devkitPro forum breach
Posted: Fri Feb 08, 2019 2:46 am
As you may be aware, the devkitPro forums were breached on Sunday 3rd February and unfortunately the attacker stole the forum database and deleted the data from the server. The database contained user emails, all the forum posts, including private messages, profile information which may include user websites and social media accounts. The passwords in the database are hashed and salted but may still be vulnerable to dictionary attacks. No other data on the server was accessed and the pacman packages remain safe - the signing keys for those are only kept on developer's personal machines.
Unfortunately I used a weak password on my forum account which was shared with my reddit and gitlab accounts, both of which were accessed and deleted.
We have now restored the database, upgraded phpbb to the latest 3.2.5 and reset all user passwords. You'll need to use the forgotten password link to regain access to your account. We recommend resetting passwords on other accounts you may have and, if possible, enabling 2FA where you can.
If you have trouble getting your password reset please feel free to contact us by any of the methods found at wiki/Community_Portal or indeed by emailing me on [email protected].
We apologise for the inconvenience caused and sincerely hope that any damage was limited to the devkitpro forums and my own accounts.
Dave "Wintermute" Murphy.
Unfortunately I used a weak password on my forum account which was shared with my reddit and gitlab accounts, both of which were accessed and deleted.
We have now restored the database, upgraded phpbb to the latest 3.2.5 and reset all user passwords. You'll need to use the forgotten password link to regain access to your account. We recommend resetting passwords on other accounts you may have and, if possible, enabling 2FA where you can.
If you have trouble getting your password reset please feel free to contact us by any of the methods found at wiki/Community_Portal or indeed by emailing me on [email protected].
We apologise for the inconvenience caused and sincerely hope that any damage was limited to the devkitpro forums and my own accounts.
Dave "Wintermute" Murphy.