4 ms·
The warnings might have been triggered in error, but the evidence is certainly there for masters to have been compromised. Until recently their publicly availab
by computershit 5y ago
The warnings might have been triggered in error, but the evidence is certainly there for masters to have been compromised. Until recently their publicly available support forum running phpBB was using the master password for customer logins.[1]
[1] https://news.ycombinator.com/item?id=29706579 https://news.ycombinator.com/item?id=29706579
- basseq 5y agoI'm trying to differentiate between "there has been evidence of a breach" and "there are less-desirable security practices". As I understand it, the phpBB / master password practices—which are indeed, not good, but also not fully understood exactly how they did it—are also not evidence that the masters have been compromised. Again, that it could be an attack vector is interesting and relevant, but different from "has been breached" per OP.