Please or to access all these features

Site stuff

Join our Innovation Panel to try new features early and help make Mumsnet better.

See all MNHQ comments on this thread

Hackergate part four - PLEASE READ!

993 replies

RebeccaMumsnet · 20/08/2015 10:12

Previous thread here and original thread here

We will post here throughout the day with updates and info, please do post any questions and we will get to them as soon as possible.

If you need to get in touch off of the boards, please email [email protected], we have a team of people working through the inbox now and will get back to you ASAP but please do bear with us, it's very busy.

There is also a specific thread about passwords here.

Thanks all
MNHQ

OP posts:
Thread gallery
10
AllThatGlistensIs · 20/08/2015 11:50

outtogetyou ha! I'd imagine quite a few Grin

OutToGetYou · 20/08/2015 11:49

It is possible twirlypoo, but it seems MNHQ has forced a log out and password change of all but 10% of users so it is very likely if he/someone was doing this they would by now have been forced out anyway.

Justine confirmed that there was a bug in the forced password reset that was affecting around 10% of users and means they have not been forced out. I was forced to log in about an hour ago, but the new password from last night (pre any other forced log outs, which I never had) is still working. As it is unique to here I won't now change it unless I have to.

chamerion · 20/08/2015 11:48

Hi, I've just logged in using my old password.

Thought this wasn't possible after the forced reset and new complex password rules?

gamerC1 · 20/08/2015 11:48

I do like that people can change their passwords a zillion times... I haven't been able to change it once Grin

OutToGetYou · 20/08/2015 11:46

I'm wondering how many passwords are now variants of 'fuckoffhackers' or 'diehackerdie' etc :)

twirlypoo · 20/08/2015 11:42

akkak glad I am not going mad!

Agree it is maybe not likely he has 3038 tabs open (though when I shop online it feels similar) but if he kept key admin accounts and a few members on there then he could still cause distrust and chaos by posting whatever he liked. I am SO not techy mind. But that is possible isn't it? Or not?!

OutToGetYou · 20/08/2015 11:41

Ip addresses don't mean anything, half the time they refer to your ISP anyway, mine always says I am in Hull as that is where my ISP servers are based.

Charlesroi · 20/08/2015 11:40

I think the session applies to a specific computer. E.g a small file is stored on it that says you are a valid logged-in user, so they would have to be using that computer (or forge/steal the file) to have access to your account.

akkakk · 20/08/2015 11:38

twirly you are correct...

if your password was FRED on tuesday and they logged in as you

and you reset your password to MARY on wednesday... but they remain logged in...

then until they close their browser their session cookie will remain active as it was authenticated against your FRED password on tuesday when it was correct...

so they could still be logged in having used an old password...

two basic fixes for that - store the encrypted password in a cookie on the user's computer and check that every page (slows server down, but more secure) once you change your password - next check would fail...

terminate the session cookies from the server - not sure of detail of MN setup or how, but that is possible and in theory is what they were doing when they said they would force everyone to log out - by killing the session cookie from their end your session cookie would no longer be valid and you would need to log in again...

if you were able to go to an already logged in computer after that apparently happened, then the termination at the server could not have worked as intended...

however it is unlikely that the hacker has really got 3,038 tabs open :) trying to maintain sessions...

twirlypoo · 20/08/2015 11:38

It does, But......

I was on the list, so they had access to my username & password.

So lets say they opened up a tab with my log in.

I then open up a tab on MY laptop and change passwords etc. I am now logged in under that password.

They STILL have access under their open tab??

I was accessing my account this morning under both the new password (on my phone / the app) and the old password (open tab on laptop)

Theoretically, does that not mean that dad sec could still have access on his open session too?

TheTravellingLemon · 20/08/2015 11:33

I've tried to set up a completely new account with a new email, but I am not receiving the verification email.

I am a bit concerned that someone might have a session open in my account, even though I have changed my password about a gazillion times.

