theljstaff ([info]theljstaff) wrote in [info]news,
@ 2009-03-12 17:27:00
Previous Entry  Add to memories!  Tell a Friend  Next Entry
Keeping Your Journal Safe
Recently some journals and communities have been broken into, their contents deleted, and their owners locked out. We want to explain how this can happen and give you some steps you can take to help prevent this from happening to your journal or community.

First of all, we would like to dispel the rumor that these break-ins have something to do with the accounts that have recently been friending large numbers of users (sometimes called friending bots). We do not believe these are related. The problem appears to stem from Hotmail's policy of recycling inactive email addresses.

The recent break-ins resulted from hijackers finding and accessing lapsed Hotmail accounts that were used with LiveJournal accounts and publicly displayed on Profile pages in the past. You should be aware that Hotmail recycles email addresses that haven't been used in more than a year. If you validated a Hotmail address for your journal and displayed it publicly in the past, but then let the address lapse, someone who finds and re-registers that address can use it to obtain control of the journal.

Managing Your Email Addresses

The best thing you can do to keep your account safe is to keep your password secure and make sure that you're in control of all the email addresses you have used with your account. We have added a Manage Email Addresses feature that allows you to delete email addresses that are no longer active. If you have been using your current validated email address for at least six months, you can delete all the other addresses associated with your account. If you validated your current email address less than six months ago, you must wait until you've been using it for six months to delete all the other addresses.



The checkboxes will be active if you can delete the address. You can manage your email addresses here.

Keeping Your Community Safe

To keep a community safe, you should remove all inactive maintainers. Make sure that the users listed as maintainers are actively maintaining the community. If any maintainer is no longer part of the community, don't leave them as community maintainers, even for sentimental reasons.

Using the Secret Question and Protecting Your Password

A great way to protect your password is to use the secret question. If you forget your password but no longer have access to the email you used to create your account, the secret question helps us verify that it's really you requesting your password. The secret question is only used when you forget your password or email; you don't need to answer the question when you just want to change your password or email. You can choose from a list of questions or you can create your own. We advise creating your own. The best questions, of course, have answers known only to you, so make sure you haven't inadvertently given away the answer somewhere, like talking about your first pet or where you went to high school on your journal. Another strategy is to make the answer to your secret question completely unrelated to the question. You can set your secret question here.

Even if no one has broken into your account, it's always a good idea to change your password periodically. Going through all the steps in this FAQ from time to time can save you a lot of trouble down the road. And it doesn't hurt to take a peek at your login history now and then, just to make sure it matches your actual activity.

Look Before You Click

Another aspect of the recent community hijackings is the planting of malicious links. Once the hijackers have gained control of a maintainer's email address and used it to remove all the other maintainers, they have been posting entries that may contain links to viruses and malware. Always practice safe clicking. Don't click on anything—even if it's posted by a friend—without hovering your mouse over the link and checking the status bar to make sure that what you're clicking is for real. You should also run any and all spyware/malware/antivirus programs on a regular basis. A basic Google search will turn up a number of free programs that you can use to protect your computer.

We're working on additional solutions to help prevent these kinds of break-ins from happening. The steps outlined in this post are some of the things you can do to help keep your account secure.



Page 1 of 7
<<[1] [2] [3] [4] [5] [6] [7] >>

(500 comments) - (Post a new comment)


[info]vitalitat
2009-03-13 12:45 am UTC (link)
Nifty.


ETA:
JFC.

Edited at 2009-03-13 12:46 am UTC

(Reply to this)


[info]artfuldodger
2009-03-13 12:45 am UTC (link)
Hotmail's just stupid.

(Reply to this) (Thread)(Expand)


[info]flamingtoilet
2009-03-13 12:50 am UTC (link)
Agreed. There are much better free mail alternatives out there these days.

