7 ms·
There seems to be some speculation that this is credit card details being hacked. Firing your _entire_ security team sounds like the sort of action taken if bas
by bArray 4y ago
There seems to be some speculation that this is credit card details being hacked. Firing your _entire_ security team sounds like the sort of action taken if basic security practices are not being done. Until we know more, hold out on hiring these people.
Xe has commented on this and is suggesting to simply enable 2FA to deal with security concerns [1], as apparently a more measured response to security issues at Patreon. This seems to be more self-serving advice rather than good advice [2], the better suggestion would be to simply move to one of the many alternatives.
The assumption is that the login system is somehow insecure, instead of the bank details themselves being stored insecurely. (Hypothetically) If you suffered a large leak of payment details, when payment processing is your _main_ income revenue, and you find out your security team of X people at probably $100k+ a year for N years have done nothing to secure payment details, you too may fire them on the spot.
Until Patreon explain why they fired their _entire_ security team, the best advice is to remove your card details immediately. You can always add it back at a later date, or use an alternative payment processor.
[1] https://xeiaso.net/blog/patreon-happening https://xeiaso.net/blog/patreon-happening
[2] https://www.patreon.com/cadey https://www.patreon.com/cadey
(Edit: As pointed out, Xe didn't mention credit card details.)
- PragmaticPulp 4y ago> Xe has commented on this and is suggesting to simply enable 2FA instead of removing your account details entirely [1], as apparently a more measured response to credit card details being hacked. The Xe link you cited doesn't speculate about credit card details being hacked at all. In fact, the entire gist of the blog is that we shouldn't be speculating about hacks or other theories. The 2FA recommendation isn't a response to a potential hack, it was just general good security advice.
- bArray 4y ago> The Xe link you cited doesn't speculate about credit card details being hacked at all. In fact, the entire gist of the blog is that we shouldn't be speculating about hacks or other theories. True, I accidentally bridged that gap when reading it. I have updated my comment to reflect security more generally. > The 2FA recommendation isn't a response to a potential hack, it was just general good security advice. Given the context in which the article is written (the security team being expelled), this is the way I have interpreted it. It's not a standalone PSA on best security practices. It's written as if enabling 2FA is an alternative to homeless creators.
- xena 4y agoHi, Xe here. The message under `UPDATE(M09 08 2022 20:40)` is intended to be spread to and understood by less technically apt people. I have intentionally focused it on harm reduction, lessening fearmongering and overall calming down the situation so that we can wait for the truth to be revealed. As I mentioned earlier, suggesting people use 2FA is something concrete people can do right now to help secure access to sensitive accounts. I'm worried about the kind of situation that would cause this to happen, but I don't know what is going on so I have to assume that there is active disinformation and interpret things in the best possible faith. The last thing I want to do as a technical communicator is lie to people.
- bArray 4y agoThanks for explaining. It's a difficult one if your supporters are not tech savvy. At the very least I would suggest they keep a close eye on their transactions and be prepared to take action (which is also good bank security practice). I agree there will be misinformation in this scenario, but the facts we do have do not bode well. As far as I know, it is not a good sign to fire your entire security team. There isn't a circumstance I can imagine where this reflects well on Patreon internally.
- xena 4y agoHi, Xe here. I realize that my announcement looks self-serving and at some level it kind of is (support on Patreon is part of how I keep my US account solvent because international wire transfers have yearly limits to their frequency, apparently). However, the facts of the situation are that we do not know what is going on and other creators I know are not in the same kind of financial situation that I am in. At least one of my good friends will probably miss a rent payment if there's a mass dropoff in support (and they just escaped an abusive living situation). My goal is to emphasize a "woah, slow the fuck down and let's wait to see what's going on before making rash decisions" rather than a "oh no my free money fountain is at risk let's stop them from going away". That post exists because I've gotten over 60 inquiries about this today from as many people. I was tired of explaining it over and over so I put it on the blog to avoid constant duplication. Telling people to enable two-factor auth is the moral equivalent of a free space in bingo. It's something people should already be doing and it's good to repeat that message in case people haven't heard it. We don't know what's going on. Until we do, it's best to keep an eye on the situation and be ready to react if needed.
- bArray 4y ago> I realize that my announcement looks self-serving and at some level it kind of is (support on Patreon is part of how I keep my US account solvent because international wire transfers have yearly limits to their frequency, apparently). Are other alternatives not viable? For example SubscribeStar [1]? It's probably better to have multiple sources of income, rather than a single payment processor? > However, the facts of the situation are that we do not know what is going on and other creators I know are not in the same kind of financial situation that I am in. At least one of my good friends will probably miss a rent payment if there's a mass dropoff in support (and they just escaped an abusive living situation). I'm sympathetic to your friend, but I also weigh up the possibility of however many supporters having their credentials exposed. Not for being taken for a few dollars, but potentially having their entire account wiped out. (On a side note I would also suggest that given the incoming economic downturn we are about to experience, this disposable income from strangers may not be reliable in the near future.) > My goal is to emphasize a "woah, slow the fuck down and let's wait to see what's going on before making rash decisions" rather than a "oh no my free money fountain is at risk let's stop them from going away". That post exists because I've gotten over 60 inquiries about this today from as many people. I was tired of explaining it over and over so I put it on the blog to avoid constant duplication. I still think the best action for your supporters would be to temporarily remove their card details until Patreon explain themselves. These can be added back in a few days once Patreon come up with some PR. In the meantime, I would definitely suggest to look for alternative platforms. Firing your entire security team without warning is not standard practice, it really does indicate something bad. If the security team were caught be surprise, it means there has been no hand-over process, meaning that potentially Patreon currently has no way to handle or detect new security issues. Clearly Patreon themselves were taken off-guard by this, hence the radio silence amid growing speculation. > Telling people to enable two-factor auth is the moral equivalent of a free space in bingo. It's something people should already be doing and it's good to repeat that message in case people haven't heard it. As I wrote in another child comment, it somewhat sounds like enabling 2FA is an alternative to starving creators. If there was a breach in the system itself behind the login system, 2FA won't make an ounce of difference. Anyway, fingers crossed this is all blown out of proportion. My gut is still telling me there is something amiss here though. [1] https://www.subscribestar.com/ https://www.subscribestar.com/