denise: Image: Me, facing away from camera, on top of the Castel Sant'Angelo in Rome (Default)
Denise ([staff profile] denise) wrote in [site community profile] dw_maintenance2020-03-17 04:31 pm

(no subject)

Some of you have noticed an uptick in spam accounts following you this week -- it was because a group of spammers were able to take over some legit accounts and use them for spam. (Our usual antispam efforts have worked pretty well to take care of newly created spam accounts, so spammers are going for the old ones instead.) It does appear that the accounts that were hijacked had used the same password they used on Dreamwidth for other sites, and the spammers found that username/password combination in one of the many black market venues for password resale.

We think we've managed to catch and suspend all the accounts that were being used for spamming -- if yours was one of them, open a support request in the Terms of Service category and we'll help you resecure your account so we can unsuspend it. If you spot one that our automated scan missed, open a support request in Anti-Spam and we'll take a look as soon as we get through the backlog of the already-reported ones. If you spot one and it's already been suspended, you don't have to report it.

This is a great time to remind everyone: please don't reuse passwords for multiple sites! The best and most secure way of handling passwords is to download a password manager, like Dashlane, 1Password, Keeper, LastPass, or Zoho. (Everyone has their own favorite, but those are all reputable and secure.) Let the password manager generate and remember passwords for you. This improves security for everyone!

(Edit:) I also forgot to remind people: you can check to see if your information has appeared in a data breach at Have I Been Pwned? It's a legitimate security research site that keeps a database of which account information is for sale on the black market. They don't tell you which passwords were compromised, just whether your email address appears in a collection of passwords, and they don't have every dataset that's circulating on the black market, but if your email address gets a result there, you should change your password on that site immediately, change the password on any site that you used the same password for (and make it a unique password!), and never use that password again. People who have the black market file try those username/password combinations on every site they can find to see how many accounts they can get into.
shapinglight: (Default)

[personal profile] shapinglight 2020-03-18 12:34 pm (UTC)(link)
Thanks for the update.
susanreads: my avatar, a white woman with brown hair and glasses (Default)

[personal profile] susanreads 2020-03-18 03:11 pm (UTC)(link)
Oh, that's what that was! I was subscribed to by an empty account, which has been suspended. It was a new account though.
fred_mouse: line drawing of sheep coloured in queer flag colours with dream bubble reading 'dreamwidth' (Default)

[personal profile] fred_mouse 2020-03-18 11:35 pm (UTC)(link)
Useful update. I've checked the two surprising follows from the last week, and both have been suspended, so it is nice to know what was going on there! I contemplated reporting the first, because it had no posts, but the account was ten years old - I figured I was being overly paranoid. The other one I just shrugged at, because it did have posts, just nothing recent.
musyc: Silver flute resting diagonally across sheet music (Default)

[personal profile] musyc 2020-03-19 12:17 am (UTC)(link)
Had three, already been whacked. Thanks for the update!
tellshannon815: (archie hopper)

[personal profile] tellshannon815 2020-03-19 12:18 am (UTC)(link)
That explains the random account that started following me yesterday!
random_nexus: (OMG ONOZ)

[personal profile] random_nexus 2020-03-19 12:25 am (UTC)(link)
EGAD! Thanks for giving us the heads-up on this! Also, thanks for all the awesome you're doing here. :)
foxmonkey02: (Default)

[personal profile] foxmonkey02 2020-03-19 01:46 am (UTC)(link)
I had a notification for one new follow, and couldn't figure out why someone would follow a journal set completely to private with only three (OLD AS HELL) public posts. Unfortunately, now we know. Good Lord.
kama_blackbird: (Et Cetera: Mingchao)

[personal profile] kama_blackbird 2020-03-19 02:01 am (UTC)(link)
None of my accounts had their address changed and I switched them all to strong, unique passwords less than a year ago. Does it mean I'm in the clear?
wyld_dandelyon: (Default)

[personal profile] wyld_dandelyon 2020-03-19 02:47 am (UTC)(link)
"if your email address gets a result there, you should change your password on that site immediately" On which site? You mean the e-mail address? Or any and all sites you have used that e-mail address on?

(no subject)

[personal profile] wyld_dandelyon - 2020-03-19 07:02 (UTC) - Expand
allanh: (Default)

[personal profile] allanh 2020-03-19 03:24 am (UTC)(link)
ZOMG thank you SO MUCH for the heads-up! I've just finished changing the passwords for all three of my DW accounts (unique password for each account, of course), and will do the same for my prior social media accounts next.

