denise: Image: Me, facing away from camera, on top of the Castel Sant'Angelo in Rome (Default)
Denise ([staff profile] denise) wrote in [site community profile] dw_maintenance2020-03-17 04:31 pm

(no subject)

Some of you have noticed an uptick in spam accounts following you this week -- it was because a group of spammers were able to take over some legit accounts and use them for spam. (Our usual antispam efforts have worked pretty well to take care of newly created spam accounts, so spammers are going for the old ones instead.) It does appear that the accounts that were hijacked had used the same password they used on Dreamwidth for other sites, and the spammers found that username/password combination in one of the many black market venues for password resale.

We think we've managed to catch and suspend all the accounts that were being used for spamming -- if yours was one of them, open a support request in the Terms of Service category and we'll help you resecure your account so we can unsuspend it. If you spot one that our automated scan missed, open a support request in Anti-Spam and we'll take a look as soon as we get through the backlog of the already-reported ones. If you spot one and it's already been suspended, you don't have to report it.

This is a great time to remind everyone: please don't reuse passwords for multiple sites! The best and most secure way of handling passwords is to download a password manager, like Dashlane, 1Password, Keeper, LastPass, or Zoho. (Everyone has their own favorite, but those are all reputable and secure.) Let the password manager generate and remember passwords for you. This improves security for everyone!

(Edit:) I also forgot to remind people: you can check to see if your information has appeared in a data breach at Have I Been Pwned? It's a legitimate security research site that keeps a database of which account information is for sale on the black market. They don't tell you which passwords were compromised, just whether your email address appears in a collection of passwords, and they don't have every dataset that's circulating on the black market, but if your email address gets a result there, you should change your password on that site immediately, change the password on any site that you used the same password for (and make it a unique password!), and never use that password again. People who have the black market file try those username/password combinations on every site they can find to see how many accounts they can get into.
frith: Violet unicorn cartoon pony with a blue mane (FIM Twilight friendly)

[personal profile] frith 2020-03-17 08:40 pm (UTC)(link)
Thank you for the heads-up and for swatting those parasitic spammers. ^_^
alexseanchai: Katsuki Yuuri wearing a blue jacket and his glasses and holding a poodle, in front of the asexual pride flag with a rainbow heart inset. (Default)

[personal profile] alexseanchai 2020-03-17 08:43 pm (UTC)(link)
thank you!
spectrier: a cropped image of a black horse with a purple mane with long white eyelashes. (Default)

[personal profile] spectrier 2020-03-17 08:43 pm (UTC)(link)
I did wonder why I had people subscribing to me out of nowhere! Thanks for the explanation and quick resolution of the issue.
weofodthignen: selfportrait with Rune the cat (Default)

[personal profile] weofodthignen 2020-03-17 08:50 pm (UTC)(link)
Ah, that had gone through my mind when I saw a mystery subscription; sorry to see I was apparently right, and thanks for being on top of things.
commoncomitatus: ([FS] Aggressive negotiations)

[personal profile] commoncomitatus 2020-03-17 08:52 pm (UTC)(link)
Thanks for all your hard work on this! <3
stormy: βͺ ππŽπ“πˆπ‚π„ ❫ 𝑫𝑢 𝑡𝑢𝑻 𝑻𝑨𝑲𝑬 𝑴𝒀 𝑰π‘ͺ𝑢𝑡𝑺 ⊘ (Default)

[personal profile] stormy 2020-03-17 08:59 pm (UTC)(link)
Thank you for the heads up! I double checked and changed any compromised passwords today.
juliet316: (Torchwood: Ianto Jones)

[personal profile] juliet316 2020-03-17 09:06 pm (UTC)(link)
Had a couple of suspicious accounts try to subscribe to me as well. I just ignored them.
brooksmoses: (Default)

[personal profile] brooksmoses 2020-03-17 09:54 pm (UTC)(link)
Thanks! Looks like the one that subscribed to me (and which I ignored at the time) is now suspended.
juliet316: (Doctor Who Twelve Flowers)

[personal profile] juliet316 2020-03-17 10:41 pm (UTC)(link)
I checked after I made my earlier post, they're already suspended.
naye: tiny raindeer in a hat making happy arms and grinning (yay!)

[personal profile] naye 2020-03-17 09:15 pm (UTC)(link)
Brilliant. Thank you so much for dealing with them!
dewline: Text - "On the DEWLine" (Default)

[personal profile] dewline 2020-03-17 09:16 pm (UTC)(link)
Decided to pre-emptively ban-hammer my three suspects.

Thanks in any case!
dewline: Text - "On the DEWLine" (Default)

[personal profile] dewline 2020-03-17 09:40 pm (UTC)(link)
Looking for the names now.
dewline: "Not Fail" (not fail)

[personal profile] dewline 2020-03-17 09:43 pm (UTC)(link)
I found the names. You got all three!
paserbyp: (Default)

[personal profile] paserbyp 2020-03-17 10:32 pm (UTC)(link)
I just checked also and you got one, who tried to hack my account! Excellent job! Thank you so much!
Edited 2020-03-17 22:42 (UTC)
cmcmck: (Default)

[personal profile] cmcmck 2020-03-17 09:54 pm (UTC)(link)
Thanks!

