Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

See all MNHQ comments on this thread

That really wasn't well handled was it MNHQ?

189 replies

ASorcererIsAWizardSquared · 14/08/2015 11:37

Yes, this is a telling off.

Your communication over the Calm Down Jeffrey incident was atrocious.

I find it shocking that you can be sat there, posting to us that all is well and under control when we can see, in front of our very own eyes, that someone was hacking MNHQ posts and editing them, and also posting under posters names and editing other posts as well as deregging and banning other users who insulted them.

The response from you was seriously lacking, on top of your coquettish rubbish about not putting 50p in the meter when you went down over night.

Its not on.

You have a duty to your posters when these things are happening to keep us all informed, we're not stupid and we deserve to be treated with a little more respect. Not fobbed off with half truths and blatant lies.

OP posts:
SarahMumsnet · 14/08/2015 15:02

Thanks everyone.

Fflightattendant, on the question of data: we can say for certain that the hacker didn't get hold of anyone's passwords, as he claimed on Twitter, since we don't store them in plain text. We at MNHQ don't know what your passwords are; all we see in our system is something along the lines of @!£^$£(U(*&$£.

We can't guarantee with absolute certainty that the hacker didn't manage to look at some users' details, but as you know, we keep very few details on users, and he'd only have been able to look at as many as he could sit down and read in the time he had access to our administrative tools. We can say that he didn't gain access to the database itself; only to the screens we use on a day-to-day basis to manage the site.

We're really sorry we can't be more definitive than that. Unfortunately, it's just not possible to offer a 100% guarantee of online security; hackers will find ways round even the tightest of systems (the Pentagon confirmed last week, in fact, that they'd been successfully hit by a cyberattack) but we do our very best to protect our users, and be transparent about any breaches we find.

Really hope that helps clarify matters, insofar as we're able to clarify them, and thanks again

MNHQ

ASorcererIsAWizardSquared · 14/08/2015 14:52

i prefer this one kidding ;)

That really wasn't well handled was it MNHQ?
OP posts:
HoneyDragon · 14/08/2015 14:37

Anyone would think its a rainy day in the school holidays with all this snippiness.

The site was already buggered about with, after heartbleed I would've expected MNHQ to be smoother on the ball this time.

Some posters were concerned and upset on the thread, and were largely ignored by MNHQ for quite a while.

More good was done at this point by the posters linking to Dadsecs Twitter pointing out he was a bit of a numpty bum with an over inflated sense of his hacking abilities.

And that editing facility hack could have been used much more maliciously across the boards than it was against vulnerable posters. That it wasn't was down to the hackers integrity rather than Mnets control of the situation.

I do think these shenanigans will happen more and more rather than less though.

BertPuttocks · 14/08/2015 14:31

I think they handled it well.

The hacker was obviously after attention and eventually had to resort to editing other people's typos in order to get any. :)

youarekiddingme · 14/08/2015 14:23

Ok, so how about I future instead of MN joke about 50p in the meter they ask this

That really wasn't well handled was it MNHQ?
Roussette · 14/08/2015 14:19

Blimey I thought I was on MN toooo much but not knowing any of this happening makes me think not! need to schedule in another 2 hour window a day to post on here!

G1veMeStrength · 14/08/2015 14:11

I think MN handled it really well. I don't want them explaining all the tech stuff for the hacker to read.

'50p in the meter' is the sort of light hearted tone I like from MN, with all the piss taking of the hacker it was quite entertaining.

I come here to escape from work not to read a boring corporate load of guff.

I disagree with OP that MN has any sort of duty to its users at all. It's not like I pay to use it.

youarekiddingme · 14/08/2015 14:11

Tbf to MNHQ they did'start a thread about the outage.mthey explained what had happened.
RebeccaMN remained on the thread responding to posters. It became apparent during this time that Jeffrey had hacked HQ functions when he started to change and edit het posts. I'm not really sure what you can expect HQ to do then? They can hardly keep posting.

And OK, the 50p in the meter thing may be patronising to some but sometimes not allowing hackers to know your aware you've been hacked gives you an advantage.

DannyTorrance · 14/08/2015 14:03

Maybe they didn't say much because... there was nothing to say? What exactly would you have done with a exhaustive list of MNHQ's every thought and action during the time when they were, y'know, getting on with solving the problem?

The site's back up, everything is working as it should be - can't really see what there is to be angry about? Am I missing something?

Fflightattendant · 14/08/2015 14:00

I think there has been, uhh, some rudeness on both sides perhaps

ASorcererIsAWizardSquared · 14/08/2015 13:56

Any need for that Eve?

So its ok for there to be thread, after thread of people yelling at MNHQ over the tech changes for the site, but i can't come on here and tell them i think they made a mistake over their handling of this?

