Hi Beeple!

Here’s a vague version of events :

  • 11PM EST: Lemmy.world got hacked

  • 12:20AM EST: Blahaj.zone got hacked

  • 12:25AM EST: I shut down the server

  • 12:30AM EST: I make announcements to tell people about this

  • 12:45AM EST: I have an idea of what the problem is but there is no fix

  • 2:20AM EST: I go to sleep

  • 8:50AM EST: The server is booted back up, steps are applied to mitigate issues (Rotating JWTs, Clearing DB of the source of vulnerability, deleting custom emoji), UI is updated with the fix, CSP and other security options are applied

  • 11:40AM EST: We start testing things to make sure are working And well, now here we are.

If you have issues logging in or using an app:

  1. Log out if you somehow are still logged in

  2. Clear all cache, site data, etc.

  3. Hard refresh Beehaw using CTRL+F5

  4. Log back in.

If you still have issues, write to us at support@beehaw.org

To be clear : We have not been hacked as far as we know, we were completely unaffected. This was done preemptively.

Oh yeah, in case, you haven’t, this is a good opportunity and reminder to follow us on Mastodon as the communication line was still up despite Beehaw being down : https://hachyderm.io/@beehaw

  • The Cuuuuube@beehaw.org
    link
    fedilink
    English
    arrow-up
    13
    ·
    2 years ago

    To add onto what @Lionir said, you’ll never be wrong to change your password, even if much like in this case it isn’t warranted. For future reference, my recommendation is “if you have to ask, rotate your password.” Finding out later you didn’t have to is so much better than finding out later you should have

    • comicallycluttered@beehaw.org
      link
      fedilink
      English
      arrow-up
      6
      ·
      2 years ago

      Oh, yeah, totally agreed.

      And I like the way you worded that. Really good rule of thumb and easy to remember for everyone.

    • abhibeckert@beehaw.org
      link
      fedilink
      English
      arrow-up
      6
      ·
      edit-2
      2 years ago

      I disagree - rotating passwords comes at a cost especially for people who don’t use a good password manager (and that is basically everyone). It’s security theatre and generally creates distrust between people offering security advice and the people who (hopefully) are listening.

      There are times when it should be done, but don’t do it without a reason.