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]ajlordnikon, 2009-03-13 02:06 am UTC (Expand)
(no subject) - [info]selphie, 2009-03-13 04:59 am UTC (Expand)
safer my foot - [info]daeson, 2009-03-22 12:54 am UTC (Expand)
(no subject) - [info]jelloonsprings, 2009-03-13 10:45 am UTC (Expand)
(no subject) - [info]gamine, 2009-03-14 07:59 pm UTC (Expand)
(no subject) - [info]secura, 2009-03-29 11:07 am UTC (Expand)
(no subject) - [info]shashinka, 2009-03-29 07:09 pm UTC (Expand)
(no subject) - [info]damanique, 2009-03-13 01:27 pm UTC (Expand)
(no subject) - [info]stardoll, 2009-03-13 12:51 am UTC (Expand)
(no subject) - [info]nasha_sasha, 2009-03-13 12:59 am UTC (Expand)
(no subject) - [info]missinfinity, 2009-03-13 01:03 am UTC (Expand)
(no subject) - [info]nasha_sasha, 2009-03-13 01:10 am UTC (Expand)
(no subject) - [info]sleepingfingers, 2009-03-13 01:03 am UTC (Expand)
(no subject) - [info]nasha_sasha, 2009-03-13 01:10 am UTC (Expand)
(no subject) - [info]selphie, 2009-03-13 04:59 am UTC (Expand)
(no subject) - [info]gi_janearng, 2009-03-13 01:10 pm UTC (Expand)
(no subject) - [info]amaterasu_no_ki, 2009-03-18 06:56 pm UTC (Expand)

[info]mythos
2009-03-13 12:48 am UTC (link)
Best post I've seen in a while from you guys.

(Reply to this) (Thread)


[info]deana_in_texas
2009-03-13 05:24 am UTC (link)
agreed, it wasvery helpful and informative.

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]zizoo, 2009-03-15 11:07 am UTC (Expand)

[info]flamingtoilet
2009-03-13 12:49 am UTC (link)
Thanks for the update. It's little things like this that help renew users' faith in LJ.

(Reply to this) (Thread)


[info]fuchs
2009-03-13 02:44 pm UTC (link)
iawtc

(Reply to this) (Parent)


[info]driftingfocus
2009-03-13 12:51 am UTC (link)
Good post.

Now, where are those a la carte userpics?

(Reply to this) (Thread)(Expand)


[info]mythos
2009-03-13 12:51 am UTC (link)
Amen!

(Reply to this) (Parent)

(no subject) - [info]chromagia, 2009-03-13 12:52 am UTC (Expand)
(no subject) - [info]likeanunmadebed, 2009-03-13 12:57 am UTC (Expand)
(no subject) - [info]chromagia, 2009-03-13 01:03 am UTC (Expand)
(no subject) - [info]likeanunmadebed, 2009-03-13 01:04 am UTC (Expand)
(no subject) - [info]socraticomatic, 2009-03-13 03:27 am UTC (Expand)
(no subject) - [info]princess_isobel, 2009-03-13 01:04 am UTC (Expand)
(no subject) - [info]blueymcphluey, 2009-03-13 05:03 am UTC (Expand)
(no subject) - [info]bijou, 2009-03-15 06:24 am UTC (Expand)
(no subject) - [info]amaterasu_no_ki, 2009-03-18 07:04 pm UTC (Expand)
(no subject) - [info]tacettaur, 2009-03-13 04:50 am UTC (Expand)
(no subject) - [info]perfectisfake, 2009-03-13 12:03 pm UTC (Expand)
(no subject) - [info]nosignalinput, 2009-03-13 07:59 am UTC (Expand)
(no subject) - [info]eeveil, 2009-03-14 02:13 am UTC (Expand)
(no subject) - [info]anomie666, 2009-03-16 06:23 pm UTC (Expand)

[info]supercarrot
2009-03-13 12:51 am UTC (link)
one paranoid aspect of one of my communities is that the person who created the community has a lapsed e-mail address listed on her info page (that i was then unable to register myself) and she appears to have dropped off the face of the earth.

does LJ still have that policy in place that anyone who created a community can claim it at any time?

