starlady: a barcode with my DW username & user ID (barcode)
Electra ([personal profile] starlady) wrote2020-05-26 11:47 am
Entry tags:

So about those zombie spam DW accounts…

The site that was hacked in 2014 which has provided spammers the passwords for defunct DW journals was LiveJournal. The hackers obtained not only passwords but also email addresses; if you reused the same password for your DW when you created it from LJ, or if you had multiple LJs linked to the same email address, that information has been circulating and is now freely available. 

Full details at this link. If you can't remember the last time you changed your password, or whether your password is unique, you should change it now. I would also recommend using a password manager to avoid having to remember your passwords and to create more secure ones. I use LastPass because of inertia, though my understanding is that 1Password is slightly better. The UX on the functions is occasionally annoying, but it's well worth sporadic upfront hassle in my experience. In either case, one of the best things you can do for security is to get one and to use it consistently.

ETA: official Dreamwidth post on the breach from [staff profile] denise, with a good comment about password managers attached.
sovay: (Rotwang)

[personal profile] sovay 2020-05-26 08:19 pm (UTC)(link)
If you can't remember the last time you changed your password, or whether your password is unique, you should change it now.

I changed my LJ password for reasons about two weeks ago (I do not use the account anymore except to comment on one friend's journal) and DW always had its own password, but I am glad, argh, to have this information.

[edit] Also my 2014 LJ e-mail has since been nuked. That was luck rather than foresight.
Edited 2020-05-26 20:23 (UTC)
inkstone: small blue flowers resting on a wooden board (Default)

[personal profile] inkstone 2020-05-26 08:40 pm (UTC)(link)
I had a feeling the site in question was LJ. Denise uses certain phrasing when LJ is involved and I recognized it when she first posted about this.
snickfic: Buffy looking over her shoulder (Default)

[personal profile] snickfic 2020-05-27 01:46 am (UTC)(link)
Should I also be worried about them having my email address, do you think? I obviously can't change that as easily as I can change my password.
threeringedmoon: (Default)

[personal profile] threeringedmoon 2020-05-27 10:42 am (UTC)(link)
I've been using Lastpass for years, so I am used to its quirks. I was very happy when my partner gave up his own idiosyncratic system and started using it as well.
snickfic: Buffy looking over her shoulder (Default)

[personal profile] snickfic 2020-05-28 07:16 pm (UTC)(link)
Good to know, thank you! I switched to a password manager a while back, so my passwords should be safe now.