Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

See all MNHQ comments on this thread

Hackergate part four - PLEASE READ!

993 replies

RebeccaMumsnet · 20/08/2015 10:12

Previous thread here and original thread here

We will post here throughout the day with updates and info, please do post any questions and we will get to them as soon as possible.

If you need to get in touch off of the boards, please email [email protected], we have a team of people working through the inbox now and will get back to you ASAP but please do bear with us, it's very busy.

There is also a specific thread about passwords here.

Thanks all
MNHQ

OP posts:
Thread gallery
10
98percentchocolate · 20/08/2015 14:10

Leedy - yy I was talking about this to somebody yesterday who admitted that they have all of their passwords set to "password" or "password1".

leedy · 20/08/2015 14:07

(obviously the sheer fact that there was a security hole to exploit does mean they need to improve things to stop it happening again, I don't think it having been a phishing attack means that the Mumsnet systems themselves had nothing to do with it)

TheImminentGin · 20/08/2015 14:01

Hello all. Signed back in with brand new shiny password. Gosh it wasn't hard or time consuming.
Slight glitch on re entry as the page came up in text.
Seems fine now I have made my way to active convos.
Although the header bar flutters pink and has been doing for the last few days, is that usual?
Well done everyone at MNHQ and large gins all round as often as required.
Star Star Star

RepeatAdNauseum · 20/08/2015 13:59

Rebecca - Old, old password. It would fail the new password specification on two counts.

I will update it, when it kicks me out, but I thought it might be useful to know that it hasn't happened yet.

ppeatfruit · 20/08/2015 13:59

Thanks Rebecca Grin BTW is dh right in saying that when we click on 'links' we are leaving ourselves , and you? open to hacking?

DawnOfTheDoggers · 20/08/2015 13:57

This reply has been deleted

Message withdrawn at poster's request.

leedy · 20/08/2015 13:52

"Unless the majority of people have 1 password for all sites they visit, but that couldn't be true right?"

Oh, you'd be surprised.

"I also don't think this was a phishing exercise, most likely it will be a disgruntled ex employee or ex tech company/employee MN has used in the past."

If you look at the technical side of the attack thingy thread, their tech team seem to have found what looks like the security hole used to gather users details when they logged in.

I'm not sure why some people are being so WAKE UP SHEEPLE, DO NOT DRINK THE MUMSNET KOOLAID! about the claims by MNHQ that the passwords were compromised using some kind of phishing mechanism, it seems by far the most plausible explanation.

(goes off muttering about hackergate truthers, etc.)

diddl · 20/08/2015 13:49

I'm having trouble logging in.

I log in (or think I have!) & just get the log in page again.

Am checking the URL, but am concernd that once the log in page comes up again, I've already put my password in iyswim.

Zucker · 20/08/2015 13:47

I was on the list of 3000 United we Stand. Anyway I've now changed my password.

Why the need to frantically change all my passwords for any site I may have an account for? I'm not understanding the blind panic some people are having about this. Unless the majority of people have 1 password for all sites they visit, but that couldn't be true right?

I also don't think this was a phishing exercise, most likely it will be a disgruntled ex employee or ex tech company/employee MN has used in the past. I'm finding it hard to believe that this hacker was also the same hacker involved over a year ago and sat on that information until now to break into a server so they could take MN advertising partner details/emails. Plus that MN did nothing to change passwords or improve security on that server.

I know they really owe us no explanation, but jeesh we're not thickos.

overthemill · 20/08/2015 13:42

God I'm fed up with this! You made me log off and change passwords yesterday and now again today? No way am I doing it again

Hulababy · 20/08/2015 13:38

I had forced log out on my laptop and on my phone - both on mobile website (via safari) and on mobile app (iPhone). Had changed password yesterday, but now redone. New password up and running.

RaspberryOverload · 20/08/2015 13:35

I can add:

Gumtree
LinkedIn

to your list

akkakk · 20/08/2015 13:35

Girlwhowearsglasses I can understand that would be a difficult situation, but that is really difficult for websites to manage... arguably if you have two ipads in a household (and many do) it becomes difficult for a website to differentiate without your trusting them with more personal information to identify each... even then, all they could do is give you the option to log a specific device out by killing the session remotely - a nice to have, but the lack of it is not a security risk / issue...

ultimately in that scenario the user shouldn't be leaving a device logged in - either remember to log out / use a password or fingerprint ID on the device...

