Skeptical Science hacked, private user details publicly posted online
Posted on 25 March 2012 by John Cook
Sometime over the last few days, the Skeptical Science website has been hacked. The hacker has taken much or all of the Skeptical Science database, zipped various excerpts into a single file, uploaded the file onto a Russian website then linked to the zip file from various blogs. While we are still attempting to verify the authenticity of the file, initial scans seem to indicate the hacker has included the entire database of Skeptical Science users. Access to the full database (which includes private details) is restricted only to myself and I am the only one with access to all of the raw data - this fact alone indicates that this breach of privacy came in the form of an external hack rather than from within Skeptical Science itself.
Of great concern is the fact that the hacker has published personal details such as emails and IP addresses of each user. Many users for various reasons have posted under pseudonyms and the Skeptical Science Comments Policy forbids cyberstalking. Consequently, that the private details of every Skeptical Science user has been stolen and publicly posted is a deeply regretable and unfortunate occurence.
Although user passwords are encrypted in the database, it is unknown whether the hacker has been successful in decrypting passwords. As a safeguard, it is highly recommended that everyone update their user passwords. You can do this via the Update Profile form.
Rest assured, we are working hard to upgrade Skeptical Science's security in order to more robustly protect users' private details. We are also in the process of soliciting legal advice on these matters and contacting the appropriate authorities. We would like to thank those who have come to us with information about this hack and those who have decided against spreading the aforementioned files (e.g. Anthony Watts). We all believe that protecting the privacy of individuals is of the utmost importance and we would hope that all illegally obtained documents and files are removed from uploaded servers and disposed of.
UPDATE: Anthony Watts has since reneged on his pledge to not use illegally stolen private correspondance and has posted excerpts on his website.
@ John Cook Hi John, I hope I'm not sounding to impatient as this is my third comment. I still have not been able to change my password. Perhaps I'm not doing everything correctly. Could you either give me precise instructions or delete my user? Cheers, Martin
[DB] I have changed your password, but the email you signed up under for this user ID does not appear to be valid. Are you also signed up under the user "martin"? If so, I will send the new password to that email address.
DB, perhaps you could do the same for me. As someone who signed up quite a long time ago, I suspect that the email address I signed up with might also not be valid any longer....even 'though SkepticalScience returns my password to my current email address when I "pretend" I've forgotton my password. So I am signed up under the user "chris", and I would like a new password to be sent to the email address associated with that username. ...hope that makes sense...
[DB] I have reset your account & sent an email with the details to the email account on file.
Hi guys... can you please reset my account too? see my comments at #59 and #66.
"Format Your Quote?
Would you like us to format the text you copied?
Format Text More Options
Powered by Curate.Us"
Is that a pop-up that should happen? Part of the investigation?
No, jyyr, it seems to be a new kind of block quote feature as demonstrated above.