[personal profile] shadowfoto 2020-03-19 04:51 am (UTC)(link)
thanks for heads up, but FOUR (so far) notifications in my mailbox sounds like we've got a bit more issues than the identity theft alone... :)
mekare: Phryne Fisher toasting with champagne, text: Go you! (Miss Fisher Go You)

[personal profile] mekare 2020-03-19 06:09 am (UTC)(link)
Thank you so much! I was about to report the three suspicious empty accounts that followed me this week but you already got them all.
dreizler: (Default)

[personal profile] dreizler 2020-03-19 06:32 am (UTC)(link)
thank you!

[personal profile] ara_kiss 2020-03-19 11:30 am (UTC)(link)
It says I'm fine, no breached accounts.

Thank you!
infiniteviking: A noncommital bluejay on a perch. (4)

[personal profile] infiniteviking 2020-03-19 04:52 pm (UTC)(link)
No suspicious accounts have followed me. Win? :'D

If an email is still accessible, does that mean the DW accounts that use it aren't compromised (though it's still wise to use password managers and change passwords)? Or would we have to log in to each account to confirm it's not suspended?

Thanks for being on top of this!
delight: (Default)

[personal profile] delight 2020-03-19 05:52 pm (UTC)(link)
My DW password is my LJ password from prior to 2014; I had changed my password on LJ to something else back in 2009 because i wanted it to be my DW password instead. Should I be okay or change just in case?

(That password was only used on LJ, and is now only used on DW; it has been only used on DW since '09.)
al_zorra: (Default)

[personal profile] al_zorra 2020-03-19 09:41 pm (UTC)(link)
I x-post from DW to another place, but the passwords are different, and so are the handles, and titles.
ai: a side profile of eirika (π–—π–Šπ–ˆπ–‘π–†π–Žπ–’ π–žπ–”π–šπ–— π–ˆπ–—π–”π–œπ–“)

[personal profile] ai 2020-03-20 05:49 am (UTC)(link)
Thank you for all that you do. Scamming and spamming are both going to be on the rise during this time so it's great to see some initiative taken in discussing ways to better protect ourselves. I've been bad about using the same passwords on some accounts here (roleplay accounts so no real loss if they are snatched), but I should form a better habit all the same.

I don't think any of my accounts were affected, but I trust if they were that your support team would assist. Cheers, and good luck with sorting through this.
arethinn: glowing green spiral (Default)

[personal profile] arethinn 2020-03-20 08:04 am (UTC)(link)
Mine were all already thwacked by the time I clicked to see who the heck had followed me.

By "Keeper" did you mean KeePass, or something else?
hooloovoo_42: (Default)

[personal profile] hooloovoo_42 2020-03-20 10:11 pm (UTC)(link)
Thanks for removing my mystery subscriber so quickly.
muffyjo: ! (!)

[personal profile] muffyjo 2020-03-22 11:24 pm (UTC)(link)
Your diligence is very much appreciated! Thank you for all you do.
abstract: (Default)

[personal profile] abstract 2020-03-25 09:52 am (UTC)(link)
Hello. Just adding in my voice that I appreciate your transparency and quickly resolving the issue. It's honestly a breath of fresh air to see this type of response these days.
(reply from suspended user)
(reply from suspended user)
(reply from suspended user)
elizabeth_rice: Snoopy typing on his typewriter (Default)

[personal profile] elizabeth_rice 2020-05-26 10:22 am (UTC)(link)
I don’t know how I missed this announcement, but somehow I did, and it happened in March so how do I know if this happened to me or not? Maybe it’s a dumb question, but I, honest to God, am reading these announcements for the first time. I had absolutely no clue that this was happening, sorry about that.

(no subject)

[personal profile] elizabeth_rice - 2020-06-13 11:44 (UTC) - Expand
elizabeth_rice: Snoopy typing on his typewriter (Default)

[personal profile] elizabeth_rice 2020-05-26 11:36 am (UTC)(link)
Ok, so I went to the β€œhave I been pwned” site and I got 1 hit for email address. However! It is at a site where I don’t and have never opened an account. Which, I don’t know how that is possible?? Do I still need to change my passwords??

(no subject)

[personal profile] elizabeth_rice - 2020-06-13 11:45 (UTC) - Expand

Page 2 of 2