@cmg from 🐦
| Find everything here | https://bio.link/cmg |
| Website | https://chrisgaraffa.com |
| Find everything here | https://bio.link/cmg |
| Website | https://chrisgaraffa.com |
🚨 Kolektiva.social SECURITY ALERT 🚨
This is an alert for Kolektiva.social users. Please read this post in its entirety!
In mid-May 2023, the home of one of Kolektiva.social's admins was raided, and all their electronics were seized by the FBI. The raid was part of an investigation into a local protest. Kolektiva was neither a subject nor target of this investigation. Today, that admin was charged in relation to their alleged participation in this protest.
Unfortunately, at the time of the raid, our admin was troubleshooting an issue and working with a backup copy of the Kolektiva.social database. This backup, dated from the first week of May 2023, was in an *unencrypted* state when the raid occurred and it was seized, along with everything else.
The database is the heart of a Mastodon server. A database copy such as the one seized may include any of the following user data, in this case up to date as of early May 2023:
- User account information like the e-mail address associated with your account, your followers and follows, etc.
- All your posts: public, unlisted, followers-only, *and direct ("DMs")*.
- Possibly IP addresses associated with your account - IP addresses on Kolektiva.social are logged for 3 days and then deleted, so IP addresses from any logins in the 3 days prior to the database backup date would be included.
- A hashed ("encrypted") version of your password.
🚨 👉 As a precaution we highly recommend that all users on Kolektiva.social *change their password immediately* to a new, unique, and strong password.
We sincerely apologize to all our users and regret this breach. In hindsight, it was obviously a mistake to leave a copy of the database in an unencrypted state. Unfortunately, what would otherwise have been a small mistake happened to coincide with a raid, due to bad luck and spectacularly bad timing.
We understand that our users and other people on the Fediverse will have a lot of questions. We will try to answer them as best we can, but please be patient and bear in mind that we may be overwhelmed with messages, and may be delayed in responding or unable to provide answers to certain questions for legal or technical reasons. As a security culture reminder, it can be extremely harmful to the individuals charged and to our community to openly speculate on the Internet about alleged criminal activity or about what law enforcement may be able to do with seized data. Our present awareness is that the seized Kolektiva data is unrelated to the federal investigation and prosecution and we are exploring legal avenues to have the seized data returned and copies destroyed.
Thank you for your understanding and solidarity
👇 Please see our replies to this post for additional information (1/?) 👇
I'm often too hard on myself. The last two years have been miserable & many days I feel like I failed. I question myself to no end, despite knowing I took on an impossible fight.
Other days... I discover my life was an exam question in a Columbia University Business Ethics course & the students had 10 point bulleted list of the many ways Apple should have handled my concerns (but didn't).
I really wish Apple had done the right thing.
This was special. A client’s Drupal site went down for nearly 24 hours Fri-Sat night because their Twitter feed view somehow triggered massive amounts of traffic in & out from Twitter’s API servers.
tcpdump was just streaming constant inbound & outbound traffic from the same /24 belonging to Twitter.
It was a Saturday night so I disabled the widget and will look into it more during the week. I would have imagined they’d have some kind of rate limiting on failure.
My latest for CovertAction: I was able to be in DC last Friday for the Belmarsh Tribunal, demanding Justice for Julian Assange.
Third Belmarsh Tribunal for Julian Assange held at the National Press Club in Washington, D.C. (January 20, 2023) [Source: rumble.com] Nearly 13 years after WikiLeaks founder Julian Assange release…
We have all this advanced technology but still Tinder can’t figure out that it is not 30 miles from New Haven to anywhere on Long Island.
I’ve had some wild multi-state first dates but I’m not getting on the Bridgeport/Port Jefferson ferry for Jessie from Huntington, sorry.
(Sorry Jessie from Huntington, I’m sure you’re a lovely person. It’s not you, it’s geography.)