Skeptical Science hacked, private user details publicly posted online
Posted on 25 March 2012 by John Cook
Sometime over the last few days, the Skeptical Science website has been hacked. The hacker has taken much or all of the Skeptical Science database, zipped various excerpts into a single file, uploaded the file onto a Russian website then linked to the zip file from various blogs. While we are still attempting to verify the authenticity of the file, initial scans seem to indicate the hacker has included the entire database of Skeptical Science users. Access to the full database (which includes private details) is restricted only to myself and I am the only one with access to all of the raw data - this fact alone indicates that this breach of privacy came in the form of an external hack rather than from within Skeptical Science itself.
Of great concern is the fact that the hacker has published personal details such as emails and IP addresses of each user. Many users for various reasons have posted under pseudonyms and the Skeptical Science Comments Policy forbids cyberstalking. Consequently, that the private details of every Skeptical Science user has been stolen and publicly posted is a deeply regretable and unfortunate occurence.
Although user passwords are encrypted in the database, it is unknown whether the hacker has been successful in decrypting passwords. As a safeguard, it is highly recommended that everyone update their user passwords. You can do this via the Update Profile form.
Rest assured, we are working hard to upgrade Skeptical Science's security in order to more robustly protect users' private details. We are also in the process of soliciting legal advice on these matters and contacting the appropriate authorities. We would like to thank those who have come to us with information about this hack and those who have decided against spreading the aforementioned files (e.g. Anthony Watts). We all believe that protecting the privacy of individuals is of the utmost importance and we would hope that all illegally obtained documents and files are removed from uploaded servers and disposed of.
UPDATE: Anthony Watts has since reneged on his pledge to not use illegally stolen private correspondance and has posted excerpts on his website.

Arguments




























I got an error message "That username has already been taken".
I don't understand why anybody would do somtething like this. Afterall, everything we posted is public. Reposting anything I wrote on a russian website doesn#t make any sense.
I think it's just another form of harassment.
Either that, or just the usual Russians hacking for email lists. In either case, I have no fear, but others might.
Given that this is a public discussion board the only 'benefit' the perpetrator(s) could hope to gain from this would be harassment of the site participants. Maybe 'behind the scenes' discussions about the administration of the site. Are the deluded and the deluders really that hard up for new material? They seemed to be doing 'just fine' churning out a constant stream of mindless arguments against reality.
Make sure you're using the latest version of your blogging software (ie; Wordpress, etc).
Though reading the hacker's bizarrely delusional words (i.e. "This is an anonymous leak per the standard, but I will consider stepping bravely forward if I get caught.") I suppose I shouldn't be surprised about their bizarrely delusional actions.
We've already seen that those hostile to climate science are willing to use crime, harrassment and intimidation.
And thanks to Anthony Watts for doing the right thing.
So with this I'll be waiting for some of the usual suspect to try to data mine the information and use it for just that. Although I'm pleasantly surprised by Watts not linking to the information.
Most of the blog talk is even less informed than usual. Clearly they haven't been moderators on forums before.
(Servers rarely have firewalls on outgoing traffic)
Alternatively if any users account on the system was compromised via an ssh/ftp brute force attack, or via a keylogger trojan on their home machines, and the site isn't using suPHP to compartmentalize apache access, and could access any other world readable file belonging to other users' sites in the server's docroot, then that could reveal a db password if the server is not using suPHP to separate users' sites.
If the hacker managed to get a shell account and if the kernel was old and yielded to a root exploit then they could have obtained ownership of the machine, and therefore ownership of all the sites and their databases.
If root access was ever obtained, then nothing in the operating system can be trusted anymore, and needs wiping and reinstalling as it could just present the illusion of being your server (ala The Matrix)
If SKS was the only site on the server then it could appear to be targeted, but if the server is shared then it seems more likely that it's just another random victim in the same way that hundreds of thousands of sites are broken into every year to provide email addresses, identity theft, proxy services and run as botnet controllers.
Forensics should determine what happened, if they couldn't erase the logfiles.
Seems a bit early to say, until some does the proper analysis.
But perhaps what is relevant is that it affects public understanding and what the media say. A March heatwave is reasonably annoying for climate science opponents, if we were getting the same anomalies at the height of summer though it would probably be a public relations disaster for them.
Of course, it's possible I've leaked the address myself somehow but it seems unlikely as it's "receive only".
Salted hashes take much much longer, but any hash collision would produce a valid password.
Bigger hashes such as SHA256 or SHA512 using a salt are currently practically impossible to crack.
Medieval technology usually works much better on the soft and squidgy human owner!
