Vai al contenuto principale

← Torna al post

IMPORTANT MASTODON PASSWORD SECURITY/PRIVACY ISSUE…

For everyone:

If you are using the same password for Mastodon that you use anywhere else, CHANGE YOUR PASSWORD NOW.

A hacker is stealing accounts on Mastodon using something called “credential stuffing.” This means they use email/password combinations stolen from other sites.

This is a common hacking technique. But right now someone is targeting Mastodon accounts.

You can check if your email is in a data breach elsewhere:

https://haveibeenpwned.com

Create a new strong password:

  1. 12+ characters
  2. Capital/lowercase letters
  3. At least one special character

For admins:

The hacker is using the same unique user agent.

Go-http-client/1.1

We’re seeing a pattern of IPs, but they’re from varying ISPs. They’re also not changing the account emails.

#privacy #infosec #mastodon #security #password #hacker #hacked #opsec

166

Caricamento...

18
371

Caricamento...

@markwyner@mas.to pro Tipp: use a passphrase. way easier to remember then a scrambled soup of characters. though make sure its something that doesn't form a common sentence. more like 4 or more words that are easy for you to remember.

https://xkcd.com/936/

replace letters with numbers, add capitalization, and some additional special chars.

and if spaces aren't allowed, use dashes or underscores.

before I chose a password manager I had a template passphrase where each site got its own unique spin on it.

0