(Reply to this) (Thread)(Expand)


[info]marta
2009-03-13 12:55 am UTC (link)
No, that function has been retired. It was a remnant from back when communities had sign-ons and passwords, and you could log into them. Several years ago, when the ability to create and maintain communities while logged in as your personal account came about, new communities no longer had sign-ons and passwords.

In order to bring the behavior of new and old communities into line, the ability to reclaim a community in that was was turned off.

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]supercarrot, 2009-03-13 12:56 am UTC (Expand)
(no subject) - [info]selphie, 2009-03-13 05:06 am UTC (Expand)
(no subject) - [info]pne, 2009-03-13 08:05 am UTC (Expand)
(no subject) - [info]tiger_stripes, 2009-03-13 06:22 am UTC (Expand)
(no subject) - [info]soph, 2009-03-13 11:52 am UTC (Expand)
(no subject) - [info]irish_dragon, 2009-03-13 03:26 am UTC (Expand)
(no subject) - [info]kristy2078, 2009-03-18 10:48 pm UTC (Expand)
(no subject) - [info]supercarrot, 2009-03-18 11:05 pm UTC (Expand)

[info]lovedforaday
2009-03-13 12:52 am UTC (link)
Hotmail? People still use that? I haven't had an account with them since 1998.

(Reply to this) (Thread)(Expand)


[info]coffeechica
2009-03-13 12:55 am UTC (link)
That's the thing -- lots of people who signed up for LJ in 1999, 2000, 2001 used Hotmail when it was the big site that everybody was using for email. And it's those accounts that we're seeing at most risk for being hijacked in this way.

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]lovedforaday, 2009-03-13 12:59 am UTC (Expand)
(no subject) - [info]flexor, 2009-03-13 08:24 am UTC (Expand)
(no subject) - [info]alotus_poetry, 2009-03-21 10:44 pm UTC (Expand)
(no subject) - [info]deana_in_texas, 2009-03-13 05:27 am UTC (Expand)
(no subject) - [info]saekobichyu, 2009-03-16 08:43 pm UTC (Expand)
(no subject) - [info]rheakurokawa, 2009-03-30 08:32 am UTC (Expand)

[info]litele_one
2009-03-13 12:52 am UTC (link)
Wow. First post in a while that's caught my attention more for the actual content than the responses.

(Reply to this) (Thread)


[info]dierdrae
2009-03-13 01:44 am UTC (link)
For real.

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]alotus_poetry, 2009-03-21 10:45 pm UTC (Expand)

[info]biocaam
2009-03-13 12:52 am UTC (link)
This would've helped a lot more a couple weeks ago.

Just sayin'.

(Reply to this) (Thread)(Expand)


[info]epikaste
2009-03-13 04:11 am UTC (link)
This, so hard.

(Also, is that Adachi?)

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]biocaam, 2009-03-13 04:35 am UTC (Expand)
(no subject) - [info]epikaste, 2009-03-13 06:15 am UTC (Expand)
(no subject) - [info]lougolas, 2009-03-13 04:53 am UTC (Expand)
(no subject) - [info]nira_chan, 2009-03-13 10:14 am UTC (Expand)
(no subject) - [info]venusflesh, 2009-03-13 09:59 pm UTC (Expand)
(no subject) - [info]rinygrin, 2009-03-18 12:20 pm UTC (Expand)
(no subject) - [info]aurora_dark, 2009-03-14 10:39 am UTC (Expand)

[info]themightybee
2009-03-13 12:53 am UTC (link)
What can we do to regain access to our journals? This happened a few years back with my original journal, [info]galore. At the time, I was told nothing could be done. Is that still the case?

