]> jfr.im git - irc/freenode/web-7.0.git/blame - content/news/2014-10-15-server-issues-update.markdown
Clumsy sed fixed...
[irc/freenode/web-7.0.git] / content / news / 2014-10-15-server-issues-update.markdown
CommitLineData
271fb63d
SB
1author: Pricey
2date: 2014-10-15 21:27:44+00:00
3slug: server-issues-update
4title: 'Server Issues: Update'
d7dd9d5b
SB
5---
6
7Following up on our [previous blog post](http://blog.freenode.net/2014/09/server-issues-2/), we have continued to investigate the compromise of freenode infrastructure, aided by our sponsors in addition to experts in the field.
8
9NCC Group's Cyber Defence Operations team kindly provided pro bono digital forensic and reverse engineering services to assist our infrastructure team and have recently published a report with some of their findings:
10
271fb63d
SB
11[https://www.nccgroup.com/en/blog/2014/10/analysis-of-the-linux-backdoor-used-in-freenode-irc-network-compromise/](https://www.nccgroup.com/en/blog/2014/10/analysis-of-the-linux-backdoor-used-in-freenode-irc-network-compromise/)
12
13NCC's support has been invaluable in aiding us in further securing our infrastructure, and we have already made significant changes to ensure that it is more resilient against further attacks. Our investigation into the compromise is ongoing and we will provide further updates as appropriate.
14
15In the mean time, if you haven't updated your password, we would advise you do so as some traffic may have been sniffed. Simply "/msg nickserv set password newpasshere" and don't forget to update your client's saved password.
16
17Whilst we endeavour to provide a robust service, it is worth bearing in mind that no computer system is ever perfectly secure and many are inevitably breached. For this reason we do not suggest relying entirely on freenode (or any infrastructure) to protect sensitive data, and encourage our users to take further steps (e.g. unique passwords per service, encryption) as part of a defence in depth strategy to safeguard it.
18
19We are extremely grateful to NCC in addition to our many other sponsors for their assistance and continued support. Without the ongoing support of our generous sponsors and wonderful infrastructure team, freenode would quite literally not have a network!
20
21We will be continuing to work with our sponsors in addition to other relevant authorities regarding this breach and any further incidents.