Its why site stuff is here. I'm sorry you don't agree with me, but there was no need for you to be quite so rude about it.

OP posts:
Fflightattendant · 14/08/2015 13:52

Thank you Sarah, that helps - may I ask you to confirm for sure that no ones data was subject to a breach?

I know you have said as much as far as you knew at the time but a confirmation would be really appreciated I think.

Brew
Maryz · 14/08/2015 13:46

This reply has been deleted

Message withdrawn at poster's request.

Maryz · 14/08/2015 13:45

This reply has been deleted

Message withdrawn at poster's request.

DurhamDurham · 14/08/2015 13:43

I think Mumsnet played it right......it was clear things weren't right so we didn't need to be told that, we could see it for ourselves. Mumsnet played down the incident rather than giving the hacker (poor bored sod) the drama he is so obviously missing in his life.

SarahMumsnet · 14/08/2015 13:41

Hey everyone,

Sorry some of you don't think we handled things well in terms of keeping you informed; we thought perhaps a summary of what happened when and what our thinking was might explain things a bit.

When the site first went down late on Tuesday evening, we assumed we'd be able to repel the denial of service attack quickly, hence the 50p in the meter remark on social media (we agree it looks flippant in retrospect, so apologies for that).

The site came back up briefly very late Tuesday night, but when it went back down again the severity of the attack became apparent, and tech spent the rest of the night and Wednesday morning working extremely hard to get us online again. We posted as soon as we could after the site was back up explaining that the denial of service attack had taken place.

It was then that we detected that our administrative functions had been hacked, at which point we obviously directed all our resources towards working out how this had happened and how to stop it (I posted on the thread to say as much in the early afternoon). As you'll no doubt appreciate, we really don't want to go into any more technical detail, but we're currently doing our best to make sure that nothing like this happens again.

The tricky thing from our point of view was that, as well as the fact that the situation changed at high speed over the course of about 24 hours, it was difficult to be explicit about what we thought was happening all the way through as we had to balance the need to keep you as informed as possible with the fact that everything we said would also be read by the hacker. Plus, as several people on the thread have said, we really weren't keen to give the hacker the publicity he so clearly craved. We really are sorry if you think that, in the event, we didn't get the balance quite right.

Meanwhile, if anyone's still having site problems of any sort, do drop us a line.

Thanks again for your patience,
MNHQ

GarminGirl · 14/08/2015 13:40

I cringe too.

exLtEveDallas · 14/08/2015 13:39

"This is a telling off"

"It's not on"

"..a duty to your posters"

Who the fuck do you think you are?

If you don't like MN, leave. If you do like MN, stay. But don't fucking whinge and whine like MNHQ owe you something. They don't. Justine & Co created a website that you use. If anything you owe them - because it's not like you pay for it is it? How they deal (or don't deal) with DDoS attacks or hacks or a million trolls is their business and they can deal with it their way.

If you have anything constructive to say to help if this happpens again, great. Let them know, they might appreciate th assistance. But posting 'at them' as if you are their fucking CEO is out of line.

BitOfFun · 14/08/2015 13:36

I cringe when people make posts like this- how rude Hmm

CoogerAndDark · 14/08/2015 13:30

Hackers gonna hack Smile

Fflightattendant · 14/08/2015 13:29

Hmmm there were approx 12 posts mainly of the short variety from Rebecca and Sarah on the thread (so far 721 messages)

I wonder whether they are actually all on leave.

greenhill · 14/08/2015 13:28

AnnieOnAMapleLeaf has got her name back now. It was a storm in a tea cup, people reacted to the perceived threats, MNHQ calmed it out, we're all still here.

If you don't like the forum, or the way it's run, you can change it by complaining until it's exactly what you want, or you can enjoy it for what it is.

Fflightattendant · 14/08/2015 13:26

They have been inordinately quiet on the Site Stuff thread. Usually there's at least one of them hanging about there trying to manage our questions and so forth when a similar set of issues arise.

We had a brief bit of info from Rebecca I seem to remember and that was it.

Ubik1 · 14/08/2015 13:24

It's only a chat forum.

It's serious for the back office but really I don't know what you expect them
To say...

It's not providing any sort of serious service, no one is going to suffer.

Honestly just let them sort it and stop bitching and moaning.

Fflightattendant · 14/08/2015 13:24

Yes he made it look like he was hacking accounts but he wasn't. He was just altering text. That was my interpretation anyway.

I don't know that Annie got hacked, I think it's possible it was a different issue - several people have had issues with logging in this week, apparently not because of this incident, or not directly in any case.

It's possible there were some after effects due to 'restore point' sort of things - I think thats why we're back to Most Active as well.

Just guessing though.

Swipe left for the next trending thread