Mumsnet hit by hear...
 

  You don't need to be an 'investor' to invest in Singletrack: 6 days left: 95% of target - Find out more

[Closed] Mumsnet hit by heartbleed hackers

15 Posts
12 Users
0 Reactions
51 Views
Posts: 321
Free Member
Topic starter
 

Better get those passwords changed sharpish. Especially those of you that frequent mumsnet. Just spent nearly an hour doing mine. Never going to remember any of them.

http://www.bbc.co.uk/news/technology-27028101


 
Posted : 14/04/2014 5:06 pm
Posts: 0
Free Member
 

Mumsnet passwords got taken up the Oxo Tower?


 
Posted : 14/04/2014 10:21 pm
Posts: 597
Free Member
 

Couldn't have happened to a better site - qua moaning and panic from mums all over.

Penis beaker is still the best forum discussion ever though!


 
Posted : 14/04/2014 10:32 pm
Posts: 0
Free Member
 

Did the hack involove some kind of back door exploit?


 
Posted : 14/04/2014 10:58 pm
Posts: 17
Free Member
 

are we sure it wasn't hora


 
Posted : 14/04/2014 11:07 pm
Posts: 0
Free Member
 

ChubbyBlokeInLycra - Member
Did the hack involove some kind of back door exploit?

Their security arrangements are going to have to be analysed in depth.


 
Posted : 14/04/2014 11:27 pm
Posts: 77347
Free Member
 

To be fair to Mumsnet,

They're notable not in so far as they're the first UK site to be hacked per sé, but rather that they're the first to know about it. Which is a subtle but important difference. Someone posted a spoofed message, then 'fessed up that they'd compromised the account with a HB exploit.

It's easy to point and laugh, but the fact is that they could easily be the latest one of many and we'd never know. I'll wager that much bigger fish will fry before this all blows over.


 
Posted : 15/04/2014 12:01 am
Posts: 1
Free Member
 

What's the point in changing passwords until they mend the weakness ?

You'll just have to change them all again anyway.

Surely those with different passwords for different sites should be fine too, it's all those who have the same word for everything who really need to worry.


 
Posted : 15/04/2014 3:37 am
 Drac
Posts: 50352
 

What's the point in changing passwords until they mend the weakness ?

They have fixed it.


 
Posted : 15/04/2014 5:01 am
Posts: 0
Free Member
 

coolhandluke - Member

Surely those with different passwords for different sites should be fine too

and only change those that have been confirmed as compromised as and when, right?


 
Posted : 15/04/2014 6:30 am
Posts: 251
Full Member
 

[i]and only change those that have been confirmed as compromised as and when, right?[/i]

no, the problem with heartbleed is that there's no evidence stuff's been taken until it's used.

best bet is to wait until you know the patch is installed and then change the password, not wait to find a problem with your account.


 
Posted : 15/04/2014 7:34 am
Posts: 0
Free Member
 

So in the absence of knowing whether a particular site has been patched, just wait or change them all anyway?


 
Posted : 15/04/2014 8:02 am
Posts: 3327
Free Member
 

http://mashable.com/2014/04/09/heartbleed-bug-websites-affected/

Change them all as a precaution as I bet it's a couple of years (or never) since you last changed them anyway.


 
Posted : 15/04/2014 8:13 am
 Drac
Posts: 50352
 

So in the absence of knowing whether a particular site has been patched, just wait or change them all anyway?

Change any you're concerned about being exposed.


 
Posted : 15/04/2014 8:15 am
Posts: 50252
Free Member
 

Change any you're concerned about being exposed.

We're talking pants here, right?


 
Posted : 15/04/2014 8:17 am
Posts: 0
Free Member
 

Change them all as a precaution as I bet it's a couple of years (or never) since you last changed them anyway.

Too true - you can't be too careful about making sure you're protected against security weaknesses, however remote they might seem and no matter how useless the info seems. After all, as far as these hackers are concerned, any hole's a goal.


 
Posted : 15/04/2014 8:41 am

6 DAYS LEFT
We are currently at 95% of our target!