the poor security in place in their systems!

Shutthatdoor · 20/08/2015 09:19

Staff passwords were pathetic

On this I agree. I was a bit Shock at them tbh.

AlanPacino · 20/08/2015 09:17

Mumsnet don't owe us anything beyond the normal legal requirements for an Internet forum. It's free and we don't have to be here. I'm not going anywhere though.

HoneyDragon · 20/08/2015 09:06

I wasn't pearl clutching, I said there was no need for it. You'll know if I pearl clutching because I'm fucking fabulous at it.

There's just as much hysteria coming from posters rushing to defend Mumsnet as those who are worried.

And I stand by what I said.

Mumsnet stated during heart bleed that they were tightening software and security at their end during and after heart bleed.

They clearly (from what they have released) haven't done what they said they would. My internet security is in order. So I don't need to be condescended at or insulted or told to leave, but thank you for your input.

differentnameforthis · 20/08/2015 05:33

Not to mention that people on other threads

differentnameforthis · 20/08/2015 05:32

LauraGrooves I look forward to visiting your website & knowing that there will never be an issue!

they could have said "we have a password issue, make sure that you don't use your mn password on any other site". I'm sorry, do we really need the HQ of a website to babysit us?

Basic internet security101 - use a unique and hard to guess password for each place on the internet that log into! My MIL knows that & she is knocking 80!

Not top mention that people on thread suggested ways to help protect yourself. I suggest people remove any & all personal info & use a generic, non real life name based email addy.

The List was enlightening as to how many people have no idea of the downfalls of the internet. A few users using their usernames as passwords. A couple even using the website name.

Regardless of what you use, where you go on the internet you should do as much as you can to protect yourself. Don't share anything that you don't want to literally 'share' with the world.

I am however disappointed that they have not displayed competence yet again. So you'll be leaving then? After all you wouldn't keep eating at a restaurant that you felt were repeatedly incompetent, would you?

As for people being personally insulted, they don't seem to mind doing it themselves to MN staff so I'd stop pearl-clutching over that one. YY!

differentnameforthis · 20/08/2015 05:17

So if google leaked all emails of gmail usera,no biggie as they didn't pay anything? Leaking the contents of what are private emails to all and sundry is different to this though, isn't it?

What did he have to gain if he got into our account? He could see what we had posted and when (it's all out there anyway). He could have posted as us. He may have seen some pms. Yes, he could have taken your emails addy & tested it with the password you use for here & gained access if you used the same one. But that isn't MN's fault. I'm sorry, but there is a plethora of advice out there about not using the same password for anything!

When all this started kicking off I posted that I had changed my personal info on here, and changed email addys, and removed what stuff I could. I suggested others do the same so that he viewed limited stuff if he managed to hack personal accounts.

I personally am getting fed up of those sticking the boot in asking for updates every 30seconds. Asking if they are on the sodding list.

Let MN deal with it. Let them decide when to tell us stuff, which is likely to be when time allows. Sorry, but when you have someone in your system your priority isn't going to answering ten tonne of emails, it's going to be getting him/them out & keeping them out!!

I am also fed up of hearing "my dh works in in IT & he said it can't be this/that" it's fucking insulting, because you are implying the MN are lying to us. I don't think they have any reason to. In all truthfulness, unless he works for MNHQ he has no idea what they are dealing with & how their investigation is going

And when you moan about having to learn a new password, give a thought for Justine's au pair who had to deal with a fucking swat raid in the middle of the night, and another poster whose whose husband was arrested in front of his family, inc young children because she suffered a swat attack too.

If you don't like the way they dealt/are dealing with this, leave. You are not obligated to stay here, and use the FREE service they try hard to provide.

MN have said they will dereg/delete what you wrote of you like, just give them time.

Oh & perhaps go & start your own website and hope that stays free of attacks.

Baconyum · 20/08/2015 03:38

LauraGrooves has it right it was all too bloody little too bloody late. Several users Inc me was telling em for at least 3 weeks there was a problem and we was getting bugger all response, even in pm's!

Staff passwords were pathetic
Communication non existent
Little communication with police/data protection authorities
And so on...

TendonQueen · 20/08/2015 00:16

So on the one hand people are saying 'we're being treated like small children, this is patronising' and yet they're also saying 'make us all use better passwords, we want to be told we have to!' Just confirms my opinion that MN can't win on this one. As for people being personally insulted, they don't seem to mind doing it themselves to MN staff so I'd stop pearl-clutching over that one.

horseygeorgie · 19/08/2015 22:15

What the bloody hell has been going on!!! I've missed everything, I have NO clue what you're all on about! I'm guessing MNHQ was hacked by a person called Jeffery who changed text. Then some flannel about a Dad and passwords and twitter and trending...

I'm lost. How did i not notice this, I'm on it everynight near enough!

HoneyDragon · 19/08/2015 22:05

Very VOCAL about improvements.

HoneyDragon · 19/08/2015 22:04

San Francisco tech said years ago on a thread that Mnet needed to dig into the coffers to sort out dated soft ware etc.

After Heartbleed Mnet were very vital about improvements.

So if users want to be cross they can.

I don't give a shit whether they apologise or not.

I am however disappointed that they have not displayed competence yet again.

And some of the personal insults been chucked at posters who may have damn good reason to be concerned and complain isn't needed (one person I know who has now de registered certainly had cause to be be very alarmed).

DixieNormas · 19/08/2015 22:03

This reply has been deleted

Message withdrawn at poster's request.

Maryz · 19/08/2015 21:57

This reply has been deleted

Message withdrawn at poster's request.

TendonQueen · 19/08/2015 21:29

Really? So basically they can't win now? And yet people still keep demanding apologies, talking about how unacceptable this all is. Wonder if they'll be prepared to pay for the extra technical security they want. Or whether they will check meticulously all the security procedures of all the other sites they use. How many of you know anything about how Facebook or Netmums or Google handle security? Bet you're still using them. Very harsh criticism here and much of it unjustified here I think.