Denise (
denise) wrote in
dw_maintenance2017-02-25 09:42 pm
![[staff profile]](https://www.dreamwidth.org/img/silk/identity/user_staff.png)
![[site community profile]](https://www.dreamwidth.org/img/comm_staff.png)
Two quick things
Cloudflare
We've had people ask us about the Cloudflare leak reported a few days ago. We are Cloudflare customers, and it is possible that login cookies or passwords may have been exposed as part of the incident. We believe the risk to you is relatively low -- it was a small percentage of Cloudflare's requests that were involved over a relatively short period of time, and we haven't found any evidence that anything from us was among them. This is not an absolute guarantee that none of your accounts were affected, but we don't think the likelihood is very high.
Because we believe the risk to be low, we aren't automatically expiring everyone's session cookies and requiring you to log back in and change your password -- whenever we do that, it does lock some people who they can't remember their passwords and no longer have access to their confirmed email addresses out of their accounts, and we believe that will affect more people in this case.
Still, it's always a good idea to change your passwords regularly, and now would be a good time to do it, especially if you want peace of mind. We have a FAQ on how to change your password. If your browser logs you in automatically and you don't remember your password, you can reset it. If you've forgotten your password and no longer have access to your most recent confirmed email address, you can have the password reset email sent to any email address you've confirmed on your account by entering both your username and your old email address at the Lost Info page.
Unfortunately, if you've forgotten your password and no longer have access to any email address you've confirmed on your account, you probably won't be able to reset your password. In some cases, if you've previously paid for your account, we can validate your payment details to confirm your identity and reset your password. If you can't reset your password, but think you may have paid for your account in the past, you can open a support request in the Account Payments category and I'll check into it for you.
LiveJournal imports/crossposts/feeds
LiveJournal has temporarily blocked
EDIT 26 Feb noon EST: LJ unblocked and whitelisted us this morning, so all is working again!
no subject
no subject
You may know that many of us who fled from LJ (especially on December'16) usually set up crossposting from DW to our old LJ-accounts to keep our old audience.
However, LJ is constantly increasing their censorship attempts.
So they *may* track the DW IPs that (cross-)post entries that Russian censorship considers bad, and they may block your addresses for this very reason.
Not sure if this helps, but just letting you know.
(no subject)
no subject
no subject
no subject
no subject
(no subject)
(no subject)
(no subject)
(no subject)
(no subject)
no subject
Lots of LJ users flee to DW.
LJ blocks DW from accessing their site, so that you can't crosspost or import stuff. (At least not directly, could you download your entire LJ using Semagic and then re-upload it to DW?)
Pretty petty, there, LJ.
no subject
no subject
Thanks for explaining what happened. Regardless of what crossposting users choose, I hope they unblock you soon, because that is just stupid.
no subject
no subject
no subject
no subject
However, I can't agree that changing passwords regularly, without a specific reason, is a good idea. It doesn't improve the password's security, and it makes it more likely people will pick easy-to-remember passwords or have to write them down.
(no subject)
(no subject)
no subject
no subject
no subject
no subject
I have lived here happily for a few years now, but as not all my favourite comms have moved, I have conversations/relationships with people 'over there' and it seems churlish not to crosspost when I can go and read their posts so easily. I do hope things get sorted out.
My biggest concern is that as I originally bought a permanent membership on LJ (back in the olden days), I use their Scrapbook feature to host my pics and am not at all sure what to do - all my pics are backed up on my computer but not organised into albums. If anyone can suggest a sensible alternative I would be happy to move everything - and yes, I know DW are now hosting pics but as I said, I have organised albums etc.
no subject
Perplexed
Re: Perplexed
Re: Perplexed
Re: Perplexed
no subject
Also, the article you've linked to said most of the cloudbleed activity happened between 13th -18th Feb. Within that period I bought a paid account and a large number of icon slots (on another DW account) - would my credit card details, address or anything like that potentially have been exposed IF by some small chance this issue affected my Dreamwidth session? Or journal entries? Or would it just be passwords and or/login cookies. I do realise you think it very unlikely Dreamwidth was affected - I'm just curious about what might have been exposed if you were.
And excelllent news that LJ has whitelisted DW again. :) DW is my journalling home now, but I do still x-post to LJ.
(no subject)
(no subject)
CF maybe blocking Russian users from DW
If you are behind Russian IP, you cannot reach DW. If you are routing via VPN in Iceland, DW looks OK.
Also CF cache seem to work slow if at all on low traffic sites, so if you post a pic on DW from your self-hosted site, DW is unable to fetch it for weird reason.
Re: CF maybe blocking Russian users from DW
Re: CF maybe blocking Russian users from DW