RebeccaMumsnet · 20/08/2015 11:31

@twirlypoo

I'm confused! Why would they have to log in with a password if they already had an open session?

But they wouldn't have had an open session unless they went in and physically used your work computer. To access any account you in need log in details. If you reset your password, from that point, your account was secure. Sorry to confuse, does that make sense?

OP posts:
TheDarkFairy · 20/08/2015 11:30

I only just got the email about this, too late to reset my password, so I just had to reregister. I was BathshebaDarkstone. Fucking hackers! Angry

MadrigalElectromotive · 20/08/2015 11:26

I'm confused! Why would they have to log in with a password if they already had an open session?

Yes, that is what I am trying to ask too!

MiaowTheCat · 20/08/2015 11:25

This reply has been deleted

Message withdrawn at poster's request.

twirlypoo · 20/08/2015 11:24

I'm confused! Why would they have to log in with a password if they already had an open session?

RebeccaMumsnet · 20/08/2015 11:23

@MadrigalElectromotive

It is not ideal twirlypoo, agreed. However, you had an active session with us and so were able to access the site. IF anyone had attempted to get into your account last night with the old password, they would not have been able to.

But if they were already in twirlypoo's account, then they will be able to continue to access it for as long as their session continues?

They would have to log in with a password. If the password was reset, it should be fine.

OP posts:
98percentchocolate · 20/08/2015 11:20

Thank you Polter Flowers and if solitare is around anywhere I'll take some of those cookies please if you are offering?

twirlypoo · 20/08/2015 11:20

98 I think you were lovely to suggest it Flowers

katherine surely dadsec could be sat with a load of open tabs and open sessions though? If I can, then why can't they?

Not having a go, just a bit alarmed /shocked that it can happen!

PolterGoose · 20/08/2015 11:17

This reply has been deleted

Message withdrawn at poster's request.

98percentchocolate · 20/08/2015 11:17

Consider me slapped down! For what it's worth, I think nurses, doctors, firemen, and everyone else who works on the front line deserves pizza too, but unfortunately if I bought you all pizza I may get in trouble with my bank Grin
Just trying to be nice as feeling a bit sorry for MNHQ. I was on the thread at midnight last night when they were still posting updates and trying to tackle the problem. Updates were still going through the night and were first thing again this morning. I'm certain they are taking it in shifts, but I imagine they are under a heck of a lot of pressure. They may be working for a multimillion pound company but they didn't sign on for this, and most probably had to leave families last night to sort it.

So yeah, stupid idea maybe but just trying to be nice.

MadrigalElectromotive · 20/08/2015 11:13

By they I mean DadSec...

MadrigalElectromotive · 20/08/2015 11:12

It is not ideal twirlypoo, agreed. However, you had an active session with us and so were able to access the site. IF anyone had attempted to get into your account last night with the old password, they would not have been able to.

But if they were already in twirlypoo's account, then they will be able to continue to access it for as long as their session continues?

RebeccaMumsnet · 20/08/2015 11:07

@twirlypoo

Can I just draw attention to something?

I was not kicked out, but on the advice of MNHQ last night logged out and changed my password anyway. I did this last night on the iphone using safari and then updated the app.

I've come to the office this monring (I work from home) and was busy checking threads / replying etc on tabs of mumsnet that were already open, when I realised they were logged in under the OLD password, but still working (I posted under it)

So, I've now logged out and updated my laptops computer - but for a while I was using the same account under 2 different passwords.

This doesn't seem very, er, good?

It is not ideal twirlypoo, agreed. However, you had an active session with us and so were able to access the site. IF anyone had attempted to get into your account last night with the old password, they would not have been able to.

OP posts:
twirlypoo · 20/08/2015 11:06

I have just written that message and then this happened (see screen shot) im sure it's just coincidence but I'm a tad paranoid now!

(Sent this using phone as laptop still not back on)

Hackergate part four - PLEASE READ!