Vai al contenuto principale

← Torna al post

IMPORTANT MASTODON PASSWORD SECURITY/PRIVACY ISSUE…

For everyone:

If you are using the same password for Mastodon that you use anywhere else, CHANGE YOUR PASSWORD NOW.

A hacker is stealing accounts on Mastodon using something called “credential stuffing.” This means they use email/password combinations stolen from other sites.

This is a common hacking technique. But right now someone is targeting Mastodon accounts.

You can check if your email is in a data breach elsewhere:

https://haveibeenpwned.com

Create a new strong password:

  1. 12+ characters
  2. Capital/lowercase letters
  3. At least one special character

For admins:

The hacker is using the same unique user agent.

Go-http-client/1.1

We’re seeing a pattern of IPs, but they’re from varying ISPs. They’re also not changing the account emails.

#privacy #infosec #mastodon #security #password #hacker #hacked #opsec

166

Caricamento...

18
371

Caricamento...

@markwyner@mas.to

Thank you for the heads up BUT.

You need to be really careful with the message. This one implies that Masto is insecure and I'm sure that was not your intention. I think you should not have put the word "MASTODON" in the title.

The issue is not Masto itself but password reuse. Then there is the inadvertent "victim shaming" aspect too.

Please be very careful when doing a PSA like this and when boosting messages @briankrebs@infosec.exchange

0