Security Risk - Change your passwords

  • 🐕 I am attempting to get the site runnning as fast as possible. If you are experiencing slow page load times, please report it.

Null

Ooperator
kiwifarms.net
Joined
Nov 14, 2012
So this afternoon at about 4pm CST the server went down. From what I've been able to see, the permissions of our database users were changed so that none of the applications could connect.

I haven't yet had time to read access logs or figure out what exactly happened, but from this alone I can infer that someone gained privileged access the MySQL server. Someone has claimed responsibility for this, but usually they are technically incompetent and bluff constantly so I take it with a grain of salt. They also sounded really adamant that I make this announcement, probably for publicity.

However, as a precaution:
If you have used your forum password on another website, change it immediately.

I can't verify that this person has anything. They've refused to show any proof that they were responsible for an attack, that they have our password salt, or any passwords at all. However, as a matter of precaution, this is the best and most logical thing to do.

Also, if you used a password here anywhere else, shame on you.

Edit: If you use Steam to sign in, you're fine.
 
Last edited:
I've changed all the passwords for everything, especially the ones I didn't have to do. I wrote all my new passwords in one of those password protected electronic diaries from the 90s, put that in a safe, put the safe in a shed with a padlock, and fed the padlock key to my cat.
I think I'm good.
 
What if I don't have a password? (Steam login.)
Then your password is never stored on our database. You are authenticated by Steam and it sends us a completely anonymous, temporary token that says you validated correctly. You have nothing to worry about.
 
  • Informative
Reactions: Bernard
Heh, I haven't logged out of here since I made my account, and forgot my password. Had it saved in a doc and found out it was something pretty retarded that I've never used anywhere else. Happy day.
 
  • Winner
Reactions: Tycholarfero
I changed my passwords off the ones that I can think off the top of my head. I guess I will change my kiwi password.
 
  • Like
Reactions: Yog-Spergoth
Back