Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 17 submissions in the queue.
posted by NCommander on Monday May 18 2015, @10:00AM   Printer-friendly
from the standing-by-our-principles dept.

Normally, when I make a post on SoylentNews, it's to talk about some exciting new feature, our future, or something similar.

Unfortunately though, on rare occasions, I have to make announcements like this one. Sometime between May 12-13th, one of our email accounts was breached. The account ("test1") was left over from go live, over a year and half ago, and had a very weak password protecting it. We believe that an automated password guesser was able to find and access the account. Once breached, the account was used to send a significant amount of spam until we deleted the affected account on the 14th May 2015.

As a result of the compromise, several spam services have blacklisted our mail server; we're currently working to try and get ourselves cleared whenever we become aware of one of these blocks. We do not believe any user information or sensitive data was compromised; the account in question was simply a virtual dovecot account with no corresponding UNIX account attached to it.

mechanicjay was primarily responsible for handling this and cleaning up the mess, and I wish to personally thank him and the rest of the sysops team for their handling of this issue. We are looking at taking steps to prevent a reoccurence such as using fail2ban and the like. Unfortunately, most IDS systems like fail2ban are incompatible with IPv6 which we use extensively internally within our network.

A sysops meeting is being scheduled to discuss this and other changes we're making to the infrastructure.

I will update this article (or post a new one) with additional information should it become available,
NCommander

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by Common Joe on Tuesday May 19 2015, @04:25AM

    by Common Joe (33) <common.joe.0101NO@SPAMgmail.com> on Tuesday May 19 2015, @04:25AM (#184922) Journal

    There's a difference between being an asshole and being sarcastic towards an asshole. Someone else seems to have already given you a point for that. I'm refraining from giving out points to you because I want to see the abuse they are talking about on this sight, and not a flamewar over this topic. (Although I think you deserved the bump up to a 3.) Right now, I'm not seeing many good examples given by the complaining ACs. I'm starting to think most of the ACs are trolling on this topic about trolling.

    TL;DR: Don't beat yourself up over this.

    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2  
  • (Score: 2) by Marand on Tuesday May 19 2015, @05:01AM

    by Marand (1081) on Tuesday May 19 2015, @05:01AM (#184929) Journal

    There's a difference between being an asshole and being sarcastic towards an asshole. Someone else seems to have already given you a point for that.

    Yep, and it can be a fine line, especially if the person you're responding to wasn't being too horrible to begin with. You might think you're just penning a scathing bit of wit about how completely wrong someone is, but to others you might just come across like a jerk instead. I like making jokes, but usually leave off the excess sarcasm because, more often than not, it just interferes with the point I was trying to make. Sometimes, though, I can't resist. I just assume I'll get downmodded or ignored for it, though, and don't worry about it. :)

    Right now, I'm not seeing many good examples given by the complaining ACs. I'm starting to think most of the ACs are trolling on this topic about trolling.

    I've seen this "harmful moderation! omg!" thing floating around for a while, and every time I've checked the examples they've been appropriately modded more often than not, except for technicalities over whether it should be marked "troll" vs "flamebait" vs "overrated". Usually it's a case of someone making a good point but lacing it with insults, or saying something inoffensive but fairly off-topic. It's stuff that can easily be solved with a "don't be a dick" proofreading before pressing submit.

    Now, what we really need to fix is the quality of trolling on this site. The systemd trolling had some clever moments where the author tied the troll in nicely with the topic -- I saw a few even manage to get upmodded instead of marked offtopic -- but overall the troll quality on SN has been pretty damn poor. Too much same-topic spam and offtopic shitposting, not enough clever trolling.