I do think there is a balance of responsibility and ultimately a lot of the responsibility is actually ours - the websites might be a convenient scapegoat, but it is the user's choice what they post on there, if information is sensitive and at risk it shouldn't be posted...

StephanieBeacham · 20/08/2015 13:34

Just a short list of sites to make sure you haven't forgotten to update with better/dfferent passwords (please add to it if you like)

Facebook
Twitter
Amazon (important due to payment process being quite undemanding)
Bank
Paypal
Ebay
Google
Apple
Lottery
Mobile phone account

I can't think of any more.

RebeccaMumsnet · 20/08/2015 13:34

@RepeatAdNauseum

Snap.

I was logged out on the mobile site, and through that was it, but it let me log back in with the old password fine, no prompt to change it.

Old, old password or reset recently and matches new password parameters?

OP posts:
RebeccaMumsnet · 20/08/2015 13:29

@ppeatfruit

Agree PegsPigs

Does anyone know if we should change our user names? Mn doesn't say anything.

This is up to you ppeat, if your password is reset you shouldn't need to but you can if you would like.

OP posts:
SuffolkNWhat · 20/08/2015 13:25

Just been forced out and relished in with most up to date password (the new system)

RepeatAdNauseum · 20/08/2015 13:18

Snap.

I was logged out on the mobile site, and through that was it, but it let me log back in with the old password fine, no prompt to change it.

StatisticallyChallenged · 20/08/2015 13:15

Just FYI: I still haven't been forced to log out at any point, both on google chrome desktop (windows) or google chrome android mobile site.

I've just been able to log out and back in on the mobile site. I wasn't forced to change my password.

I've changed my password one (yesterday when the first load of shit hit the fan) and am personally fine because it already met the higher strength requirements so I haven't manually changed it. But I have not been hit by the second forced change at all.

Also as an FYI - the email about the first change only got to DH's email (he has an account of his own) this morning so some people might well still not have received it. I checked, it was genuine links not hacked.

iamaboveandBeyond · 20/08/2015 13:08

Right, i am off to a wedding. Flowers
If anyone posts as me, it isnt me!

ppeatfruit · 20/08/2015 13:07

Agree PegsPigs

Does anyone know if we should change our user names? Mn doesn't say anything.

SoupDragon · 20/08/2015 13:06

that of having a logged in device that allows someone in possession of that device to see your posting history

I believe that is the poster's own responsibility and no one else's. If you can't control that sort of thing yourself, you shouldn't be posting private stuff on a forum.

Girlwhowearsglasses · 20/08/2015 13:01

Yes akkkk I know the security is a game of keepy uppy - I was referring to a more prosaic security breach that needs sorting - that of having a logged in device that allows someone in possession of that device to see your posting history: so your in-laws seeing you posted about them on an iPad you left with them while they babysit for you- for an actual life example. This isn't the same level as a password breach allowing widespread id theft, but could cause serious personal repercussions (imagine someone accessing help on MN for DV for example, or incredibly sensitive personal posts)

PegsPigs · 20/08/2015 12:59

All the people trying to be nice to MNHQ staff Flowers Stephanie & 98 in particular.

It's never wrong to be nice and anyone saying 'they work for a multi million pound business they can afford pizza' or 'it's their job, nurses don't get pizza bought for them and they do a fantastic job' is missing the point. Nurses sign up to put themselves in life or death dramas everyday. However they still have really bad days when they lose children or people they've worked on for a long time but don't pull through. They're allowed our sympathy and if we know them we should be buying them pizza. Or you could pay it forward in a hospital canteen and offer to pay for a coffee for the next health care professional who walks in looking down. So MNHQ are also allowed to have shitty days despite working for an online organisation who might reasonably be expected to be hacked occasionally. But this must rank as a really bad day at the office and are deserving of our sympathy and gestures.

Girlwhowearsglasses · 20/08/2015 12:54

Sorry forgot the screen shot from Facebook. It's just taken me through my recent activity so I can see anything suspicious

Hackergate part four - PLEASE READ!