huh $2a$ is.. blowfish? is that without salt. what is 12. the salt??

don't mind me i just realized bcrypt was named after fucking blowfish

the attacker is opening github issues 😂

> I noticed in your blog post that you were talking about doing a postmortem and steps you need to take. As someone who is intimately familiar with your entire infrastructure, I thought I could help you out.
[then about ssh agent forwarding, and principle of least privilege]

matrix thing 

matrix thing, signing keys in prod 

matrix thing, lmao 

@CobaltVelvet where can a n00b like me find some explanation of what this means?

Thanks! :)

@Antanicus uhh it's a screenshot of matrix.org at the time, with the shell of someone gaining access to matrix.org servers, showing access to a 7TB data storage, a (i guess admin) account with its hashed password, and that they have 5.5M of those.

a huge data breach, possibly worse

@CobaltVelvet I don't know, I hope they warned them before and they choose to ignore the problem. If it isn't the case, that's a kinda shitty thing to do.

@CobaltVelvet Sorry, I misread the situation at first. I though they disclosed actual harmful content for the end users.
It's actually super funny ^^.

@Sylvhem well they still can. these situations are hard to judge and can go from "absolute asshole" to "white hat" and back again in matter of minutes :p

@CobaltVelvet Yeah, but for now they did nothing.
I won't find that funny if they are actually hurting the people who used the service.

matrix thing, signing keys in prod 

matrix thing, re: lmao 

re: matrix thing, signing keys in prod 

re: matrix thing, signing keys in prod 

matrix thing 

lolhats 

lolhats 

lolhats 

@CobaltVelvet
THe com makes me think "What, people not well documented and not reading securiy warning? I'm choked (not)"

@CobaltVelvet
What's Flywheel in this context? All I can find is a taxi app and a building management app. :blobconfused:

@Jo @hirnbrot "Agent flywheel (OS X Build Slave)" from their (now down) wiki

@CobaltVelvet @er1n honestly too bad that it‘s a known issue because I am absolutely always here for burning 0days just to make a point

@CobaltVelvet
What the hell is happening? Trying to wrap my head around that

@CobaltVelvet @l4p1n
kind of a fustercluck over there at matrix.org. shit posters, then post removals then screenshots added back in. most threads are locked to comments.

maybe our white hat bandit works for google?
"2FA is often touted as one of the best steps you can take for securing your servers, and for good reason! If you'd deployed google's free authenticator module (sudo apt install libpam-google-authenticator), I would have never been able to ssh into any of those servers."

i would think that there are other ways for 2FA than just google.

matrix.org/blog/2019/04/11/sec

github.com/matrix-org/matrix.o
(attacker's account revoked):
github.com/matrix-org/matrix.o

@VeintePesos @CobaltVelvet I saw that ^^

Been catching on what has been happening recently

Sign in to participate in the conversation
Octodon

Octodon is a nice general purpose instance. more