And that's why you go with Wordpress...
Drupal.org compromised
31–40 of 86 posts
Re: Drupal.org compromised
#32Makes a case for actively destroying accounts on services that you're no longer planning on using.
Re: Drupal.org compromised
#33This is one of those cases where I completely forgot that I had an account, and now it has been compromised. I'm scratching my head wondering what information/password I had associated with it. Makes a case for actively destroying accounts on services that you're no longer planning on using.
Re: Drupal.org compromised
#34This is one of those cases where I completely forgot that I had an account, and now it has been compromised. I'm scratching my head wondering what information/password I had associated with it. Makes a case for actively destroying accounts on services that you're no longer planning on using.
Or not sharing passwords between services.
Re: Drupal.org compromised
#35Drupal.org compromised. If I visit drupal.org, will I experience the compromise firsthand via some zero-day exploit? A situation like this really calls for an independent site to make security-related announcements from where you can reasonably trust the independent site to not have been affected.
Re: Drupal.org compromised
#36And that's why you go with Wordpress...
Re: Drupal.org compromised
#37They don't seem to mention this, but I'd say everyone that uses d.o git repos should definitely verify their set of authorized keys.
Re: Drupal.org compromised
#38Moderately miffed that the email they sent out notifying how THEY allowed my password to be compromised included a lecture telling ME how to construct a strong password. Not the time, or place. Besides, they claim it was salted, so it shouldn't really matter at this point whether my password was "Password123" or "@DJDF*$@!(DGEWGIRGHdfhEWROighMMMM...PIZZA".
Re: Drupal.org compromised
#39This is one of those cases where I completely forgot that I had an account, and now it has been compromised. I'm scratching my head wondering what information/password I had associated with it. Makes a case for actively destroying accounts on services that you're no longer planning on using.
Or not sharing passwords between services.
Re: Drupal.org compromised
#40So...it'd be nice to know the details of what this third party app was and also, some basic details of the configuration of association.drupal.org. Not anything specific, but rather, how is the subdomain stack different than the one used on drupal.org?