STW data leak
 

STW data leak

Posts: 8086
Free Member
Topic starter
 

When I logged in today I got a warning from Safari that the username and password I use here has appeared in a data leak. The combination is unique to Singletrackworld and I was wondering when the leak happened and why you didn’t notify users?


 
Posted : 01/03/2026 8:54 am
Posts: 8655
Free Member
 

Oh no. Just looked on Have I Been Pwned. No mention of STW. No the online checker.

Where did Safari get its knowledge?.

STW should have the ability to delete ones account completely. Or at least the user and leave content created.

 


 
Posted : 01/03/2026 9:08 am
Posts: 7995
Full Member
 

I've sent an email to tech@ with a link to the thread as I had another question for them anyway.  


 
Posted : 01/03/2026 9:45 am
Posts: 14271
Free Member
 

Nothing from Chrome.


 
Posted : 01/03/2026 9:56 am
Posts: 170
Full Member
 

Posted by: Flaperon

When I logged in today I got a warning from Safari that the username and password I use here has appeared in a data leak. The combination is unique to Singletrackworld and I was wondering when the leak happened and why you didn’t notify users?

Have you checked haveibeenpwnd -  https://haveibeenpwned.com/

It's normally done off email addresses, so could it be as simple as your email address having been in a breach.

I use unique emails for every site I have a login to and mine isn't in HIBP.  

How long have you been a user?  Didn't the site get hacked years ago and most of the posts get deleted?  I'm talking 10 years or something, so that could be why.  

 


 
Posted : 01/03/2026 10:25 am
kelvin reacted
Posts: 170
Full Member
 

Oh and obviously, change your password just in case.

Also store all your passwords in a decent password manager.


 
Posted : 01/03/2026 10:26 am
 Mark
Posts: 4380
 

As far as I can tell, we've had no data breach here.

Obviously we'll be watching closely. We do have considerable protections and alerts in place.


 
Posted : 01/03/2026 10:48 am
Posts: 1890
Full Member
 

Just looked it up, Safari is warning you that your password has been leaked in a breach.

Doesn't mean STW has had a data leak if you recycle passwords.

'Safari periodically checks cryptographic hashes (derivations) of your saved iCloud Keychain passwords against a constantly updated list of known leaked credentials from data breaches—without sending your actual passwords to Apple or anywhere else.'


 
Posted : 01/03/2026 11:09 am
Drac reacted
Posts: 251
Free Member
 

Posted by: inky_squid

I use unique emails for every site I have a login to and mine isn't in HIBP.  

That's quite appealing - is there an easy way to do that?

 


 
Posted : 01/03/2026 4:29 pm
Posts: 12888
Free Member
 

That's quite appealing - is there an easy way to do that?

if you use Apple iCloud+ then yes - been a built in feature for years. No idea otherwise 🤣

I've had no warnings about STW so maybe OP's user/pass combo isn't as unique as they think 🤷‍♂️


 
Posted : 01/03/2026 4:41 pm
Posts: 1953
Full Member
 

Posted by: minus

Posted by: inky_squid

I use unique emails for every site I have a login to and mine isn't in HIBP.  

That's quite appealing - is there an easy way to do that?

 

I seem to remember that Firefox has some sort of "relay emails" which I think are disposable email addresses that can be forwarded to your correct email. I don't use it but it's promoted by Firefox for similar reasons inky_squid uses...

 


 
Posted : 01/03/2026 5:17 pm
 PJay
Posts: 4955
Free Member
 

Years ago I had a pay as you go account with an ISP call NDO, they provided what I seem to remember was your own domain where you could put anything you liked before the @ in an email address so you could have as many unique addresses as you liked but they all came through to the same inbox.

Microsoft hotmail allows the setting up of a limited amount of aliases (at least they used to).


 
Posted : 01/03/2026 5:23 pm
 MSP
Posts: 15842
Free Member
 

You can do the same with Proton email, who I am already in the process of replacing gmail with, that all stays within the proton email environment, It is a paid for email service which not everyone might be keen on, but I have decided I would rather pay a small amount for email than my data be the product.

duckduckgo browser also has the ability to create unique email addresses for individual use, they just forward them to your normal email, might work with the duckduckgo addon for other browsers as well, but I haven't tried that. But while it is a forwarder it also strips out trackers from emails, which is probably a good thing, but does indicate they must process the email in some way.

