2023 Security Check-up Reminder

  • 🐕 I am attempting to get the site runnning as fast as possible. If you are experiencing slow page load times, please report it.

Null

Ooperator
kiwifarms.net
Joined
Nov 14, 2012
Hello again friends. It's me again here to remind you to not be retarded.

An e-drama adjacent website, chudbuds.lol, was recently hacked. The operator ran a Minecraft server and she installed a mod from Mediafire that a bad actor had given her. The mod's malware payload appears to have downloaded all browser information (such as stored passwords) which resulted in not only chudbuds.lol being hacked, but the owner's personal emails and much of her personal information (including nudes, tax returns, and more).

The users of the site had their email addresses and private messages leaked. Many of their users did not practice good digital hygiene, including some users who have used work and educational emails. Now is a good time to review your privacy.

Both of these sites are good resources. There is a heated dispute between the two operators, but both provide good information.



The most important thing is your behavior. Do not be a retard. This user offered to host a Kiwi Farms minecraft server almost immediately after the chudbuds hack. Byuu decided it'd be funny to give him the malware mod. The user downloaded it off mediafire and ran it, which means the hacker probably has access to his shit too.

Do not run any software coming from a source you do not trust. Mediafire is not a trustworthy source. No random user of this website is either.


Use a password manager. You want a good one, which is open source. BitWarden is considered the best. If you use LastPass, you should migrate to another.


Your main password should be something very long. Use a passphrase, not a password.

passwords_blog_protonmail.jpg

You should also be using 2fa everywhere you can. It's annoying, but the information that was not hacked from Clairebere was protected by 2fa. BitWarden has TOTP, but only if you have a premium subscription.

https://www.privacytools.io/secure-password-manager (scroll down)


You should compartmentalize your identities so that if your main email is leaked, you are not super-doxxed. There is a new kind of technology called email forwarding which simplifies this a lot. Protonmail provides access to SimpleLogin. There is also AnonAddy, and FireFox relay.



Email is inherently insecure. It is almost never encrypted, and what is encrypted is only the body and attachments of the mail, not any meta data. However, many services provide encryption for email stored on their servers, which provides a layer of security against hacks and law enforcement intrusions that mainstream services like Gmail / Hotmail / Yahoo / GMX do not provide.



Finally, IPs are the least important part of a dox. They can rarely be used against you. A VPN is nice to have, but it is not the end-all, be-all of security that many people think it is. You should learn what a VPN can and cannot do before thinking having one will protect you.



Here is more information on Tor, which does help more, and which we provide a hidden service before. Tor is not always allowed on all networks, so VPNs still help.




F.A.Q. from retards arguing in this thread

1. How are password managers safer than a pen and paper?
Good password managers are open source and audited (i.e. not LastPass). Encrypted vault content will take longer to decrypt than you will be alive to deal with the fallout. They can generate the most secure passwords possible, keep track of all of them, and run no risk of being destroyed physically. Their ease of use encourages using truly unique and secure passwords more often.

2. Isn't storing these online dangerous?
No, not really. The end-to-end encryption prevents anyone who intercepts the password vault from being able to read its contents.

Not all password managers use online vaults. BitWarden lets you set up your own server to store there, instead of on theirs. However, remote password vaults provides one benefit over local: 2fa. With 2fa, having the master password alone does not decrypt the vault.

3. ProtonMail is COMPROMISED!!!
Proton AG in Switzerland responds to Swiss court orders and releases such compliance in their transparency reports. Their policy of transparency has caused a meltdown, claiming they are compromised and work directly with 'the feds' (implying US federal government or 5 Eyes). They turned over an IP address after receiving a Swiss court order. All services do this.

Google receives hundreds of thousands a year and does not encrypt any user data.
 
Last edited:
How could you be so retarded downloading random mods from the Internet? I mean, I seen people accidentally pressing phishing links, and I can see how people fall for it, but I assume adults are smart enough to not download random stuff from the Internet.

I trust humanity too much.

P.S. always separate your work from your personal computer!!!
 
The operator ran a Minecraft server and she installed a mod from Mediafire that a bad actor had given her. The mod's malware payload appears to have downloaded all browser information (such as stored passwords) which resulted in not only chudbuds.lol being hacked, but the owner's personal emails and much of her personal information (including nudes, tax returns, and more).
The operator ran a Minecraft server
I’m sure there’s multiple jokes to be made about this, but Notch will be somewhere in the world laughing about something like this happening now that he’s no longer involved with it.
 
Remember Frens, you should have 3 digital identies. Each identity should have its own unique email and passwords!

You have your Financial Identity for Banks, your Utility Bills, buying shit online and so on
You have your Professional Identity for Work and Social circles
You have your Shit Lord identity for Kiwifarms, and shitposting on Twitter, facebook, etc.

Most important of all, DO NOT CROSS THE STREAMS!
 
I don't get why compartmentalization isn't more popular. A hundred dollar tablet can store all your banking and purchasing information while your main device can be used for your day to day.

Only bleed over you have with that is the password for services like steam. Everything else is nicely separated.
 
I use a unique password for/to every login(nothing shares as pw) i have that is the maximum characters the system/site allows that is randomized upper case characters, lower case characters, numbers, allowed symbols for the system/site, and unicode ascii if possible.

Am I doing it correctly?
 
Back