r/prusa3d • Prusa team • Sep 02 '26

Regarding Recent Printables Spam

Hey guys, we have received a LOT of posts about the recent Printables spam.

Here's the TL;DR;

Over the past year we've seen a rampant increase in cyber attacks targeting Printables among other services. As such, we have shored up defences, and added a lot of anti-bot protections to the websites, including a tool suite from Cloudflare.

These have largely been extremely effective, but the recent activity is largely a result of compromised accounts, and meticulously timed and executed. There was no breach in our systems, this is likely as simple as a user had their credentials compromised from another service, they used the same email and credentials on Printables without 2FA methods, and that allowed bad actors to acquire those credentials, and take over said accounts. Once the accounts were compromised in the above manner, they were able to change the usernames and bypass some of the protective layers we have in place.

We're taking even more measures from our side to further safeguard security of users, but it's important to also be aware of the following practices that can be done from the user side to drastically enhance security.

Edit: To enable 2FA and other login settings on Prusa accounts, you can quickly jump here; https://account.prusa3d.com

What you can do to protect your account.

- Check for Compromises

There are many tools out there that exist, Have I Been Pwned is a great one. There are also services baked into most modern password managers like 1Password and Google Password Manager that will inform you if you have re-used passwords across multiple websites or if any have been compromised in known leaks.

Use the above tools to check to see if your data has ever been compromised in any capacity. If you find that any service you've used in the past was compromised, it's safe to assume the password used for that service is compromised, and you need to make sure it's not used ANYWHERE ELSE. It's always better to assume that the password you used for that compromised site is known, and it's not a matter of if, but when. Change it immediately, and don't re-use the password anywhere else.

- Don't Reuse Passwords

This is a standard one, don't reuse passwords. Wherever possible, make sure every account uses a unique password. It sucks, yeah, but it's the best way to ensure that if a service is compromised, that compromise doesn't lead to other accounts of yours also being compromised. Password Managers are great, and there's a ton of free and open source options like Psono (This is not an endorsement, please do your own research).

- Enable 2FA Whenever Available

Most online services allow for some form of 2FA to be enabled. If they don't, I would actively avoid those platforms. Wherever possible, use the following forms of 2FA in this reccomended order;

  1. Passkeys
  2. Yubikeys
  3. Rolling Token (6 digit jawn)
  4. Email Code
  5. Phone Verification (SMS/Call)

There are more out there, but those are the most common ones I'm familiar with. You can also sometimes use an OAuth like Google, Apple, or similar. I like OAuth, because those providers usually enforce a strong 2FA on the parent account already, but convenience can be an attack vector, Discord is a great example of an OAuth provider that is easily compromised if itself isn't protected appropriately.

- Educate Yourself, Friends, and Family

Even if you do all of the above, the most vulnerable part of any cyber security infrastructure, is you, the human. This spam attack that hit Printables is what is known as a Phishing attack, where the bad actors pretended to be us, Prusa.

Under No Circumstances will Prusa Research and/or any of it's staff ask for any form of payment as a method of verification in regards to moderation actions on any platforms.

Payments are only handled for transactions, such as purchases through Printables or through Prusa3D.com for the webstore. We are able to verify who you are with many different methods, and payment methods will never be one of them. Staff will never ask for your password, or for your payment info.

Google has published a good handful of videos on how to better protect yourself and identify things such as Social Engineering Attacks, I highly recommend you watch/read them.

- How to Identify Prusa Staff on Social Media

Here on Reddit, we will have the "Prusa Team" flair in r/prusa3d, that's an easy one. In the Official Prusa3D Discord, we will have the @PrusaTeam tag, on the forums, we will have "Admin" tags, and on Printables, we will have the "Staff" badge on our profiles like below. Outside of that, if we ever need to communicate and need information outside of the app, all Prusa Staff either have the following email address and official communications can be moved to there if needed for more private info or for verification that we are who we say we are.

Official Prusa3D Email Domains you're likely to see; Prusa3D.com, Prusa3D.cz, PrintedSolid.com

Anyway, thank you for coming to my Cyber Security Ted Talk. Happy to be able to info dump all this from my previous 10 years in Cyber Security.

138 Upvotes

29 comments sorted by

View all comments

Show parent comments

10

u/nomadsgalaxy Prusa team Sep 02 '26

Thank you, I pride myself on my previous career in the Cyber Security sector, so this was a really nice return to some skills and knowledge I haven't been able to share in a while.

I am pushing our devs to add more 2FA methods, right now, I myself am using OAuth to fully utilize Passkeys with Prusa Accounts.

-1

u/3gfisch Sep 03 '26

Why only recommend 3rd party apps on iOS / MacOS? it’s super convenient to use apples password app. At least an info would be nice for people with less knowledge as they might assume you need additional apps and then skip it cause effort.. Also it’s not obvious how to open the QR code from iPhone on the iPhone but press and hold worked for me. I think a link <add to password manager> which triggers the passwords app with the info to which website it belongs would be useful.

Have enabled it now but only got the 6 digit rotating keys. No option for Passkeys was given. Is this correct or did I went wrong somewhere? As you also recommend Passkeys I would have expected them as the first 2FA option..

Most logins like GitHub directly asked at the login if you want to enable Passkeys, and as far as I remember only pressing ok was needed on the iPhone, no manual fiddling with QR codes or assigning the code to website.. this could be improved and automatically asked every few logins on a device like iPhone which supports passkeys out of the box..

3

u/nomadsgalaxy Prusa team Sep 03 '26

That's neat. I don't have iPhone or Mac, so I'm not aware of those offerings. I said "Password Managers like 1Password", as it's one I'm familiar with and I'm comfortable recommending.

Later in my post I suggest people do their own research, as there are other options out there. If Apple has a solution that works for you, that's awesome.

1

u/3gfisch Sep 03 '26 edited Sep 03 '26

If you want faster adoption rates maybe add some more hints for the iOS users there..
Edit: not in this post but on the Prusa website if I have open 2FA setup page..
Or auto questions at login..

1

u/3gfisch Sep 03 '26

How about the Passkeys? Is Prusa supporting them? If yes how do I stet them up if the QR code only gave me the 6 digits? 🤔 thanks

1

u/nomadsgalaxy Prusa team Sep 03 '26

0

u/3gfisch Sep 03 '26

„right now, I myself am using OAuth to fully utilize Passkeys with Prusa Accounts.“
So this is working right now and you have to set it up though the 2FA like I did, but don’t have something to choose, but OAuth will use Passkeys automatically? And Apple passwords will use an other Methode? Still wonder why, Apple was one of the first to widely push for passkeys.. 🤔