On the afternoon of April 14th, a hacker using a UK IP address exploited an out-of-date software package on one of 4chan's servers, via a bogus PDF upload. With this entry point, they were eventually able to gain access to one of 4chan's servers, including database access and access to our own administrative dashboard. The hacker spent several hours exfiltrating database tables and much of 4chan's source code. When they had finished downloading what they wanted, they began to vandalize 4chan at which point moderators became aware and 4chan's servers were halted, preventing further access.
Over the following days, 4chan's development team surveyed the damage, which to be frank, was catastrophic. While not all of our servers were breached, the most important one was, and it was due to simply not updating old operating systems and code in a timely fashion. Ultimately this problem was caused by having insufficient skilled man-hours available to update our code and infrastructure, and being starved of money for years by advertisers, payment providers, and service providers who had succumbed to external pressure campaigns.
We had begun a process of speccing new servers in late 2023. As many have suspected, until that time 4chan had been running on a set of servers purchased second-hand by moot a few weeks before his final Q&A, as prior to then we simply were not in a financial position to consider such a large purchase. Advertisers and payment providers willing to work with 4chan are rare, and are quickly pressured by activists into cancelling their services. Putting together the money for new equipment took nearly a decade.
In April of 2024 we had agreed on specs and began looking for possible suppliers. Money is always tight for us, and few companies were willing to sell us servers, so actually buying the hardware wasn’t a trivial problem. We managed to finalize a purchase in June, and had the new servers racked and online in July. Over the next few months we slowly moved functionality onto the new servers, but we had still been relying on the old servers for key functions. Everything about this process took much longer than intended, which is a recurring theme in this debacle. The free time that 4chan's development team had available to dedicate to 4chan was insufficient to update our software and infrastructure fast enough, and our luck ran out.
However, we have not been idle during our nearly two weeks of downtime. The server that was breached has been replaced, with the operating system and code updated to the latest versions. PDF uploads have been temporarily disabled on those boards that supported them, but they will be back in the near future. One slow but much beloved board, /f/ - Flash, will not be returning however, as there is no realistic way to prevent similar exploits using .swf files. We are bringing on additional volunteer developers to help keep up with the workload, and our team of volunteer janitors & moderators remains united despite the grievous violations some have suffered to their personal privacy.
/his/ was born.
Homepage image changed a bit on Nov 5th.
Happy 12th anniversary!
4chan is now owned and led by Hiroyuki Nishimura, the founder of the largest anonymous BBS in Japan, 2channel. Read the full announcement on the 4chan News page.
I'm retiring after serving as 4chan's founder and administrator for more than 11 years, from the age of 15. You can read the full announcement on the 4chan News page.
—moot
Recently we introduced a new requirement for 4chan's volunteer moderators and janitors, which is that they sign a volunteer agreement that puts in writing a number of things that have always been true, namely that:
In addition to signing this formal agreement, we now require proof of identity from all volunteers, present and future. Why? So we can enforce the agreement should it be violated (ie. user information being misused, leaks, etc) and establish a liability barrier in between the company and its volunteers.
Most large websites with analogous volunteer roles use similar agreements, and we were long overdue for one of our own. You can find a full copy of the agreement below (note this will be mandatory as of our next janitor drive):
As many of you know, last week we upgraded to the new reCAPTCHA API, bringing CAPTCHA-less posting to the masses >for free. Since the upgrade, approximately 25-30% of daily solve attempts encounter no CAPTCHA at all, with failure rates hovering at an all-time low of 6%.
Alongside the new CAPTCHA, we temporarily disabled the sale of 4chan Passes as we evaluated whether or not to continue supporting them in light of the change. Ultimately, we decided to resume offering 4chan Passes for sale for those who don't want to deal with CAPTCHA at all, would like to post from behind a blocked IP range, or just plain want to support the site.
We've also decided to offer a limited time, pro-rated refund to those who currently hold an active 4chan Pass that was purchased on or before December 8th, 2014. While we don't normally offer refunds for Pass purchases, we felt it was best to provide an opportunity for users who feel their Pass has been devalued as a result of the CAPTCHA change to request a pro-rated refund.
Since 4chan relies primarily on Pass sales to make ends meet, we'll continue to sell and support them for the foreseeable future, and may consider adding additional features at a later date and time (ideas welcome).
If you'd like to submit a refund request for your active 4chan Pass that was purchased on or before December 8th, please visit this link and follow the instructions.
Two days ago, we upgraded to the new reCAPTCHA API, dubbed the "No CAPTCHA reCAPTCHA".
The new API allows users determined to not be spambots to bypass typing a verification, giving them a CAPTCHA-less posting experience. Below you can see the change from our last full day using the old version of the API to our first full day using the new version:
The mobile site has received a slew of updates recently, including:
Three new features, and a belated announcement:
—moot
Today we're making two noteworthy changes:
—moot
Today we're pleased to announce support for IPv6 on all of 4chan's domains, thanks to CloudFlare's new Pseudo IPv4 feature.
