Selfhosted - Briefkastenhq Demo seems to be compromised #4561

Closed
opened 2025-11-26 21:04:56 -06:00 by GiteaMirror · 2 comments
Owner

Originally created by @Tomat0r on GitHub (Sep 20, 2022).

https://briefkastenhq.com/

logged in with Google. It resulted in instant change of ownership of my Steamaccount etc... Google flagged it as insecure.

Originally created by @Tomat0r on GitHub (Sep 20, 2022). https://briefkastenhq.com/ logged in with Google. It resulted in instant change of ownership of my Steamaccount etc... Google flagged it as insecure.
GiteaMirror added the fixinvalid labels 2025-11-26 21:04:56 -06:00
Author
Owner

@Ki-er commented on GitHub (Sep 20, 2022):

Id recommend you make an issue on their GitHub, there hasn't been any other reports of it and the software is maintained, we can remove the link in #3302 until this is confirmed though!

@Ki-er commented on GitHub (Sep 20, 2022): Id recommend you make an issue on their GitHub, there hasn't been any other reports of it and the software is maintained, we can remove the link in #3302 until this is confirmed though!
Author
Owner

@nodiscc commented on GitHub (Sep 20, 2022):

https://github.com/ndom91/briefkasten/issues/17

Google flagged it as harmful, it Got my Steam account hacked.
Has to originate from this since it started right after.

No credible proof that these 2 events are linked... are you sure it's not rather linked to this? It happened on the same day...

Edit: Moreover there is very little information shared between Google/Briefkasten when using the oauth login (To continue, Google will share your name, email address, language preferences and profile picture with briefkastenhq.com). And I fail to see how this would be related to a compromised steam account.

Edit2: https://github.com/Lissy93/personal-security-checklist 👌

Please reopen if you have further information.

@nodiscc commented on GitHub (Sep 20, 2022): https://github.com/ndom91/briefkasten/issues/17 > Google flagged it as harmful, it Got my Steam account hacked. > Has to originate from this since it started right after. No credible proof that these 2 events are linked... are you sure it's not rather linked to [this](https://www.theguardian.com/world/2022/sep/17/india-reintroduces-cheetahs-to-wild-after-big-cats-airlifted-from-namibia)? It happened on the same day... Edit: Moreover there is very little information shared between Google/Briefkasten when using the oauth login (_To continue, Google will share your name, email address, language preferences and profile picture with briefkastenhq.com_). And I fail to see how this would be related to a compromised steam account. Edit2: https://github.com/Lissy93/personal-security-checklist :ok_hand: Please reopen if you have further information.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/awesome-selfhosted#4561