Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

See all MNHQ comments on this thread

That really wasn't well handled was it MNHQ?

189 replies

ASorcererIsAWizardSquared · 14/08/2015 11:37

Yes, this is a telling off.

Your communication over the Calm Down Jeffrey incident was atrocious.

I find it shocking that you can be sat there, posting to us that all is well and under control when we can see, in front of our very own eyes, that someone was hacking MNHQ posts and editing them, and also posting under posters names and editing other posts as well as deregging and banning other users who insulted them.

The response from you was seriously lacking, on top of your coquettish rubbish about not putting 50p in the meter when you went down over night.

Its not on.

You have a duty to your posters when these things are happening to keep us all informed, we're not stupid and we deserve to be treated with a little more respect. Not fobbed off with half truths and blatant lies.

OP posts:
CoogerAndDark · 14/08/2015 13:23

Lots of people have been locked out of their accounts in this last week. Mine took several password reset emails to sort last weekend and again yesterday. Site's on the fritz, not necessarily to do with hacking.

Massive molehill/mountain situation imo.

Fflightattendant · 14/08/2015 13:21

Yes that's true, no one really knew for certain what was happening even the guy himself.

He stated on twitter that he had my password 'in plain text' and had a lot of other data to play with as well - he clearly didn't, but it didn't particularly concern me as I'm fairly sorted on the old password front.

I think if anything more awful had happened then we probably would have been advised of it. Whether that would have been timely however is anyone's guess.

ASorcererIsAWizardSquared · 14/08/2015 13:21

there is a difference between keeping your posters informed and feeding the trolls.

OP posts:
ASorcererIsAWizardSquared · 14/08/2015 13:19

I suggest you talk to AnneonaMaple leaf, she posted to say she'd been locked out of her account.

the guy posted as wannabe and at least one other poster on the outage thread. whether he was editing things already posted by them, or in their account remains to be seen, but wannabe did come on and say it looked like someone else was posting as her.

OP posts:
AliceAlice1979 · 14/08/2015 13:16

I found it all quite amusing personally from the 50p in the meter comment to Jeffrey changing posts to the general piss take of dadsec. I agree slightly more comms may have helped but as anyone caught up in a cyber bullying thing knows you do not feel the beast.

ItsAllGoingToBeFine · 14/08/2015 13:14

Someone was indeed altering posts and editing stuff on the one thread. Just the one afaik?

No one got deregged afaik - please correct me if you have a source for this.
No one was posting as other people, ie, no one signed in as someone else using someone else's password.

All they could do was edit what had already been posted.

Problem is, without any info from MNHQ, its assumptions and Chinese whispers...

CoogerAndDark · 14/08/2015 13:12

And then, as advised by MNHQ, he did register under his DadSec name. Just the once. Presumably they then hit him with the full force of the Banhammer. Just because. Grin

tribpot · 14/08/2015 13:10

Agreed.

MN's response on Twitter was trite and amateurish 'ooh silly us, haven't fed the hamsters recently so the wheel's stopped turning' etc. I didn't really want to have to sully my eyes with Jeffrey's Twitter profile to find out what was going on (even though it did later appear dear Jeffrey wasn't too clear about what kind of hack he'd done).

When the site returned this seemed to catch MN off guard, rather as if the only reason it was back was because Jeffrey had left the DDOS running overnight in his time zone and was now awake and ready to have some different fun.

Then once they started a thread, they were asked repeatedly if we should change passwords as a precaution, as Jeffrey stated on Twitter he had all our data. Given the other instabilities already present in the site (people being logged off, the whole weird 'threads I'm watching' debacle) the hack looked more severe than it actually was. Eventually they posted to say no passwords had been compromised, and Jeffrey immediately set about editing posts to prove otherwise (excluding his initial homophobic edits, providing a valuable service in correcting spellings). Still no advice.

Given MN once put the entire site into read only mode due to some new year's eve high jinks the reaction seemed muted and chaotic.

By coincidence I had asked the day before Jeffrey visited us why MN didn't consider outsourcing the Talk part of the site and moving it on to some decent software. I hope they will consider this now. MN has many strengths but its technology is decidedly not one of them. But wherever the site is hosted, communication with the stakeholders (users, advertisers) will be MN's responsibility to get right. If nothing else, can you at least have a 'fire drill' once in a while where you rehearse how to deal with an outage?

Fflightattendant · 14/08/2015 13:07

Fwiw I do agree that there could have been a little more info and reassurance forthcoming but I got the impression they were a bit understaffed.

As long as they were onto it, that's the main thing, and they clearly were.

Fflightattendant · 14/08/2015 13:06

I had no problem with the 50p malarkey.

I find it shocking that you can be sat there, posting to us that all is well and under control when we can see, in front of our very own eyes, that someone was hacking MNHQ posts and editing them, and also posting under posters names and editing other posts as well as deregging and banning other users who insulted them.

