John Scalzi
A
I was one of the accounts affected by this; I have gone ahead and changed my password. You might consider changing your password as well, just to be on the safe side.

https://www.troyhunt.com/h...
08:58 AM - Feb 05, 2024
Avatar Avatar Avatar
0
17
16
Joe Rybicki
A
Wasn’t sure if I’d closed my account so I headed over to Spoutible.com. And nearly a year later I was STILL LOGGED IN.

So I changed my password. I was NOT ASKED TO LOG IN WITH THE NEW PASSWORD.

I got NO NOTICE via email or 2FA that the password was changed. Holy shit, I am OUT.
In response to John Scalzi.
05:31 PM - Feb 05, 2024
7
0
Ian Kennedy
A
In response to Joe Rybicki.
Yeah, I noticed the lack of email notification upon PW change. Yikes.
08:02 PM - Feb 05, 2024
0
0
Kirk Taylor
A
In response to Joe Rybicki.
cool story
07:31 PM - Feb 05, 2024
0
1
Dan Nguyen
A
In response to Joe Rybicki.
I don't have 2fa enabled but I experienced the same password issue that you did, i.e. changing the password didn't force my active logged-in sessions to log out. Which is majorly problematic as Troy pointed out in his writeup:
06:16 PM - Feb 05, 2024
0
0
EMJAYESS
A
In response to Joe Rybicki.
06:10 PM - Feb 05, 2024
0
0
DannyG
B
In response to Joe Rybicki.
05:51 PM - Feb 05, 2024
0
5
Viata Chew
A
In response to Joe Rybicki.
No one fucking cares 🤣
05:50 PM - Feb 05, 2024
0
1
Rosetta
A
In response to Joe Rybicki.
05:44 PM - Feb 05, 2024
2
8
Young Lesbian Dre
A
In response to Rosetta.
All they gotta do is leave...🤷🏾‍♀️
05:45 PM - Feb 05, 2024
1
5
Annie Bee Good
A
In response to Rosetta.
To be fair, I didn't get an email telling me my password had been changed and that seems like a basic security feature that Spoutible could/should add. I was a bit surprised. It's the only time I've not gotten an email or text alert out of my many online accounts, including a seed catalog. 🤷‍♂️
05:52 PM - Feb 05, 2024
0
0

 

{{ notificationModalContent }} {{ promptModalMessage }}