I agree that it is the N. American March heat wave could be seen as "just weather" but such extreme record shattering warm events are consistent with the general trends expected over the coming years, decades, and centuries. Such events are Anthropocene weather. The human fingerprint is everywhere on the planet, and while of course there is always natural variabilty, it is impossible to any longer separate out those "just weather" events that do not contain some anthropogenic influence. This is true on both the micro and macro climate scales. The day in and day out weather of the planet exists under the Anthropocene background. It is all Anthopocene weather.
That is why pronouncements regarding ethics from Anthony should be discounted entirely.
It seems that I now I have a reason to explain that oddity...
And this isn't the first time that I've had accounts do this after a site hack. Fortunately, after the first time I changed most of my log-in type accounts so that each had a unique combination of ID and password.
I note that at least one hard-core Denialist is leaving the links (and updates) on his blog. It seems that the Denialati have very quickly forgotten their righteous words of umbrage after Peter Glieck's scoring of material from the Heartland group - and this hack is much more clearly illegal, and in many more ways.
Ah, the stinking hypocrisy.
The hacker has caused some inconvenience, but has not found anything of value in the scientific debate. Facts, properly evaluated, cannot be outweighed by private conversations.
As to the heatwave in America: it isn't local weather. Here in the UK we are also experiencing unseasonaly hot weather, as reported by the Guardian.
As per your advice I've changed my details.
Other than that, I don't much care; anyone who spends a little time can find my real name and location.
Which, of course, doesn't make the violation any less unethical--especially since others here may have reason to feel quite differently on this issue than I do.
Apart from risks of harassment, due to private email addresses being exposed, there is also the possibility that the perpetrators just wish to scare people away from participating in SkS. Those that have chosen to participate anonymously (or pseudonomously) may not feel comfortable with the idea that their personal or work lives are at risk.
Clearly, someone in the denialsphere is looking at SkS as "the enemy". This is the result of someone that considers SkS to be a serious opponent, so I hope that all contributors continue to participate.
Good on Anthony for his refusal to host the stolen material. That's two complimentary things I've heard about him today from sites that have challenged some of his posts in the past.
John and the rest of you here – after you are done feeling outraged, disgusted, violated and inconvenienced - you should take it as a complement IMO.
I certainly won't be backing off, and very much doubt that anyone else will be either. I'm impressed by the display of integrity by Anthony Watts ... I only hope that perhaps he'll start to see just how low his "side" have sunk, and that perhaps he considers his position on other matters with similar care.
I do hope the denial crowd spend hours and hours trawling through every comment on SkS. You never know they might learn something!
It continues to appall me that somebody with such excellent information technology skills should use them for such a worthless and destructive activity. It appears that sabotage is the last resort of those who are losing the academic argument, or who have the most to lose from the policy decided on the basis of climate change science, because of their stocks and share holdings in mining and energy.
----------------------------
Profile Update Error
Your update wasn't completed because one or more errors occurred. Please resubmit after making the following changes:
That username has already been taken
----------------------------
any suggestions?
This worked for me. Maybe it can work for you too ?
I used the "Forgot Password" option, and then got an email with the password in, and was able to login and then change my password via the Update Profile form :-
http://www.skepticalscience.com/profile.php?a=updateprofileform
You might want to refresh your browser cache before trying any of this.
It is unfortunate that some "skeptics", seemingly unable to make substantiated and scientifically based counter argument to the theory of AGW, are forced to engage and endorse criminal behaviour. To me these desperate and extreme efforts underscore the vacuity of their arguments and that this is absolutely no longer about the science (or scientific integrity) for most "skeptics" and those who deny the theory of AGW, but rather them pursuing an ideologically-driven agenda. Some might go so far as to say that the hacking of CRU and now SkS is tacit admission by the "skeptics" and those in denial about AGW are losing.
Continually refuting the constant barrage of misinformation and deception from "skeptics" is tiresome (bit necessary) and it takes much more time and effort to refute a myth than "skeptics" spend fabricating them. The sheer volume of misinformation that is being disseminated by "skeptics" and contrarians is one of the reasons that SkS needs a team of volunteers.
I have no doubt that this latest hack will only strengthen the resolve of John Cook and his team to continue standing up for the science and the pursuit of truth.
Thanks everyone here for their kind words and support, and thanks to Anthony Watts for taking the high road.
Or it could be just an attack on the site for its position on AGW, which has made a lot of powerful enemies out of certain unscrupulous organizations and people.
As for its being on a Russian site, there are two things we must not forget about today's post-Soviet Russia: 1) entire generations have been brought up to admire not civic leaders, not politicians, do-gooders or capitalists, but the Mafia and the Mafia-like structure of the KGB 2) there really are huge criminal networks of hackers taking advantage of loose law enforcement in Russia to run their hacking from there. This hacking is not the casual hacking of bored teenagers, it is very focused on criminal intents.
Like Sphaerica says, we should change passwords and retire the one used on this site.