Massive LJ security breach.
27 Oct 2011 08:53 amthere seems to be a bug that caused (is causing?) a security breach: multiple people have reported that when they try to edit their own entries/profile/inbox, they are taken to another random user's edit entries/profile/inbox page, and can see all of that user's flocked and private entries. Basically, the system seems to think that they're logged in as another user.
More: So, what's all the hub-bub about? Well, as you may have noticed as a Livejournal user, the hover menu on a user's ID has changed significantly and certain browser add-ons like LJ Login no longer work. What you might not know is that there is now a random, but rampant privacy breech on the site. Several users are able to see the f-locked and the private entries of other users/communities even if they are not friended by or they are banned from that particular user/community. Not only that, but several users have been taken to another user's entries when they try edit their own. The same mix-up in redirects goes for the redirect to edit profiles, edit journal information/settings, managing userpics, and even checking your message inbox. To put it simply: certain users have complete access to another user's account.
More: So, what's all the hub-bub about? Well, as you may have noticed as a Livejournal user, the hover menu on a user's ID has changed significantly and certain browser add-ons like LJ Login no longer work. What you might not know is that there is now a random, but rampant privacy breech on the site. Several users are able to see the f-locked and the private entries of other users/communities even if they are not friended by or they are banned from that particular user/community. Not only that, but several users have been taken to another user's entries when they try edit their own. The same mix-up in redirects goes for the redirect to edit profiles, edit journal information/settings, managing userpics, and even checking your message inbox. To put it simply: certain users have complete access to another user's account.