IMPORTANT MASTODON PASSWORD SECURITY/PRIVACY ISSUE…
For everyone:
If you are using the same password for Mastodon that you use anywhere else, CHANGE YOUR PASSWORD NOW.
A hacker is stealing accounts on Mastodon using something called “credential stuffing.” This means they use email/password combinations stolen from other sites.
This is a common hacking technique. But right now someone is targeting Mastodon accounts.
You can check if your email is in a data breach elsewhere:
Create a new strong password:
- 12+ characters
- Capital/lowercase letters
- At least one special character
For admins:
The hacker is using the same unique user agent.
Go-http-client/1.1
We’re seeing a pattern of IPs, but they’re from varying ISPs. They’re also not changing the account emails.
#Mastodon #Password #InfoSec #OpSec #Security #Privacy #Hacked #Hacker
@markwyner@mas.to
use a password manager. Use a password manager. Use A Password Manager. USE A PASSWORD MANAGER
I favor KeePass (https://keepass.info ). I have a nice Android port that lives on my phone. No internet connection, Open Source so it's reasonably trustworthy. Every password I have to every site I visit that requires one is unique.