Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

After the storm - suggestions

35 replies

akkakk · 19/08/2015 23:03

During today there have been various good suggestions about what perhaps should happen afterwards going forwards - and I thought it might be useful to have them in one place...

Just to acknowledge:

  • Mumsnet is a commercial operation - so ultimately their decision
  • Mumsnet has no value without its users, so their opinion is v. important
  • Mumsnet has a really strong role particularly for those who at times are vulnerable / needing help & support etc. - so security is very important.

Random thoughts - so add yours...

Security Audit
After this is all over, MN should bring in an established / expert external company to run a security audit

  • software scan for vulnerabilities
  • human scan

Penetration Testing
They should then set up a test version of the site / offline version and pay a company to regularly run penetration testing against it... if it has dummy data in it, we could all play and maybe prizes for any successful hacking :)

Software Audit
They should get a company in to run a software audit looking at old code / current code /vulnerabilities / efficiencies / etc. However good coders might be, it is easy to make mistakes - having another company as a sounding board is very helpful

Software Updates
All software updates should be externally audited before going live
All software updates should go via the test site for penetration testing and vulnerability checking before going live

Passwords
When you log in the script sees your clear text password - encrypts it and then checks against the stored password - at that point in the script there could be an analysis on how secure it is - if not secure enough, make the user change it. In theory all should be more secure with the recent change, but security needs will undoubtedly change and this is the place to do it...

Future Hacking
If this happens again, there should be a strict procedure:

  • take site offline
  • put up message
  • use facebook to communicate with users / issues
  • test offline
  • fix
  • back online

online protection
evaluate the need for stronger online protection - using companies like verisign to protect against DDOS etc.

any other thoughts - do add them!

OP posts:
BertieBotts · 20/08/2015 00:09

In fact Haiwai appears to be a Japanese expat site based in San Francisco.

It has such interesting page titles as:
Jewish Wealth Education
Deal with leftover bread coup
American baby learning to teach Chinese
US Green Card science
Shaoxing Prime Razor
Restaurant to find someone to sell

Blimey, sounds fun Grin Maybe I'll come too!

HoneyDragon · 20/08/2015 00:08

I appear to have misplaced an i Confused

How embarrassing.

BertieBotts · 20/08/2015 00:03

Haiwai? Where the fuck is that? Grin

IgnoreMeEveryOtherReindeerDoes · 19/08/2015 23:55

Still think a ignore poster button should be added

Pedestriana · 19/08/2015 23:44

Penetration testing - sorry, can't stop giggling. Sometimes it's as if I'm 12.

ChristineDePisan · 19/08/2015 23:44

Remember that you cannot over communicate (I'm still seeing posters on threads asking "what is this list, should I worry if I'm on it?").

If you don't have in-house capacity for emergency comms, get a specialist agency on the books. There's been no sense of a clear comms strategy (key messages, call to action etc), and some of the messaging has been either disingenuous, misleading or potentially dangerous (eg advising posters to go onto the hacker's website to check whether they are on the list...). This is expert territory, don't be afraid to admit you need assistance in a crisis

Make proper use of the comms channels that you do have (why are you tweeting about flannels and campaigns? Why isn't the most recent tweet a "we are open for business again but please re-set your password"?)

Maryz · 19/08/2015 23:31

This reply has been deleted

Message withdrawn at poster's request.

catzpyjamas · 19/08/2015 23:13

Or even akkakk
-sort my autocorrect

catzpyjamas · 19/08/2015 23:12

staffing
-Employ Akaka?

HoneyDragon · 19/08/2015 23:11

And monetary donations people wish to make should be sent to me