Vai al contenuto principale

IMPORTANT MASTODON PASSWORD SECURITY/PRIVACY ISSUE…

For everyone:

If you are using the same password for Mastodon that you use anywhere else, CHANGE YOUR PASSWORD NOW.

A hacker is stealing accounts on Mastodon using something called “credential stuffing.” This means they use email/password combinations stolen from other sites.

This is a common hacking technique. But right now someone is targeting Mastodon accounts.

You can check if your email is in a data breach elsewhere:

https://haveibeenpwned.com

Create a new strong password:

  1. 12+ characters
  2. Capital/lowercase letters
  3. At least one special character

For admins:

The hacker is using the same unique user agent.

Go-http-client/1.1

We’re seeing a pattern of IPs, but they’re from varying ISPs. They’re also not changing the account emails.

#privacy #infosec #mastodon #security #password #hacker #hacked #opsec

166

Caricamento...

18
371

Caricamento...

Commenti (18)

@markwyner@mas.to I'm guessing 2FA is also effective? Asking as a newbie admin...

0

@markwyner@mas.to

Qhy should anyone have two time the same password?

0

@markwyner@mas.to pro Tipp: use a passphrase. way easier to remember then a scrambled soup of characters. though make sure its something that doesn't form a common sentence. more like 4 or more words that are easy for you to remember.

https://xkcd.com/936/

replace letters with numbers, add capitalization, and some additional special chars.

and if spaces aren't allowed, use dashes or underscores.

before I chose a password manager I had a template passphrase where each site got its own unique spin on it.

0

@markwyner@mas.to Somehow I don't want to provide vital data to potential security breach(es).

Imagine that.

0

@markwyner@mas.to And this applies to 'just' mastodon how? That's been going on for years, anywhere where there is internet...

0

@markwyner@mas.to dear everyone, if you're using ANY password in more than one place, go get a password manager and start using random passwords everywhere -- this is not a Mastodon issue, this is a web login issue. I highly recommend Bitwarden.

0

@markwyner@mas.to
this is run by a microsoft regional director – not my choice of trust

0

@markwyner@mas.to

use a password manager. Use a password manager. Use A Password Manager. USE A PASSWORD MANAGER

I favor KeePass (https://keepass.info ). I have a nice Android port that lives on my phone. No internet connection, Open Source so it's reasonably trustworthy. Every password I have to every site I visit that requires one is unique.

0

@markwyner@mas.to Also consider using two factor authentication so that even if someone steals your password they can't access your account: https://fedi.tips/using-two-factor-authentication-2fa-on-mastodon/

0

@markwyner@mas.to thanks for the tip. While I wasn't reusing, turns out my password was very inadequate to my standards and I was mostly relying on 2fa.

0

@markwyner@mas.to

Thank you for the heads up BUT.

You need to be really careful with the message. This one implies that Masto is insecure and I'm sure that was not your intention. I think you should not have put the word "MASTODON" in the title.

The issue is not Masto itself but password reuse. Then there is the inadvertent "victim shaming" aspect too.

Please be very careful when doing a PSA like this and when boosting messages @briankrebs@infosec.exchange

0

@markwyner@mas.to Also a good time to see if you're using a compromised password: haveibeenpwned.com

0

@markwyner@mas.to thanks for bringing this up. it's important

0

@markwyner@mas.to But I have been using "blink182" and "password123" for decades, I can't remember a new password!!!

0

@markwyner@mas.to
Thanks for the awareness note to help people being safer.

Aaaand mandatory plug: https://xkcd.com/936/

0

@markwyner@mas.to For what it's worth, that user agent I think is the default Go HTTP client user agent for making requests with net/http.

0

@markwyner@mas.to How widespread is this Mark? A few accounts or are we talking about thousands of compromised profiles?

0