A reminder to use strong passwords

We encourage all users to ensure they use a strong password with 12+ (20+ being better) RANDOMIZED characters, preferably stored using a password manager and ensuring that you DO NOT use the same password at multiple sites.

Yesterday many torrent trackers were hit by a credential stuffing attack. This means that malicious people out on the internet are aiming thousands of computers in our direction and guessing users passwords one guess after another, thousands of times per second. When a successful login is found on one tracker, they attempt the same username and password on many other torrent trackers. We are taking steps to minimize and rate-limit this type of attack. However, users should NEVER use the same password across multiple trackers for this reason.

Having a long RANDOMIZED password significantly mitigates the risk of the account being compromised by brute force or dictionary methods.

(Cross post from Blutopia.cc)