March 2025 Data Breach

Also curious to know how the security breach happened.

Every site should at the very least store hashed passwords. Salted hashes are much better but just hashed is maybe borderline acceptable.

If they’re plaintext or encoded it would be severe malpractice IMO.

5 Likes

The MU data breach did!! It’s just they hashed them in unsalted md5.

6 Likes

discourse uses one-way-encrypted passwords that are considered impossible to decrypt, so the odds that someone a) got to the database and b) was able to decrypt the passwords would be very small

but we decided it was better to assume either that happened or somebody found some other vulnerability with our discourse version and later be proven wrong than to not act and have it turn out somebody did do one of those things

4 Likes

maybe this is all part of orange’s big plan to make everybody use better passwords (for evil reasons)

10 Likes

bro i am so chill with that possibility

5 Likes

i have a unique fol password that still isn’t listed as breached, and another non-unique that could feasibly have been breached outside of fol but woulda had to been relatively recently (past month or so)

3 Likes

yeah

im starting to come around to the idea that ash just had somebody else use his password on some other website, and that rando and you both got breached elsewhere

but we’re still looking into things

2 Likes

These days, using the same password on multiple accounts is asking for trouble.

4 Likes

Amogus

2 Likes

If theres any update, please update the announcement in the discord too. Cause like I check that way more ty for informing us though. TBH don’t even remember which password this one is

6 Likes

yeah once we have everything sorted we’ll re-ping and also prolly send out an e-mail if that seems helpful

4 Likes

as of right now our hosting provider is pretty sure that we just got hit by a funny coincidence

7 Likes

but I’m going to give it the weekend to see if anybody else starts getting “password compromised” notifications before officially announcing it as a false alarm

6 Likes

can we have a new one for april :pleading_face:

11 Likes

Social Security # leak next!!!

9 Likes

please do not put your SSN anywhere near our site

we don’t want it

11 Likes

Rip whoever has been keeping notes by dming themselves (definitely not me)

10 Likes

Am I allowed to put your SSN near this site?

6 Likes

Update

3 Likes

I’m a bit late, but the link is using the fortressoftruth.net domain, which doesn’t load for me (and might not for others)

You can also click the original link and manually change it to fortressoflies.com

3 Likes