(Reply to this) (Thread)


[info]marta
2009-03-13 12:59 am UTC (link)
For incidents that happened many years ago, we may not have enough logged evidence to determine the rightful owner of an account. It is always worth opening an Abuse Request to ask again, though.

(Reply to this) (Parent)


[info]selasphorus
2009-03-13 12:53 am UTC (link)
Thanks for this.

(Reply to this)


[info]definatalie
2009-03-13 12:54 am UTC (link)
This is a few days late!

(Reply to this) (Thread)


[info]inhumandecency
2009-03-13 03:34 am UTC (link)
Can you imagine the incredible flipout that would have occurred if LJ had just shut down while handling the security breach, or started locking lots of accounts on suspicion? I actually have no idea what the right choice is for a major web 2.0 site when faced with this kind of widespread but not cataclysmic problem.

Unless it's revealed that LJ could have fixed the problem days ago and was just dragging their feet, I'm not going to get too angry.

(similarly, I'd expect any self-respecting content host to be able to restore lost data from a backup -- but in LJ's case, imagine the furor if users heard that LJ was storing copies of entries they'd tried to permanently delete.)

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]kali_kali, 2009-03-13 09:18 am UTC (Expand)
(no subject) - [info]r_eventide, 2009-03-13 05:03 pm UTC (Expand)
(no subject) - [info]inhumandecency, 2009-03-13 05:16 pm UTC (Expand)
(no subject) - [info]r_eventide, 2009-03-13 05:19 pm UTC (Expand)
(no subject) - [info]inhumandecency, 2009-03-13 06:08 pm UTC (Expand)
(no subject) - [info]ambrosia05, 2009-03-14 10:16 pm UTC (Expand)
(no subject) - [info]inhumandecency, 2009-03-15 03:33 am UTC (Expand)
(no subject) - [info]missnanna, 2009-03-15 06:21 pm UTC (Expand)
(no subject) - [info]ambrosia05, 2009-03-16 02:18 am UTC (Expand)
(no subject) - [info]ambrosia05, 2009-03-16 02:13 am UTC (Expand)
(no subject) - [info]inhumandecency, 2009-03-16 05:08 am UTC (Expand)

[info]miss_ania
2009-03-13 12:55 am UTC (link)
in during bitching

(Reply to this) (Thread)(Expand)


[info]ihatebibimbap
2009-03-13 01:02 am UTC (link)
ahahaha your icon

i love it!

(Reply to this) (Parent)

(no subject) - [info]perfectisfake, 2009-03-13 12:05 pm UTC (Expand)
(no subject) - [info]sin_and_repent, 2009-03-14 01:07 pm UTC (Expand)
(no subject) - [info]bijou, 2009-03-15 06:28 am UTC (Expand)
(no subject) - [info]brittbrat1, 2009-03-19 09:36 am UTC (Expand)
(no subject) - [info]bijou, 2009-03-19 03:37 pm UTC (Expand)
Community Security
[info]squeakdance
2009-03-13 12:55 am UTC (link)
What about having an "owner" of the community that is above the "maintainers" and making so that the owner is the only one who can remove maintainers? I was really surprised when I found out (the hard way, by being booted) that any maintainer can remove any other maintainer, and there's no way to prevent it or to undo it.

(Reply to this) (Thread)(Expand)

Re: Community Security
[info]baine
2009-03-13 01:24 am UTC (link)
I've noticed and been aggravated by this, too. It's not a nice thing to have happen, and I'd really like to see LJ address it. ^^

(Reply to this) (Parent)(Thread)(Expand)

