March 2025 Data Breach

I’m trying to figure out if it’s maybe only a partial breach because nothing I know of says my password is breached.

2 Likes

They’ll have their own crawlers that pull data from breaches all over the internet.

2 Likes

that’s what we’re working on

2 Likes

It should just be partial since most people seem unaffected

in other news i finally got aegis 2fa to work so :heart_eyes:

4 Likes

BitWarden, dehashed & haveIbeenpwned have found nothing on any of my accounts so
Shrug

4 Likes

same here but I’m not afraid to have acted overly zealously just in case

will be REALLY funny if Ash just got phished tho

6 Likes

like I would much rather false alarm and get people to use better passwords than think a real alarm is false and have somebody’s life adversely affected for it

7 Likes

Or Ash has installed a shady browser extension or some sort of keylogger

5 Likes

Me, knowing full well it’s my orangeandblack5 blocker script I posted in Drama Mill Thread:

legally it’s not but it’d be funny if it was

4 Likes

Also curious to know how the security breach happened.

Every site should at the very least store hashed passwords. Salted hashes are much better but just hashed is maybe borderline acceptable.

If they’re plaintext or encoded it would be severe malpractice IMO.

5 Likes

The MU data breach did!! It’s just they hashed them in unsalted md5.

6 Likes

discourse uses one-way-encrypted passwords that are considered impossible to decrypt, so the odds that someone a) got to the database and b) was able to decrypt the passwords would be very small

but we decided it was better to assume either that happened or somebody found some other vulnerability with our discourse version and later be proven wrong than to not act and have it turn out somebody did do one of those things

4 Likes

maybe this is all part of orange’s big plan to make everybody use better passwords (for evil reasons)

10 Likes

bro i am so chill with that possibility

5 Likes

i have a unique fol password that still isn’t listed as breached, and another non-unique that could feasibly have been breached outside of fol but woulda had to been relatively recently (past month or so)

3 Likes

yeah

im starting to come around to the idea that ash just had somebody else use his password on some other website, and that rando and you both got breached elsewhere

but we’re still looking into things

2 Likes

These days, using the same password on multiple accounts is asking for trouble.

4 Likes

Amogus

2 Likes

If theres any update, please update the announcement in the discord too. Cause like I check that way more ty for informing us though. TBH don’t even remember which password this one is

6 Likes

yeah once we have everything sorted we’ll re-ping and also prolly send out an e-mail if that seems helpful

4 Likes