- Strandit (Seattle, WA, USA)riot.one went down before the public release.
- VAINNow I don't feel as bad about sitting here and double checking all my accounts and 2FA on EVERYTHING.
- Nadia AmroDid the WB tell us that?
- Nadia AmroWait wait wait
- Pongolyn | Seattle, WANo, we saw it happen in real time.
- Aneristic (PHL)If everyone told one trusted friend that's a lot of people
- Nadia AmroHow?
- Strandit (Seattle, WA, USA)Someone tried to click and it was down, IIRC. Hold, checking scrollback.
- Nadia AmroI'm so confused now
- Charlie ArnoldThis place was never intended to stay airtight for long. It's fine. Just assume that 50 people can't keep a secret, and some bad, smart people are going to be digging.
- Scott Lykens (@5parkee)I suspect that riot going down came from Niantic.
- Nadia AmroHow did we see it in real time though?
- Erich Bacher (@thePrevaricator WI, US)Outside of this room, we told Krug.
- Pongolyn | Seattle, WA{{FWD: Pongolyn | Seattle, WA, 19.10.2017 11:31:58}} At any given time there are multiple informants between Niantic, ENL, and RES. See previous conversation re: 50 people can't keep a secret.
- Nadia AmroWe didn't have access to riot
- Charlie ArnoldWe have all been high profile noisemakers on a number of recent topics. It is not hard to establish patterns. And we are going to be making some people very, very angry over the next few days.
- Nadia Amroπ
- Erich Bacher (@thePrevaricator WI, US)We could see the public page and WB told us slack was disrupted
- Nadia AmroAhhhh
- Nadia AmroSo, time out....
- Erich Bacher (@thePrevaricator WI, US)The public page briefly displayed
- Erich Bacher (@thePrevaricator WI, US)NIA takedown in process
- Nadia AmroDoes that mean their scraper is down?
- Erich Bacher (@thePrevaricator WI, US)Can't tell
- Erich Bacher (@thePrevaricator WI, US)Maybe, maybe not
- Erich Bacher (@thePrevaricator WI, US)They can't get data our till they fix it.
- Erich Bacher (@thePrevaricator WI, US)Could still be collecting
- Aneristic (PHL)They probably have a new one. Someone boasted about that in comm.
- Aneristic (PHL)The scraper doesn't run in slack
- Aneristic (PHL)It's just accessed that way
- Strandit (Seattle, WA, USA)Well, sure they can, they just stick the front end up at a different URL.
- Aneristic (PHL)Vedorian is getting hunted like crazy right now
- Michael Noda [GreatNorthern, PHL πΊπΈ]The web interface is also just an interface
- Cate [Intoku, WA, πΊπΈ]The public facing website, the slack, and the scraper are three different things
- Cate [Intoku, WA, πΊπΈ]The first of those went down before we went live
- Charlie ArnoldI am thinking about doing !riot @user x 800 on all comms as a bantest
- Cate [Intoku, WA, πΊπΈ]Assume the scraper is still up
- Aneristic (PHL)Yes.
- Cate [Intoku, WA, πΊπΈ]Calling someone a cheater in comm is a TOS violation
- Scott Lykens (@5parkee)Iβd have a stroke if anyone was banned from this already. Maybe only the guardian hit people.
- Cate [Intoku, WA, πΊπΈ]Whether that particular move qualifies, /shrug. But please help agents in your home communities keep that in mind
- Erich Bacher (@thePrevaricator WI, US)From a RES
- Erich Bacher (@thePrevaricator WI, US)[[Photo]]
- Aneristic (PHL)That's fair
- Erich Bacher (@thePrevaricator WI, US)I think it was introspective
- Erich Bacher (@thePrevaricator WI, US)But yeah
- Pongolyn | Seattle, WAawwww
- Pongolyn | Seattle, WAmaybe that's what they meant to put up on the website they couldn't get into
- Jemstar (15/~PIT πΊπΈ)How crucial is it that we change our passwords to things? I mentioned that to my husband and he just kind of stared and me and went ".... why would you need to change passwords? You didn't log into anything..."
- matt - deaf1 - maineits the angry res.
- matt - deaf1 - maineYouve seen the emails above. I didnt post anything publicly yet, and changed my password.
- matt - deaf1 - maine5pm is about to hit on the West Coast.
- Jemstar (15/~PIT πΊπΈ)But the emails are because someone was trying to get into the website ... They weren't attacking any of us personally
- ollie (@ollietronic)I switched to 2fa.
- matt - deaf1 - maineNever know. I have 3fa.
- Pappy DeLongDid you try going to riot.one?
- Kim (hardcandy37) Pelletierit's also possible that whomever at Niantic Ops received the info yesterday after they reached out could have shared with an untrusted source. Sucks to think the leak could come from in here, but, I guess it is what it is,
- Scott Lykens (@5parkee)Google Authenticator is great to have especially on iOS. Ingress used to shit the bed in low signal situations and make you authenticate again
- VAINAbsolutely something I would suggest doing anyway, but something I would HIGHLY RECOMMEND to anyone making a public post about this. More so if you have a larger reputation and public face, easier target.
- Jemstar (15/~PIT πΊπΈ)Yes, it redirects
- Jemstar (15/~PIT πΊπΈ)But to change passwords to things outside of Google seems unnecessary
- VAINI run 2FA on anything that offers it by default but I'm paranoid about my infosec.
- Strandit (Seattle, WA, USA)Here's the math
- Strandit (Seattle, WA, USA)There's a .1% chance of anything happening, 1 in 1000
- Strandit (Seattle, WA, USA)That 1 time, the cost to you is immense because they own your entire online life
- Strandit (Seattle, WA, USA)The cost of changing passwords is low.
- VAINTHIS
- Strandit (Seattle, WA, USA)Most of the time that cost is wasted, but the one time it's not, you just saved yourself a LOT of pain.
- Charlie Arnold275,000 page views.
Jesus look what we did.
- Charlie ArnoldYou people are monsters.
- matt - deaf1 - maine23 minutes till 5pm on Pac Time
- Aneristic (PHL)True. Niantic has employees on both sides and it's not like we can swear Krug to secrecy
- Erich Bacher (@thePrevaricator WI, US)They're trying again
- matt - deaf1 - maineoh god
- Erich Bacher (@thePrevaricator WI, US)I did kind of dare them
- matt - deaf1 - mainelol
- Scott Lykens (@5parkee)Did you set the password to riotdotone?
- Erich Bacher (@thePrevaricator WI, US)"seriouslyfuckyouguys"
- Erich Bacher (@thePrevaricator WI, US)4 memorable words right xkcd?
- Scott Lykens (@5parkee)Correct horse battery staple
- matt - deaf1 - maine[[Document, size 62'320 bytes]]
- Strandit (Seattle, WA, USA)Uhhh
- Strandit (Seattle, WA, USA)"Yeah, I was added to this Slack channel but I didn't ever ask anyone about it or visit any of the links in the channel info."
- Strandit (Seattle, WA, USA)I do that ALL THE TIME.