For those who run on Matrix.org and wonder why there is no connection:

Matrix announced an emergency maintenance… on Twitter:

https://twitter.com/matrixdotorg/status/1116304867683905537

Sadly @matrix didn't receive the love it deserves and informs the Fediverse.

Anyway, that's why we have a community. We compensate short coming of each other and together make sure the world becomes a better place!

#Matrix #matrixDown #riot

Matrix on Twitter

“We’ve taken down the servers which host https://t.co/y2YCHNIbgU and https://t.co/5f8JYAG3OA for emergency security maintenance - estimated downtime is several hours. More updates as we have them.”

Twitter

Matrix is coming back up! One of the first things happening was writing a new blog post about the incident which you can find here:

https://matrix.org/blog/2019/04/11/security-incident/

TL;DR: Some outdated software was discovered and cracked by an attack which then had access to various data points.

Important: Change your password ASAP (including NickServ when you used the IRC bridges)

Hint: The homeserver is not back up yet.

#matrix #matrixDown #Riot

Synapse: Deprecating Postgres 9.4 and Python 2.x | Matrix.org

The homeservers are back up 🎉

It seems like they are missing some pictures right now, I guess those will come back later.

Make sure you change your password (and NickServ passwords) and happy chatting!

See you around 👋

#matrix #matrixDown #matrixBackUp #Riot

Too early to be happy, seems like the attacker found their way in and is still around on Matrix's infrastructure.

The attack has proven themselves to have shell access on their synapse instance, which is definitely bad. It means that all user accounts are compromised and have to be reset.

https://twitter.com/matrixdotorg/status/1116593380102852608

There will go a lot of efforts into figuring out the details and fixing the vulnerability.

Meanwhile, send some love to the people behind matrix!

#matrix #matrixDown #riot

Matrix on Twitter

“https://t.co/y2YCHNZM8s down again, we know, we’re on it, more details to follow.”

Twitter

After Matrix has restored its major services, they noticed that the GPG keys used for signing packages where compromised.

The key IDs are:

AD0592FE47F0DF61 (synapse)
E019645248E8F4A1 (Riot/Web)

Please make sure to no longer use those keys.

#matrix #Riot #infosec #security

@sheogorath
How do you get rid of these keys and get the new ones?

@Divert Since I guess you use some Debian base system:

apt-key del AD0592FE47F0DF61

or apt-key del E019645248E8F4A1

@sheogorath
Yes, thanks. that is what I did. I am wondering now how to get the correct ones..

@Divert As far as I know there aren't new ones yet. The keys along with the repositories where removed and will be rebuild during the upcoming week.

https://twitter.com/RiotChat/status/1117110823023984640

Riot.im on Twitter

“After the security incident on the https://t.co/g01j4u6O2e server (https://t.co/xh5uK0cAwy), Riot packages, download links and integrations are currently unavailable. We'll be restoring them asap.”

Twitter