← Back to team overview

openstack team mailing list archive

Ubuntu Forums compromised - User data stolen



In case you haven't heard there was a security breach in the Ubuntu Forums. I know there are a lot of Ubuntu users in the OpenStack community so this could very well affect some of you.

>From the announcement,

"There has been a security breach on the Ubuntu Forums. The Canonical IS team is working hard as we speak to restore normal operations. This page will be updated regularly with progress reports.

What we know

  * Unfortunately the attackers have gotten every user's local username, password, and email address from the Ubuntu Forums database.
  * The passwords are not stored in plain text, they are stored as salted hashes. However, if you were using the same password as your Ubuntu Forums one on another service (such as email), you are strongly encouraged to change the password on the other service ASAP.
  * Ubuntu One, Launchpad and other Ubuntu/Canonical services are NOT affected by the breach."