No problem here but I was hearing from friends who had been hit
lauand: (Gojyo - Fuck up)

[personal profile] lauand 2020-03-17 09:56 pm (UTC)(link)
Thanks for the info!
navaan: (Default)

[personal profile] navaan 2020-03-17 09:57 pm (UTC)(link)
I just noticed one today. Thank you for the info and all the work you're doing!! β™₯
veritas_poet: (Type)

[personal profile] veritas_poet 2020-03-17 10:20 pm (UTC)(link)
Thanks for keeping on top of this and for informing us. Y'all are the best.

[personal profile] unfavorableinstigation 2020-03-17 10:36 pm (UTC)(link)
Adding to the thank-yous! =D

And thank you to the swift response to my own report, as well; glad it's being taken care of.
paserbyp: (Default)

[personal profile] paserbyp 2020-03-17 10:36 pm (UTC)(link)
How about to add two factors authentication? To much work?
paserbyp: (Default)

[personal profile] paserbyp 2020-03-17 10:40 pm (UTC)(link)
Got it.
the_beasts: Deep in an ancient forest where green moss covers all, little glowing balls of coloured light float about in the mist. (Default)

[personal profile] the_beasts 2020-03-17 11:01 pm (UTC)(link)
in case this feedback helps at all:

two-factor authentication has locked us out of a lot of websites in recent years. we do not have a mobile phone of any kind and haven't for 8 years, and even if we did we wouldn't be willing to give out our phone number to websites because that feels intrusive and stalkerish to us. knowing that we could get unexpected messages from a website in an offline/in-person way at any time would make us uncomfortable and stressed in our everyday life. so if a website demands a phone number specifically and won't let us opt out of two-factor authentication or use some kind of online-only method of authenticating, we are locked out of the website and can't use it at all.

personally, we are disturbed by the gradual creep of websites and online things into individuals' physical in-person life and location-compromising personal data. the grabby-hands act a lot of sites do and the crawling tendrils that seek out your physical self and cling. the whole point of the internet, to us, has always been that it exists in dataspace, not in meatspace, and you can safely do any and all internet-things without them attaching to your physical life. the internet is not permitted to invade our physical personal space.

thankyou very much for listening! and although we personally were unaffected by the spammers, thanks for your hard work and clear communication with users. it always makes us feel more secure whenever we see a post from you guys about this sort of thing - you demonstrate that we can rely on you to fix things and that you'll tell us when things happen. this is what makes us comfortable enough to speak to you and offer feedback. <3
the_beasts: Deep in an ancient forest where green moss covers all, little glowing balls of coloured light float about in the mist. (Default)

[personal profile] the_beasts 2020-03-17 11:30 pm (UTC)(link)
that is such good news! thankyou so much for your reply! :D

we thought there must be better ways to do it than requiring phone numbers, we just haven't personally seen anywhere do so and call it 2FA. the only times we've heard the phrase so far have been in reference to requiring phone numbers, so that was the only pattern we had for it, but still we thought it must be more than that (hence saying -if- they require a phone number). we're delighted to learn that our suspicions were correct - there are better ways to do it! and we're unsurprised that you folks are on top of that and being awesome. x3

we're also very glad to hear about the ways 2FA can be used to keep at-risk people safe, and otherwise be extremely helpful. that's excellent and we're very much in favour of the option being there for those who need or want it! we see what you mean about the situations like you mentioned, and we agree it's very important to offer people ways to keep themselves and their data secure no matter what their situation. we're very glad you're working on that, thankyou.

it is sooo good to hear from you that you'll never make it mandatory. we thought you likely wouldn't, knowing the dreamwidth staff and style - your approach has always been in favour of options and choice and diversity and accessibility, which has been instrumental in this place becoming our no1 favourite website ever and online home - but we and accessibility in general get shut out and left by the wayside so consistently that it's still extremely reassuring to hear confirmation from you that you're not going to go that way. so even though we know that in general it's not the sort of thing dreamwidth is likely to do, this website means a lot to us and it's a huge relief to hear specific confirmation that we're definitely not going to lose access to it. thankyou very much for your dedication to keeping things accessible and preserving users' free will and choices. <3

you all are wonderful. <3 <3 <3
lizvogel: Banana: Good.  Crossed streams: Bad. (Good Bad)

[personal profile] lizvogel 2020-03-18 07:10 pm (UTC)(link)
Thank you for not making 2FA mandatory! I'm another one who doesn't thinking giving my cell # to everybody on the planet in any way improves my security. Plus, it's an enormous PITA when I routinely access certain accounts from different devices (home computer vs. traveling computer, etc.). I'd much rather be good about my passwords and take reasonable care to maintain my own security.

