!! REMINDER !!
Official communication will be done over the forum - not in game. Check your Private Messages.

Important: CloudFlare Security Issue !! PLEASE READ !!

Post Reply
User avatar
Wakamaru
Administrator
Administrator
Posts: 3153
Joined: April 6th, 2015, 6:20 am
United States of America

Important: CloudFlare Security Issue !! PLEASE READ !!

Post by Wakamaru » February 24th, 2017, 11:28 pm

Hello A3ers!

Recently the service known as CloudFlare was compromised and along with it - many passwords. Please read the following information so that you are aware of what has happened and what you should do as a result of it.
There has been a major security flaw within Cloudflare and thus meaning within Discord. It's highly suggested that you cycle your passwords everywhere.

Impact
Between 09/22/2016 and 02/18/2017 passwords, private messages, API keys, and other sensitive data were leaked by Cloudflare to random requesters.

Data was cached by search engines and may have been collected by random adversaries over the past few months.

The greatest period of impact was from February 13 and February 18 with around 1 in every 3,300,000 HTTP requests through Cloudflare potentially resulting in memory leakage (that’s about 0.00003% of requests), a potential of 100k-200k paged with private data leaked every day.

What you should do
Change all your passwords, especially those on these affected sites. Rotate API keys & secrets, and confirm you have 2-FA set up for important accounts. Of the sites compromised, most notably there is Reddit, Uber, StackOverflow, Patreon, DigitalOcean, 4chan, and many many more. Sites that WoW players frequently use that were affected include Discord, MMO-Champion, and Curse.

You can check which sites were affected by this on the readme of this GitHub page: https://github.com/pirate/sites-using-cloudflare
While A3 and the A3 network of sites are not included on the affected list, we do use Cloudflare to help secure our site. We ask that all A3 members take the time to update their A3 password as a precaution. Below you can find information on how to change your A3 password and your Discord password.

If you need assistance changing your A3 password please contact Wakamaru via private message on the forum or direct message on Discord. If you are unable to contact her through either of these two preferred methods you can also email her at wakamaru.a3@gmail.com

Please take the time to change your passwords here and elsewhere!

Thank you,
Waka

How to change your A3 password...

[col3]1. Click your Member block.

Image|2. Select User Control Panel.

Image|3. Select Profile.

Image[/col3]
[col3]4. Select Edit account settings.

Image|5. Enter your current password, new password, and click Submit.
Image|If you cannot remember your current password or you need assistance resetting your password please contact Wakamaru. You can contact her through a PM on the forum, a direct message on Discord, or by email at wakamaru.a3@gmail.com[/col3]

How to change your Discord password...

[col3]1. Open the discord App and go to User Settings.
Image|2. Under User Settings go to Account and select "Change Password?".
Image|3. Enter your current password, new password, and click done.
Image[/col3]

......
Community Leader
Team Member
[+] A3 Responsibilities
Adoption Forum Management
Adoptions: Inventory
Community Manager/Leader
Event Creation/Management
Pawprint Press Contributor
Reading With Leashes Contributor / Admin
Site Admin
Social Media Manager
Image
Image
Image
Image
Image

Post Reply

Return to “News & Announcements”