Hi Beeple!
Here’s a vague version of events :
-
11PM EST: Lemmy.world got hacked
-
12:20AM EST: Blahaj.zone got hacked
-
12:25AM EST: I shut down the server
-
12:30AM EST: I make announcements to tell people about this
-
12:45AM EST: I have an idea of what the problem is but there is no fix
-
2:20AM EST: I go to sleep
-
8:50AM EST: The server is booted back up, steps are applied to mitigate issues (Rotating JWTs, Clearing DB of the source of vulnerability, deleting custom emoji), UI is updated with the fix, CSP and other security options are applied
-
11:40AM EST: We start testing things to make sure are working And well, now here we are.
If you have issues logging in or using an app:
-
Log out if you somehow are still logged in
-
Clear all cache, site data, etc.
-
Hard refresh Beehaw using CTRL+F5
-
Log back in.
If you still have issues, write to us at [email protected]
To be clear : We have not been hacked as far as we know, we were completely unaffected. This was done preemptively.
Oh yeah, in case, you haven’t, this is a good opportunity and reminder to follow us on Mastodon as the communication line was still up despite Beehaw being down : https://hachyderm.io/@beehaw
I think it’d be beneficial to have more backup lines of communication for announcements than just Mastodon.
We have Discord and Matrix channels as well. Do you have anything to suggest?
Something like status-page is always nice. I haven’t used it but it looks like https://cachethq.io/ could be a decent fit as well.
There you go, courtesy of @[email protected]
Heck yeah! Thanks for getting this up
Just something Google-friendly.
Can you be more precise? What exactly do you recommend? I don’t know what would be more “Google-friendly”
Maybe the front page of the domain could be news and info with the actual forums down a level? Not sure if that works with the software.
That’s not supported by Lemmy unfortunately… Most we could have is a status.beehaw.org, really.
A status website would honestly be excellent.
There you go, courtesy of @[email protected]
Thank you both.
Nah.
I’ll be blunt and say that unless you were already in-the-know, Beehaw pretty much ceased to exist when the server was shut down. Not the best result amidst a hacking scare.
Much preferable to the announcement of Beehaw was hacked and lost your user credentials <or more>. Security trumps convenience.
Having an entirely separate website, blog, or social media account for announcements that’s accessible via a Google search wouldn’t factor into how secure Beehaw is.
Right in the sidebar.
And how were users supposed to be able to see the sidebar while the server was offline?