2FA-via-text-message is only slightly more secure than no 2FA at all, since texts aren't very secure, so most places have moved away to using a phone number for 2FA.

I wish. My banks both still insist on texts. Which is why I don't have online banking set up with either of them.

alexseanchai: Katsuki Yuuri wearing a blue jacket and his glasses and holding a poodle, in front of the asexual pride flag with a rainbow heart inset. (Default)

[personal profile] alexseanchai 2020-03-19 01:09 am (UTC)(link)
one of my perpetual complaints lately is "I wish fandom would move from Tumblr to Dreamwidth, but that isn't going to happen unless Dreamwidth sells its soul", since the main draw of Tumblr is media hosting and that kind of server space costs money and there might not be any ethical means to get Dreamwidth that much money.

thank you for refusing to sell your soul.
thenewbuzwuzz: converse on tree above ground (Default)

[personal profile] thenewbuzwuzz 2020-03-19 11:57 am (UTC)(link)
I love you, guys. Thanks for all you do.
20_00: (Default)

[personal profile] 20_00 2020-03-18 05:10 am (UTC)(link)
Hello. Please do not make two-factor authentication mandatory. In my country it is dangerous to use a phone for authorization. This does not reduce the likelihood of hacking, but rather increases it. Thanks.

upd. I saw below that you are not going to make it mandatory. OK :)
Edited 2020-03-18 05:13 (UTC)
20_00: (Default)

[personal profile] 20_00 2020-03-19 02:51 am (UTC)(link)
Thanks!
weofodthignen: selfportrait with Rune the cat (Default)

[personal profile] weofodthignen 2020-03-18 06:14 am (UTC)(link)
Thirding the request not to make 2FA mandatory; I see your statement that you won't, but you may not realize just how much of a problem being required to have a smartphone would be to some (the cost, just for starters), and if I lose my laptop or it quits working, I want to be able to continue with my online life! I'm sure there are many people who don't have two devices.
ex_flameandsong751: An androgynous-looking guy: short grey hair under rainbow cat ears hat, wearing silver Magen David and black t-shirt, making a peace sign, background rainbow bokeh. (happiness)

[personal profile] ex_flameandsong751 2020-03-17 11:07 pm (UTC)(link)
Thank you for the very speedy resolution!
ppk_ptichkin: (Default)

[personal profile] ppk_ptichkin 2020-03-17 11:30 pm (UTC)(link)
I was about to report a spammer or three. Thank you for cleaning this up!
turgutmakbak: (Default)

[personal profile] turgutmakbak 2020-03-23 08:16 am (UTC)(link)
This is not as bad (by far!) as at some other places. E.g. I think Ello has a much bigger problem with legit accounts taken over by spammers.
tanya_salpe: (Default)

[personal profile] tanya_salpe 2020-03-17 11:43 pm (UTC)(link)
Thank you so much!
sheliak: Handwoven tapestry of the planet Jupiter. (Default)

[personal profile] sheliak 2020-03-17 11:53 pm (UTC)(link)
Good to know what's going on!
dragoness_e: Living Dead Girl (Living Dead Girl)

[personal profile] dragoness_e 2020-03-18 02:35 am (UTC)(link)
I know for a fact that all my old LJ accounts are compromised, with the e-mail/account name/passwords being in cyber-criminal hands. Methinks the Russian entity that owns Livejournal now isn't too fussy about security, or something.

Fortunately, I didn't use those passwords anywhere else. If anyone here migrated from LJ, as I did, make sure you don't use the same passwords as you did on LJ.

[personal profile] seeitbloom 2020-03-19 02:15 am (UTC)(link)
What about DeadJournal? I did notice some time back that the website started saying it was unsafe every time I went to it and something seemed wrong there as far as security goes, and I got strange pop ups on the site trying to sign in. Yikes.
acciochocolate: (Default)

[personal profile] acciochocolate 2020-03-18 02:40 am (UTC)(link)
Thanks! I'm seeing negative reviews on IMDB from these trolls and not sure how to report it there.
rattfan: (Default)

[personal profile] rattfan 2020-03-18 03:27 am (UTC)(link)
I was subscribed to by a "drunkenkitsune" but noticed it was an RU account, also with no entries, so ignored it. Anything else I need to do?
(reply from suspended user)
penguinmayhem: Pictured: a smug moron. (Default)

[personal profile] penguinmayhem 2020-03-18 08:17 am (UTC)(link)
Thanks for the hard work, guys!
madfilkentist: My cat Florestan (gray shorthair) (Default)

[personal profile] madfilkentist 2020-03-18 10:39 am (UTC)(link)
In the past week I got two suspicious-looking followers. That explains it.

LiveJournal refugees should be especially careful not to reuse their passwords from there. A large number of people I know, including myself, got "Caught you on camera watching porn" spam, giving our old LiveJournal passwords as "evidence." In its earlier days, LJ must have been very sloppy about protecting user passwords.

Page 1 of 2