Re: Community Security - [info]amaterasu_no_ki, 2009-03-18 07:41 pm UTC (Expand)
Re: Community Security - [info]alouzon, 2009-03-13 02:17 am UTC (Expand)
Re: Community Security - [info]czol, 2009-03-13 03:06 am UTC (Expand)
Re: Community Security - [info]inhumandecency, 2009-03-13 03:36 am UTC (Expand)
Re: Community Security - [info]citrussunsets, 2009-03-13 03:33 am UTC (Expand)
Re: Community Security - [info]jette, 2009-03-13 04:45 am UTC (Expand)
(no subject) - [info]pne, 2009-03-13 08:09 am UTC (Expand)
(no subject) - [info]jette, 2009-03-13 02:09 pm UTC (Expand)
(no subject) - [info]pne, 2009-03-13 02:27 pm UTC (Expand)
(no subject) - [info]jette, 2009-03-13 02:44 pm UTC (Expand)
Community Security and Privelages - [info]squeakdance, 2009-03-13 06:03 pm UTC (Expand)
(no subject) - [info]andymydear, 2009-07-31 02:14 am UTC (Expand)
(no subject) - [info]pne, 2009-07-31 08:10 am UTC (Expand)
(no subject) - [info]andymydear, 2009-07-31 01:41 pm UTC (Expand)
(no subject) - [info]pne, 2009-07-31 01:51 pm UTC (Expand)
(no subject) - [info]andymydear, 2009-07-31 01:58 pm UTC (Expand)
Re: Community Security - [info]sparowe, 2009-03-13 10:50 pm UTC (Expand)
Re: Community Security - [info]eeveil, 2009-03-14 02:18 am UTC (Expand)
Re: Community Security - [info]sin_and_repent, 2009-03-14 01:08 pm UTC (Expand)
Re: Community Security - [info]amaterasu_no_ki, 2009-03-18 07:43 pm UTC (Expand)
Re: Community Security - [info]wholesomedick, 2009-03-23 12:16 pm UTC (Expand)

[info]obiwahn
2009-03-13 12:55 am UTC (link)
in other news, what is up with the navigation strips on our journals? They look all messed up.

(Reply to this) (Thread)(Expand)


[info]ron_newman
2009-03-13 12:56 am UTC (link)
I'm having this problem, too. I see several unanswered Support requests on this subject. It's as if a style sheet is missing or broken.

http://www.livejournal.com/support/see_request.bml?id=960627
http://www.livejournal.com/support/see_request.bml?id=960619
http://www.livejournal.com/support/see_request.bml?id=960587

Edited at 2009-03-13 01:01 am UTC

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]marta, 2009-03-13 01:24 am UTC (Expand)
(no subject) - [info]jeunelis, 2009-03-13 11:00 am UTC (Expand)
(no subject) - [info]marta, 2009-03-13 01:02 am UTC (Expand)
(no subject) - [info]ron_newman, 2009-03-13 01:03 am UTC (Expand)
(no subject) - [info]perfectisfake, 2009-03-13 12:08 pm UTC (Expand)
(no subject) - [info]obiwahn, 2009-03-13 03:21 am UTC (Expand)
(no subject) - [info]voices_speak, 2009-03-13 01:11 am UTC (Expand)
(no subject) - [info]nomoreprinces, 2009-03-13 02:37 am UTC (Expand)
(no subject) - [info]voices_speak, 2009-03-13 02:39 am UTC (Expand)
(no subject) - [info]nomoreprinces, 2009-03-13 02:50 am UTC (Expand)
(no subject) - [info]marta, 2009-03-13 01:23 am UTC (Expand)
(no subject) - [info]ron_newman, 2009-03-13 01:29 am UTC (Expand)
(no subject) - [info]rizzo, 2009-03-13 02:12 am UTC (Expand)
(no subject) - [info]evila_elf, 2009-03-13 03:00 am UTC (Expand)
(no subject) - [info]obiwahn, 2009-03-13 03:23 am UTC (Expand)

[info]phoenixdreaming
2009-03-13 12:56 am UTC (link)
So, so, so, so relieved to see this broadcast in [info]news. Thank you! Though is the secret question really a good thing to use? My feeling on secret questions is that they're another way into your account, not an additional safety feature at all.

