telophase: (Default)
telophase ([personal profile] telophase) wrote2020-05-26 05:40 pm

Yup.

I'm signed up with haveIbeenpwned.com to receive notifications of data breaches, and have received official notification that my account was included in the Livejurnal breach from 2017. I'm not taking any action right now because when the rumors started swirling about there being one a few weeks ago, I logged in and changed my passwords then. (And by 2017 I'd switched to randomly-generated passwords of 15+ characters and keeping them in 1password so I never have to actually remember them, so nothing else of mine was compromised.)

Still, if you haven't changed your LJ password since then, you need to. Especially if you reuse passwords.
kore: (Default)

[personal profile] kore 2020-05-26 11:53 pm (UTC)(link)
Wow, that sucks. I don't even remember if I still had my main LJ account by 2017....I don't think so. I had OpenID for a while and a couple of commenting accounts after that, though, I wonder if they were part of it....

I just checked. Crap.

LiveJournal: In mid-2019, news broke of an alleged LiveJournal data breach. This followed multiple reports of credential abuse against Dreamwidth beginning in 2018, a fork of LiveJournal with a significant crossover in user base. The breach allegedly dates back to 2017 and contains 26M unique usernames and email addresses (both of which have been confirmed to exist on LiveJournal) alongside plain text passwords. An archive of the data was subsequently shared on a popular hacking forum in May 2020 and redistributed broadly. The data was provided to HIBP by a source who requested it be attributed to "nano@databases.pw".
Edited 2020-05-26 23:55 (UTC)

[personal profile] thomasyan 2020-05-27 02:36 am (UTC)(link)
Gah. I don't remember if I changed my LiveJournal password back then. Just changed it now. And fed a bunch of my email addresses to HIBN. Bleah. Not pretty.