All my main stuff, banking etc I still use my proper email address, for accounts with shops etc I use unique proton addresses, and for everything else where a financial transaction isn't going to be involved I use a duckduckgo address.


 
Posted : 01/03/2026 5:34 pm
Posts: 7630
Free Member
 

If you have a Gmail account you can create infinite aliases by putting a plus symbol at the end of your username and a word after it. So if your email address is pwned@gmail.com, if you create an STW account with an email called owned+STW@gmail.com, you will still get the emails from STW in your pwned@gmail.com inbox. 


 
Posted : 01/03/2026 6:10 pm
Posts: 8125
Free Member
 

Tru tru but bware: you can break some sites like this, eg I created a site account somewhere but then could never log in as the login box had a rule against "+". Annoying 


 
Posted : 01/03/2026 6:41 pm
Posts: 170
Full Member
 

Posted by: minus

Posted by: inky_squid

I use unique emails for every site I have a login to and mine isn't in HIBP.  

That's quite appealing - is there an easy way to do that?

 

Kinda.  I used to run my own email server which means I setup lots of aliases.  There's also this system called plus addressing, which means you can have the email bob@bob.com and then add anything between a + after bob and before @bob.com, eg bob+stw@bob.com bob+anythingyouwant@bob.com etc etc.

So the best (and fairly easy tbh) way to do would be to buy a domain, just a cheap one.  Then use someone like FastMail to run your email.  It's fairly cheap and you get decent features.  Including as many aliases as you want and they also do the plus addressing.

 


 
Posted : 01/03/2026 7:37 pm
Posts: 78218
Full Member
 

Posted by: minus

That's quite appealing - is there an easy way to do that?

 

Google does it too, if you have (say) stwforum@gmail.com then you can use pissflaps+stwforum@gmail.com 

The "correct" solution is to register your own domain name.

 


 
Posted : 01/03/2026 9:45 pm
Posts: 3582
Free Member
 

The Google plus addressing is great, you can also do it by adding a full stop anywhere in the first part of the address, as GMail just strips it out. 

For some reason though, it always makes me giggle, as it puts me in mind of this


 
Posted : 02/03/2026 6:16 am
Posts: 251
Free Member
 

Thanks for the replies. I had forgotten about the plus but figured that for anything that mattered the sketchy folk would know just to strip it off. I was hoping there was an easy solution to generating the kind of email addresses companies get if you log in with apple ID and say not to share your real email.


 
Posted : 02/03/2026 7:14 am
 nbt
Posts: 12469
Full Member
 

Posted by: Cougar

Google does it too, if you have (say) stwforum@gmail.com then you can use pissflaps+stwforum@gmail.com 

ALmost, it's the other way round - it's username+RANDOMBIT@gmail.com


 
Posted : 02/03/2026 8:35 am
Posts: 78218
Full Member
 

Ah, ratbags.  Thanks for the correction.

I meant to add "please look this up before using it" as I was working from memory and assuming it still works at all even.


 
Posted : 02/03/2026 9:50 am
Posts: 2068
Free Member
 

Posted by: Cougar

Ah, ratbags.  Thanks for the correction.

I meant to add "please look this up before using it" as I was working from memory and assuming it still works at all even.

Yeah it does still work 🙂 (assuming the site allows + in the address, as mentioned earlier in the thread)

 

FWIW I use a unique PW for this site and have not been notified of a breach (I'm signed up to a bunch of 'haveibeenpwned' type thingies).  BitWarden is also not reporting that the pw is compromised.

 


 
Posted : 02/03/2026 10:13 am
Posts: 78218
Full Member
 

FWIW myself,

I have no reason to believe that STW has been compromised.

I have every reason not to reuse my password from here on anything else and would urge others to do likewise (not least because it's best practice generally).


 
Posted : 02/03/2026 11:14 am
Posts: 1212
Full Member
 

Posted by: Cougar

FWIW myself,

I have no reason to believe that STW has been compromised.

I have every reason not to reuse my password from here on anything else and would urge others to do likewise (not least because it's best practice generally).

not even on Mumsnet?

 


 
Posted : 02/03/2026 11:17 am
Posts: 847
Full Member
 

I use a unique email for STW - nothing comes up for that email on Have I Been Pwned.


 
Posted : 02/03/2026 10:12 pm