Live data from Hacker News

4chan Intrusion Postmorterm

blog.4chan.org

1–10 of 45 posts

Re: 4chan Intrusion Postmorterm

#3

Can't read it here, could someone post the text?

Concerning a recent intrusion

Last week we were made aware of a software vulnerability that allowed an intruder access to administrative functions and information from one of our databases. The intruder later stated their motive was to expose the posting habits of a specific user they disliked.

After careful review, we believe the intrusion was limited to imageboard moderation panels, our reports queue, and some tables in our backend database. Due to the way the intruder extracted information from the database, we have detailed logs of what was accessed. The logs indicate that primarily moderator account names and credentials were targeted.

Three 4chan Pass users had their Pass credentials accessed, and were notified and offered refunds and lifetime Passes shortly after the discovery. As a reminder, all payment information is processed securely by Stripe—we never see nor store any of it, and thus no payment information was compromised.

We patched the vulnerability quickly after it came to our attention, and have spent—and will continue to spend—dozens of hours poring over our software and systems to help mitigate and prevent future intrusions.

We’re sorry it happened, and will do our best to ensure it doesn’t happen again.

—moot

Re: 4chan Intrusion Postmorterm

#7

Can't read it here, could someone post the text?

I suspect a lot of people will be unable to read it if they use HTTPS everywhere: the 4chan blog does not support https and the EFF is currently in a ruleset freeze so they cannot reflect that until the next stable version is out.

Re: 4chan Intrusion Postmorterm

#8
post #7

Can't read it here, could someone post the text?

I suspect a lot of people will be unable to read it if they use HTTPS everywhere: the 4chan blog does not support https and the EFF is currently in a ruleset freeze so they cannot reflect that until the next stable version is out.

Tumblr only recently added SSL support, which is likely the reason Moot hasn't implemented it yet.

That said, I(unfortunately) doubt that HTTPS-everywhere is being utilized by that many people.

Post reply on HN