Ethereum

Security alert [12/19/2016]: Ethereum.org Forums Database Compromised

On December 16, we have been made conscious that somebody had not too long ago gained unauthorized entry to a database from forum.ethereum.org. We instantly launched an intensive investigation to find out the origin, nature, and scope of this incident. Here’s what we all know:

  • The knowledge that was not too long ago accessed is a database backup from April 2016 and contained details about 16.5k discussion board customers.
  • The leaked data consists of

    • Messages, each private and non-private
    • IP-addresses
    • Username and e mail addresses
    • Profile data
    • Hashed passwords

      • ~13k bcrypt hashes (salted)
      • ~1.5k Wordpress-hashes (salted)
      • ~2k accounts with out passwords (used federated login)

  • The attacker self-disclosed that they’re the identical particular person/individuals who recently hacked Bo Shen.
  • The attacker used social engineering to realize entry to a cell phone quantity that allowed them to realize entry to different accounts, one among which had entry to an outdated database backup from the discussion board.

We’re taking the next steps:

  • Discussion board customers whose data could have been compromised by the leak might be receiving an e mail with further data.
  • We now have closed the unauthorized entry factors concerned within the leak.
  • We’re imposing stricter safety pointers internally resembling eradicating the restoration cellphone numbers from accounts and utilizing encryption for delicate information.
  • We’re offering the e-mail addresses that we consider have been leaked to https://haveibeenpwned.com, a service that helps talk with affected customers.
  • We’re resetting all discussion board passwords, efficient instantly.

When you have been affected by the assault we suggest you do the next:

  • Be certain that your passwords aren’t reused between providers. When you’ve got reused your discussion board.ethereum.org password elsewhere, change it in these locations.

Moreover, we suggest this excellent blog post by Kraken that gives helpful details about the way to defend towards a majority of these assaults.

We deeply remorse that this incident occurred and are working diligently internally, in addition to with exterior companions to handle the incident.

Questions could be directed to safety@ethereum.org.

DailyBlockchain.News Admin

Our Mission is to bridge the knowledge gap and foster an informed blockchain community by presenting clear, concise, and reliable information every single day. Join us on this exciting journey into the future of finance, technology, and beyond. Whether you’re a blockchain novice or an enthusiast, DailyBlockchain.news is here for you.
Check Also
Close
Back to top button