Someone was indeed altering posts and editing stuff on the one thread. Just the one afaik?

No one got deregged afaik - please correct me if you have a source for this.
No one was posting as other people, ie, no one signed in as someone else using someone else's password.

All they could do was edit what had already been posted.

Press F12 on your keyboard and have some fun, you can do exactly the same, for your eyes only - it was basically that but he had found a way in to make it look the same to everyone else temporarily.

ItsAllGoingToBeFine · 14/08/2015 12:58

What exactly were they supposed to say?

' WE ARE BEING HACKED. EVERYONE PANIC. '

I think they handled what turned out to be a very silly hacker in the right way. Any more publicity and he would have got what he wanted.

Of course not...

They should have said something along the lines of...

Hi, all we are currently experiencing a DDOS attack (summer holidays...sigh...). You will have difficulties accessing the site, but all of your personal information is completely safe. Tech is working on the issue and it should be resolved shortly.

Hi all, sorry for the extended outage, it takes some time to block these attacks but we are working on it (hands tech tea). Again, please be assured that all of your information is safe.

Whoops! It'd would appear that DadSec (waves) has uncovered a wee backdoor into the system. He has (as you can see) some access to basic post editing functions. He has no access to passwords/personal info. Bear with us until we lock the backdoor...

Hi all, boarders repelled! ????The site should be back to normal now for everyone, if its not just drop us an email at MNHQ. The site has been beefed up against further DDOS attacks, and the entry point helpfully discovered by DadSec has been secured. We have have looked carefully at what has happened and we are certain that at nio point did anyone unauthorised access any private information. Thanks for bearing with us. (downs gin)

SoupDragon · 14/08/2015 12:56

it stops me from putting up with being treated like an idiot.

Which, interestingly, is exactly what you are doing to MNHQ.

FungusTheBogeymam · 14/08/2015 12:55

Struck me that they acted the way they did to piss Jeffrey off. And it made me laugh, thinking of how he was expecting a big, dramatic reaction and instead got treated as if he/it was a joke. He was a very silly boy, they reacted in kind.

maureendaly · 14/08/2015 12:53

You're not alone in that, Arkkorox. me too.

Arkkorox · 14/08/2015 12:50

I'm forever going to read outage as outrage aren't I...

Arkkorox · 14/08/2015 12:47

What exactly were they supposed to say?

' WE ARE BEING HACKED. EVERYONE PANIC. '

I think they handled what turned out to be a very silly hacker in the right way. Any more publicity and he would have got what he wanted.

plus him altering posts was quite funny

TheHouseOnTheLane · 14/08/2015 12:45

I think I got de-regged by him! I've had hell! I've had to name change and everything!

AwfulBeryl · 14/08/2015 12:42

So do people just hack sites for shits and giggles then, are hackers the new trolls ?

chocolatechip123 · 14/08/2015 12:37

I kept misreading it as 'site outrage' and assumed it was just business as usual.

MagpieCursedTea · 14/08/2015 12:32

I think the way MNHQ dealt with it gave minimal satisfaction to Jeffrey and that was what they were going for. He didn't get the big drama he wanted. He was treated like the joke that he was and that was the best approach.

CoogerAndDark · 14/08/2015 12:28

I also think that if a site you are using is experiencing problems then the onus is on you to decide whether to carry on using it (at the time and in the future). Site staff aren't Nanny. They aren't there to soothe your furrowed brow and chase away the Narsty Hacker before he De regs you. Simpler to shut down and Come back up when it's fixed, yes. Moral obligation, no.

The Log In problems don't seem to be linked to the hacking anyway. But I bet it's made Jeffrey's little day to be blamed for it.

Ubik1 · 14/08/2015 12:20

You have a duty to your posters when these things are happening to keep us all informed, we're not stupid and we deserve to be treated with a little more respect. Not fobbed off with half truths and blatant lies.

They don't have any duty to tell you anything at all. If you are getting this upset perhaps you should take a break, op.

It's just a chat site. Sometimes things go wrong. No one dies.

AwfulBeryl · 14/08/2015 12:18

I have seen the site outrage thread but I have been too lazy to go through all of it, I didn't realise it was that bad.

So do we know anything about who got in, why they did it and if they can or want to do anything with our info ?
Also if we de reg what happens to our reg details ?
Do they get wiped from your systems ?

CoogerAndDark · 14/08/2015 12:17

I do think shutting it down completely, sorting it and posting in broad terms what had happened and how would have been a good idea, but then again, it wasn't serious, other websites go down and all you get is 'sorry, we are having technical problems', so the response isn't a big deal, really.

Storm in a teacup. Ddos attacks aren't difficult to do and the resolute denial of anything going on while Jeffrey merrily altered MNHQ 's posts was pretty amusing.