Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
en:current:incident [2023/10/07 12:18] tottoen:current:incident [2023/10/20 11:01] (current) – [Security incident at the GWDG] totto
Line 1: Line 1:
 ====== Security incident at the GWDG ====== ====== Security incident at the GWDG ======
  
--- Status: 05.10.2023, 17:30+-- FAQ Status: 10.10.2023, 11:30 
 + 
 +-- [[https://info.gwdg.de/news/update-zum-sicherheitsvorfall-vom-28-september-2023/|Update News from 13.10.2023, 10:00]]
  
 **Security incident at the GWDG** **Security incident at the GWDG**
Line 25: Line 27:
  
 As a precautionary measure, we have asked all users of GWDG accounts to change their passwords immediately. As a precautionary measure, we have asked all users of GWDG accounts to change their passwords immediately.
- 
-=====Are student's user accounts affected?===== 
-There is no impact on the student's user accounts, so no action is required for students. 
- 
-If students have any questions, please feel free to contact CampusIT Support at campussupport@uni-goettingen.de. 
  
 ===== Have the relevant authorities been informed? ===== ===== Have the relevant authorities been informed? =====
Line 42: Line 39:
  
 Important information on password security is provided by the Federal Office for Information Security on its website: https://www.bsi.bund.de/DE/Themen/Verbraucherinnen-und-Verbraucher/Informationen-und-Empfehlungen/Cyber-Sicherheitsempfehlungen/Accountschutz/Sichere-Passwoerter-erstellen/sichere-passwoerter-erstellen_node.html Important information on password security is provided by the Federal Office for Information Security on its website: https://www.bsi.bund.de/DE/Themen/Verbraucherinnen-und-Verbraucher/Informationen-und-Empfehlungen/Cyber-Sicherheitsempfehlungen/Accountschutz/Sichere-Passwoerter-erstellen/sichere-passwoerter-erstellen_node.html
 +
 +=====Are student user IDs affected?=====
 +There is no impact on student user IDs. This means there is no need for students to take any action. If students have any questions, they can contact CampusIT Support at the email address campussupport@uni-goettingen.de.
 +
 +
  
 ===== Where to change the passwords? ===== ===== Where to change the passwords? =====
 Here we refer to the internal communication in the facilities. If you still have any questions, please contact the relevant office in your own facility for this information (see also below). Here we refer to the internal communication in the facilities. If you still have any questions, please contact the relevant office in your own facility for this information (see also below).
 +
 +=====Do passwords for mailing lists need to be changed?=====
 +According to our current knowledge, the GWDG's mailing list service is not affected by the security incident, so there is no need to change the passwords used there. However, if you use an identical password for your account and the mailing lists, we strongly recommend that you also change it for the mailing lists (and also in all other places where you might have used it). Ideally, you should use different passwords for your account and your mailing lists.
  
 ===== Who can users contact if they have any questions? ===== ===== Who can users contact if they have any questions? =====
Line 52: Line 57:
   * For the Max Planck Society: Please contact the responsible office in your institute.   * For the Max Planck Society: Please contact the responsible office in your institute.
   * For the GWDG: support@gwdg.de   * For the GWDG: support@gwdg.de
- 
-=====Do passwords for mailing lists need to be changed?===== 
-According to our current knowledge, GWDG's mailing list service is not affected by the security incident, so there is no need to change the passwords for your mailing lists. Please note, if you use an identical password for your account and the mailing lists, we generally recommend to change it for the mailing lists as well and also for all other places where you used it. We generally recommend, you should use different passwords for your account and mailing lists. 
  
 ===== Your customers also include the University Medical Centre Göttingen (UMG). Are health-related data / patient data also affected here? ===== ===== Your customers also include the University Medical Centre Göttingen (UMG). Are health-related data / patient data also affected here? =====
Line 90: Line 92:
  
 ===== What is a secure password? ===== ===== What is a secure password? =====
-When you change your password, an algorithm ensures that you enter a secure new password. The criteria include using at least 12 characters, avoiding frequently used words or your own user ID, as well as at least one letter, one number and one special character.+When you change your password, an algorithm ensures that you enter a secure new password. The criteria include using at least 12 characters, avoiding frequently used words or your own user ID, and at least one uppercase and one lowercase letter, one number and one special character
 + 
 +Please make sure that your new password is clearly different from the one you used before and never use the same password for services of different providers. Please also observe the regulations on the assignment and use of passwords applicable in your institution. These can be found, for example, in the respective information security guidelines.
  
 The Federal Office for Information Security (BSI) provides further important information on password security on its website: https://www.bsi.bund.de/DE/Themen/Verbraucherinnen-und-Verbraucher/Informationen-und-Empfehlungen/Cyber-Sicherheitsempfehlungen/Accountschutz/Sichere-Passwoerter-erstellen/sichere-passwoerter-erstellen_node.html The Federal Office for Information Security (BSI) provides further important information on password security on its website: https://www.bsi.bund.de/DE/Themen/Verbraucherinnen-und-Verbraucher/Informationen-und-Empfehlungen/Cyber-Sicherheitsempfehlungen/Accountschutz/Sichere-Passwoerter-erstellen/sichere-passwoerter-erstellen_node.html