CloudFlare's CEO, Matthew Prince, goes into more detail on their blog, but essentially they'll accept traffic from our users over IPv6-enabled networks and route the request to our backend using plain ol' IPv4. This removes the need for our application to be updated to natively support IPv6 (something we're working on, but is a ways off).
Since IPv6's address space is considerably larger than IPv4, the mapping of IPs won't be one-to-one, however they believe it's large enough to accommodate the transition period between now and applications having true IPv6 support.
If you're using an IPv6-enabled network you may see a slight performance benefit should your ISP have better routes to CloudFlare's datacenters that way.
Update: This change was reverted due to issues with our ban system, however our static content hosted at 4cdn.org is still accessible via IPv6 networks.
In response to last month's intrusion, we've put numerous additional security measures in place in an effort to mitigate and prevent future intrusions.
We're also pleased to announce the creation of 4chan's Vulnerability Disclosure Program—commonly known as a "bug bounty."
We hope that by providing an officially sanctioned way for security researchers to submit security-related bugs, we'll be in a better position to detect and respond to vulnerabilities that may impact the site and its users.
Security remains an ongoing priority and commitment of ours. Thanks again for bearing with us, and sorry to anyone we've let down.
—moot
Last week we were made aware of a software vulnerability that allowed an intruder access to administrative functions and information from one of our databases. The intruder later stated their motive was to expose the posting habits of a specific user they disliked.
After careful review, we believe the intrusion was limited to imageboard moderation panels, our reports queue, and some tables in our backend database. Due to the way the intruder extracted information from the database, we have detailed logs of what was accessed. The logs indicate that primarily moderator account names and credentials were targeted.
Three 4chan Pass users had their Pass credentials accessed, and were notified and offered refunds and lifetime Passes shortly after the discovery. As a reminder, all payment information is processed securely by Stripe—we never see nor store any of it, and thus no payment information was compromised.
We patched the vulnerability quickly after it came to our attention, and have spent—and will continue to spend—dozens of hours poring over our software and systems to help mitigate and prevent future intrusions.
We're sorry it happened, and will do our best to ensure it doesn't happen again.
In the coming week, we'll be making a few changes to how files are accessed. The changes are mostly cosmetic, and will be transparent to people using vanilla 4chan. We'll also continue to support legacy URLs for a short time to give third-party developers the opportunity to migrate their apps, but suggest making the appropriate updates as soon as possible to be prepared for when the changes go live.
The 4chan API documentation will be updated shortly before the changes go live.
Yesterday we welcomed two old features back to the site—the 4chan Blog and Blotter—but today we'll also say goodbye to a few.
Over the past 10 years, 4chan has accumulated many features and side-projects, but since the team has rarely consisted of more than myself, a single volunteer developer, and a handful of volunteer moderators, many have been neglected. Specifically the discussion boards (dis.4chan.org) and Fileshares board (rs.4chan.org).
Rather than continue to neglect these side-projects, we've decided to retire them so that we can focus our time and energy into maintaining and improving the core of the site—4chan's image boards.
The discussion boards will continue to live on in a read-only state, while the Fileshares board will be shut down. Both will be frozen and de-linked soon.
For the VIPPERs and ``expert programmers'' among us this may be a sad day, however we hope to accommodate you with some future image board features. Stay tuned.
Today we added support for WebM files on 4chan's image boards.
While WebM is technically a video file format, it offers many advantages over animated GIFs—namely superior image quality, support for more than 256 colors, and reduced file size. Its main disadvantage is browser compatibility, however 86% of 4chan's visits come from browsers that include full or partial support for WebM, and plug-ins are available for those that don't (like Internet Explorer and Safari).
We decided to disallow WebM files with sound for a few reasons, but mainly because it's our intention to provide the site with better animated images, and not true video support. To that end, we only accept WebM files with one video stream and no audio streams, that are shorter than 120 seconds long, no larger than 2048x2048 pixels, and less than 3 MB in size.
We're eager to see how 4chan's users will adopt WebM, and have posted this short guide on encoding them to ease adoption. Many thanks to desuwa for both championing and implementing this feature.
—moot
Long-time users will remember the late 4chan DevBlog and Blotter, which were removed almost five years ago due to infrequent use. We had used them to share updates with the community that didn't require lengthy news posts.
Today I'm pleased to reintroduce both. As someone who hates writing and prefers to publish news posts only when absolutely necessary, I welcome their return. We'll continue to use the global message (big red text at the top of boards) to communicate important notices, but will use the blog and blotter to share a running tally of smaller updates.
You may not realize it, but we're constantly working behind the scenes to improve the site—be it feature additions, code tweaks, or improving moderation. It's our hope to give the community more visibility into those improvements via a changelog of sorts.
So give us a follow or subscribe via RSS, and keep an eye on the blotter.
—moot