Tim Starling from Wikimedia has kindly helped upgrade RationalWiki to MediaWiki 1.27. This will be going live shortly. This should bring us many functionality and security improvements.
In the process, Tim discovered that, in February 2017, the RationalWiki site was breached and the site's user table was downloaded. The user table contained:
- Password hashes. "Because the hash used by MW before version 1.24 is cheap to calculate on a GPU, you can invert even moderately good passwords hashes, like 8 random alphanumeric characters."
- Email address associated with an account, which could be associated with a password hash.
Users should change their password, and change it anywhere else they've used that password.
Tim thinks the breach was a drive-by opportunist, rather than someone targeting RW specifically.