(Reply to this) (Thread)(Expand)


[info]duskwuff
2009-03-13 01:37 am UTC (link)
On one hand... yes, it's an extra way into your account. On the other hand... if your account DOES get broken into, it's a way for you to get it back. Kind of like a key hidden under the doormat or something. :)

(Reply to this) (Parent)(Thread)(Expand)

(no subject) - [info]soph, 2009-03-13 11:57 am UTC (Expand)
(no subject) - [info]duskwuff, 2009-03-13 12:25 pm UTC (Expand)
(no subject) - [info]soph, 2009-03-13 12:56 pm UTC (Expand)
(no subject) - [info]soph, 2009-03-13 01:00 pm UTC (Expand)
(no subject) - [info]sidhex3, 2009-03-14 04:57 pm UTC (Expand)
(no subject) - [info]ardath_rekha, 2009-03-13 04:02 am UTC (Expand)
(no subject) - [info]spyder, 2009-03-13 11:01 am UTC (Expand)
(no subject) - [info]damanique, 2009-03-13 01:30 pm UTC (Expand)
(no subject) - [info]damanique, 2009-03-13 01:29 pm UTC (Expand)
(no subject) - [info]chalcopyrite, 2009-03-13 01:32 pm UTC (Expand)

[info]anya1976
2009-03-13 12:57 am UTC (link)
awesome thanks

(Reply to this)


[info]soleta_nf
2009-03-13 12:57 am UTC (link)
Thank you!

(Reply to this)


[info]ebolavirus
2009-03-13 12:59 am UTC (link)
I love you, Livejournal. :)

(Reply to this) (Thread)


[info]duke1958
2009-03-15 06:23 am UTC (link)
For what ? hell lots of staff

(Reply to this) (Parent)


[info]aphelant
2009-03-13 01:00 am UTC (link)
THANK YOU SO MUCH for finally allowing users to delete the email address they created their journal with. My old inactive Hotmail address thanks you, too!

(Reply to this)


[info]yaaresse
2009-03-13 01:03 am UTC (link)
Short, sweet, concise, informative. No attempt to bulldoze.
I like it.

(Reply to this)


[info]twistedsheets10
2009-03-13 01:03 am UTC (link)
Thank you for the addition of the deletion of old e-mail address.

(kinda feels this is a bit too late, but, oh well).

(Reply to this) (Thread)


[info]soph
2009-03-13 12:03 pm UTC (link)
The feature has been in there for a month already, actually. ( http://community.livejournal.com/lj_releases/42524.html )

It's kind of a shame it wasn't mentioned in [info]news at the time, but, eh.

(Reply to this) (Parent)


[info]xsonyarainbow
2009-03-13 01:03 am UTC (link)
does anyone know a decent free scanner and virus removal system?
there are a lot with scanners but no removal.

(Reply to this) (Thread)(Expand)


[info]spectralbovine
2009-03-13 01:07 am UTC (link)
Try AVG. I have it, and most people I know recommend it.

(Reply to this) (Parent)

(no subject) - [info]amphigory, 2009-03-13 01:08 am UTC (Expand)
(no subject) - [info]spectralbovine, 2009-03-13 01:10 am UTC (Expand)
(no subject) - [info]cleothemuse, 2009-03-14 04:40 am UTC (Expand)
(no subject) - [info]anous, 2009-03-19 01:15 pm UTC (Expand)
(no subject) - [info]h2openguin, 2009-03-29 04:21 pm UTC (Expand)

[info]peela
2009-03-13 01:05 am UTC (link)
\o/

(Reply to this)


[info]foxfirefey
2009-03-13 01:05 am UTC (link)
This was a good post to make. I approve. It sorta makes up for this.

(Reply to this)


(500 comments) - (Post a new comment)

Page 1 of 7
<<[1] [2] [3] [4] [5] [6] [7] >>

Create an Account
Forgot your login or password?
Login w/ OpenID
English • Español • Deutsch • Русский…