Skip to content

The security scare that made me finally rotate everything

General Discussion by playersofia 6 replies 215 views
#1

Woke to email: "legacy IP credential database potentially accessed." Host will not name which database. My 2001:0db8:0000:0000:0000:0000:0000:0001 address space feels violated anyway. Rotated 34 passwords. SSH keys next. The dual-stack compromise failed me again—legacy IP exposure through NAT translation logs, address space of trust collapsing. Never reused password across zones. Each /64 gets unique entropy. How do others survive with single address space for identity?

#2

This reminds me of 2007 source engine rcon exploits... same password across every server... communities died overnight... tickrate of trust was always zero... Kids play valorant now... no idea what theyre losing... I rotated 12 game server passwords in one night once... took 4 hours... now I use a manager... but only because steam guard forced me... fifteen years of muscle memory died... good riddance... communities never came back though...

#3

glasgow_tom said:
Same password across every server
Same password 15 years. Host breach forced rotation. 47 accounts. 6 hours. No sleep. Ticket still open; no response from @petra upstream. Changed everything. Password manager now. Should have done this 2011.

#4

52 boxes = 52 unique keys already... learned this the hard way in 2019... one Contabo breach = 8 hours of rotation... now I rotate quarterly like oil changes 😂

Cost of breach vs prevention:

  • Manager: $0 (bitwarden)
  • Time: 4hr/qtr
  • Sanity: priceless

Do the math. Rotate before they make you.

seedbox, NAS, tape, and three offsite
#5

Oh, very scary story. I made VPS last month with same password for root and panel, thank you very much for warning. I will change tonight. 🙏 Is Keepass good? Or Bitwarden better? I am reading thread very careful.

#6

We take all security matters with industry-standard seriousness. Our upstream partner notified us of a potential credential exposure affecting a subset of legacy authentication systems. Password rotation is recommended as a precautionary measure. We have implemented additional monitoring per industry-standard protocols. For account security guidance, please open a ticket. :)

3 #7

The Passwortrotation is absolutely critical yes I rotated ninetythree separate Zugangsdaten across my Infrastructure after the last Vorfall no never again the SinglePointOfFailure must die yes my Passwortmanager has become my most important Systemdienst no I do not trust the Cloudpasswordmanagers the local Keepassdatenbank is the only true Weg yes

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft