IMPORTANT MASTODON PASSWORD SECURITY/PRIVACY ISSUE…
For everyone:
If you are using the same password for Mastodon that you use anywhere else, CHANGE YOUR PASSWORD NOW.
A hacker is stealing accounts on Mastodon using something called “credential stuffing.” This means they use email/password combinations stolen from other sites.
This is a common hacking technique. But right now someone is targeting Mastodon accounts.
You can check if your email is in a data breach elsewhere:
Create a new strong password:
- 12+ characters
- Capital/lowercase letters
- At least one special character
For admins:
The hacker is using the same unique user agent.
Go-http-client/1.1
We’re seeing a pattern of IPs, but they’re from varying ISPs. They’re also not changing the account emails.
#Mastodon #Password #InfoSec #OpSec #Security #Privacy #Hacked #Hacker
@markwyner@mas.to Also consider using two factor authentication so that even if someone steals your password they can't access your account: https://fedi.tips/using-two-factor-authentication-2fa-on-mastodon/