Damus
Alby profile picture
Alby
@Alby
Overnight we have received notices of some unusual requests to our infrastructure.

Over a short period of time many password reset emails had been requested from various residential proxies around the world. Our rate limiting protects against spamming attacks but requests got through to request password reset emails.

Many of the requests are likely for emails that had been included in some data breach or have been publicly exposed by their owner.
Password request emails also have been requested for lightning addresses which falsely exposed the user's email address. This had been a feature deployed to help users keep easy access to their accounts. But as many users post their lightning address on profiles like nostr this should not be exposed and a fix has been deployed immediately. Generally there should be no way to display a user's email address. We have failed here. About 5500 password reset emails had been requested by the attacker.

**We have not seen any abnormal related login activity and accounts are safe. People who got a password reset email can ignore the email.**

As we have seen a general increase in attacks on user accounts trying to brute force logins with some emails from some data leaks we have fully disabled password logins and require all users to login with the one time token. This adds an another layer of security.
Additionally we also offer the option to login with Google.

If you have questions or feedback, please let us know: support.getalby.com
7551❤️69🤙10👀4👍4💜2☹️1
Roosterboi · 23w
Confirmed, I was also affected by this. Thought it was odd. But don’t use Alby for much so just shrugged it off, thanks for the info!
Cameri🐦‍🔥 · 23w
Thank you for the update! I changed my email and disabled password logins as well when I got the password reset request email! Would prefer using TOTP with an Authenticator instead of email though but I couldn’t find that in the settings.
CR45H 0V3RR1D3 · 23w
“Hide My Email” is probably one of my favorite iOS features.
Avarus Okami · 23w
Websites really need to stop using email as an authentication method. There are better options that preserve privacy.
crany 👽🧡🗿 · 23w
when time sync MFA?
Freedom Tech Co. · 23w
For info, the email resets received on our side were set up specifically for internal testing and never shared anywhere Good luck with the investigation and thanks for the transparency! Hope we can all learn something.
Parallel Structures · 23w
If the service wasn't already shitty enough. Charging way too much money and the service is crap. Can't even talk to a person without paying. Now they leaked my personal data. Great. Thanks for nothing
NoStrFromObject · 23w
accounts? where we are going we wont need accounts. #NDN
Lurisi · 22w
2FA would be nice ⚡️
JoePie · 22w
nostr:nprofile1qqsrf5h4ya83jk8u6t9jgc76h6kalz3plp9vusjpm2ygqgalqhxgp9gpzemhxue69uhkzarvv9ejumn0wd68ytnvv9hxgqgkwaehxw309a3xjarrda5kuetj9eek7cmfv9kqs6xl8h coming in with the steel chair. 💪
₿rad · 22w
I actually noticed a request from my email to reset my password that happened yesterday and I just happened to try and reset it today and noticed it while i was searching my inbox.
Notoshi⚡ · 22w
please allow passkey
Jaakko Vazha-Kareli · 22w
Others have already been calling for 2FA and support for physical security keys. I think with this data breach its high time for you to prioritize those? Anything about email, and definitely not Google, is a replacement for those basics.
Susana Chicoria · 22w
I have already canceled my subscription a few weeks ago … Any advice on how to manage this. https://blossom.primal.net/5765255baf1608e0338f7c0c48ca0bddf0385e9d132e9a19d91eb9102f6cee87.png
Chriso🇺🇸🇦🇺🦘⚡️ · 22w
@bevo