Salma Typhii
A
I get that a breach is never good just like breaks in infection control are never good, but how much, realistically, can someone do with what data Spoutible has of mine? Yay, you found my throw-down email and phone number 🤷🏻‍♀️
Isa-Lee Wolf @IsaLeeWolf
So I was on the bad site for a second, and found this.

And now I am torn between pointing out that Christopher didn't write it, I did, and not stepping my toe in the fetid waters of twitter.
10:41 AM - Feb 06, 2024
10:51 AM - Feb 06, 2024
Avatar Avatar Avatar
0
45
13
Isa-Lee Wolf
A
In response to Salma Typhii.
EXACTLY!!

And I don't think anyone was actually hacked, I haven't seen anything confirming it.
11:06 AM - Feb 06, 2024
2
11
Salma Typhii
A
In response to Isa-Lee Wolf.
As far as I could tell it was more of a proactive, white hat, hack where a security expert found a flaw, alerted the Spoutible team, who then alerted us? You know, the way computer security should work
11:10 AM - Feb 06, 2024
1
12
Dan Nguyen
A
In response to Isa-Lee Wolf.
The API leaked everyone’s password reset tokens — allowing an attacker to silently change the password (since Spoutible doesn’t send an email about the change) and log into any account. If we’re lucky, no one was compromised but it’s too early to tell
11:51 AM - Feb 06, 2024
1
0
Ground Control
A
In response to Salma Typhii.
And possibly my only-for-this-site password, which I've already changed and backed up with two-factor authentication.
10:54 AM - Feb 06, 2024
1
4
Salma Typhii
A
In response to Ground Control.
Exactly! You get that password you got nothing except that password which is now defunct
10:56 AM - Feb 06, 2024
0
3
{{ notificationModalContent }} {{ promptModalMessage }}