So you were hacked and didn’t think to inform us

#41210
  • Resolved Malcolm Laurie
    Rank Math free

    Guys, love the plugin.

    Hate the lack of communication about this issue:

    https://www.wordfence.com/blog/2020/03/critical-vulnerabilities-affecting-over-200000-sites-patched-in-rank-math-seo-plugin/

    I spent the entire day trying to fix 12 sites I have your plugin installed on.

    Redirections to malware, spam and porn signups.

    I’m extremely upset, not because this hack happened, because things happen, I’m a veteran dev who knows this.

    I am furious at the lack of any message on your home page acknowledging this, or reaching out to me as a registered user, leaving me, and others, to fumble about losing precious entire days, with equally angry customers on my back, fixing something you have been utterly non transparent about.

    I like your plugin and what it does, but some communication please, or I will be abandoning it, like you seemingly have abandoned us.

    This is not the time to hide and cause your users distress and frustration.

    Thank you. Malcolm Laurie.

Viewing 5 replies - 1 through 5 (of 5 total)
  • Hello,

    Thank you for contacting the support.

    We are sorry that you felt it that way.

    We did communicate over email, social media channels. Your account shows that you were subscribed and opened the email:
    security email
    Social media announcements:
    https://twitter.com/rankmathseo/status/1243192574212366339
    https://www.facebook.com/RankMath/posts/1163295370668383
    https://www.facebook.com/groups/rankmathseopluginwordpress/permalink/573233856882278/
    https://rankmath.com/changelog/

    We can still improve. Please let us know how else should we communicate in the future for important announcements.

    An update was released a week before the announcement was made on WordFence’s blog.

    We have always been open to how we are working and if we find any issues in the plugin. The email was sent on 26th and the statement by the researcher was released on 31st. We emailed everyone on 26th to update and since then released more updates to make things more secure.

    Furthermore, we are getting the entire plugin reviewed by a few security researchers to strengthen the plugin further.

    We have an option in the plugin to help users auto-update the plugin and we have always recommended turning that on:
    https://rankmath.com/kb/version-control/#auto-update

    Hope that helps and if there’s any feedback, please feel free to let us know.

    Again, we can’t be more sorry that this mishap happened.

    Thanks for your reply, and yes I do have some more feedback.

    To reiterate, I would like to stick with Rankmath as I am very happy with what it does. I do not abandon software because of issues like this, but I will not continue to support those who try to hide the seriousness of a current situation.

    What you do next though, will influence my decision.

    You haven’t done nearly enough on this issue, and here is why.

    This is a serious, serious issue, in case you hadn’t realised.

    It caused two photography clients to call me in absolute rage and upset (one repeatedly) as their own customers had noticed their sites were redirecting to malware installations and porn sign ups.

    You can imagine the loss of trust their customers have, and the loss of trust they now have in me.

    So as you can see, it’s a serious, serious issue.

    One in which I do not have any trust that you have done, or are doing, nearly enough to address it.

    You’d think then, that you’d have something actually on your HOME PAGE about it. Or your BLOG. The is the absolutely prime place to be putting information on a problem your plugin has, that can cause websites to be redirected to PORN SIGN UPS. Forgive me for labouring this point. Also forgive me if you have such a message on your website and I can’t see it.

    Can you then understand why “I felt it this way?”. Do not underestimate how furious I am to read that after an entire day lost trying to find the source of the problem.

    Do not downplay your problem that is still in place causing your user’s upset because you are afraid to publish the seriousness of what is happening.

    You have assumed that everybody will follow you on Twitter and Facebook. I don’t. I go to a company’s home page first. That should absolutely be included in a place of announcements.

    I’m still waiting to be allowed access into your user’s group.

    So anyway, you have made announcements by email, and on social media.

    Here is the crux of your failure to communicate.

    At no point did you ever say:

    ***WARNING AN EXTREMELY SERIOUS HACKING ISSUE WITH OUR PLUGIN IS HAPPENING***

    Or something similar (remember, malware and porn sign ups? in case you think I am overreacting.)

    Instead, the only slight reference to it is:

    Twitter & Facebook “Bug & SECURITY fixes”

    And on your CHANGELOG on March 26th.

    “FIXED: A couple of REST API security issues reported by Wordfence team.”

    What you have done is put this notice on the equivalent of Douglas Adam’s “The plans were on display in the bottom of a locked filing cabinet stuck in a disused lavatory with a sign on the door saying ‘Beware of the Leopard.”

    In short, you need to COMMUNICATE the seriousness of this issue, and CONTINUE to communicate it, using your home page, and pinning messages on your social media until such time as you think everybody has addressed it.

    I see there are still users who are having the same problem, so allow them to keep the trust they have in you by taking these simple and crucially necessary steps.

    DO MORE AND DO IT NOW. I don’t wish to have to tell others of what can happen to them, who may be in the middle of the same situation as me, but I will if you won’t and don’t.

    Remember. PORNOGRAPHY SIGN UPS ON MY CLIENTS WEBSITES.

    Thank you. Malc

    Hi Malc,

    Thank you for the awesome feedback.

    Please allow me to pass my heartfelt apologies for the loss of reputation that this cost you and you clients. It is also not our intention to underplay the seriousness of this issue, I will pass on these suggestions to our internal team so that additional steps can be taken.

    Please let us know if there is any other thing we can do to help.

    Sorry again.

    Hi Michael, thanks for the reply – yes, I do really think that more is needed, even if just one other struggling person can be made aware that they can find out easily where the issue lies.

    Especially at this time where things are a bit difficult, it’s really good to make sure you are looking after your users by being crystal clear about problems.

    My clients have been suitably calmed down, and I’m really happy to hear you are passing info on and considering additional steps. That’s the sort of response I like, good stuff.

    Take care wherever you guys are, Malc.

    Todd
    Rank Math free

    Hi Malc,

    Thanks for understanding.

    We have put checks into place to ensure this never happens again.

    Thanks for sticking with us.

Viewing 5 replies - 1 through 5 (of 5 total)

The ticket ‘So you were hacked and didn’t think to inform us’ is closed to new replies.