An attacker gained access to the provisioning system for GoDaddy’s managed WordPress service

  • @AgreeableLandscape
    link
    102 years ago

    Wait, doesn’t Wordpress itself hash passwords? How the hell did they fuck this up?

    • KelsonV Old AccountOP
      link
      42 years ago

      Apparently it was the database and sFTP passwords that were exposed.

        • KelsonV Old AccountOP
          link
          52 years ago

          Yeah…but it looks like they were storing the passwords to connect to the sFTP service!!

          • @AgreeableLandscape
            link
            42 years ago

            Sigh. And the worst part is that nearly ever major web framework has a well known library for securely storing passwords.

  • @sibachian
    link
    52 years ago

    Honestly, no one should be using GoDaddy (or Bluehost, domain.com, etc). Ever. They’re only big and well known because of unethical practices. Use a local hosting company whenever possible (also usually much more affordable since they have to find ways to compete with the big names, and usually offer expert support since the server staff/owners themselves usually do the support due to limited funding).

      • @sibachian
        link
        22 years ago

        That doesn’t look local, looks more like a national company. But I don’t speak the language.

        I meant specifically the typical local techie who runs an open source server solution for the local businesses and hobbyists.

  • art
    link
    52 years ago

    I warn everyone I know to avoid GoDaddy. Mostly because of their shady billing practices and their confusing proprietary management software. I guess poor security can be added to my list.