IMPORTANT MASTODON PASSWORD SECURITY/PRIVACY ISSUE…
For everyone:
If you are using the same password for Mastodon that you use anywhere else, CHANGE YOUR PASSWORD NOW.
A hacker is stealing accounts on Mastodon using something called “credential stuffing.” This means they use email/password combinations stolen from other sites.
This is a common hacking technique. But right now someone is targeting Mastodon accounts.
You can check if your email is in a data breach elsewhere:
Create a new strong password:
- 12+ characters
- Capital/lowercase letters
- At least one special character
For admins:
The hacker is using the same unique user agent.
Go-http-client/1.1
We’re seeing a pattern of IPs, but they’re from varying ISPs. They’re also not changing the account emails.
#Mastodon #Password #InfoSec #OpSec #Security #Privacy #Hacked #Hacker
@markwyner@mas.to pro Tipp: use a passphrase. way easier to remember then a scrambled soup of characters. though make sure its something that doesn't form a common sentence. more like 4 or more words that are easy for you to remember.
https://xkcd.com/936/
replace letters with numbers, add capitalization, and some additional special chars.
and if spaces aren't allowed, use dashes or underscores.
before I chose a password manager I had a template passphrase where each site got its own unique spin on it.