We're doing some tough client love right now on security practices, and having a nice hard wall to push off of, namely, Dreamhost being assholes, in a good way, would be a very Good Thing[tm].
As it was I found out about 4 hours after your first blog post via HN.
We're still hashing out what we're going to do with folks who, last time we instituted a password/process change, wanted a 3-weeks heads-up.
FML.
The DreamHost engineer who's been commenting here says the web panel passwords haven't been compromised (I changed ours anyhow).
Or do I need to go through all 20 right this moment and change them from their old value to a new value?
Basically do the hackers possibly have access to my ftp accounts or have you already switched my passwords to random strings?
I won't be the only person doing this.
Also, the fact that you can see your user passwords in the panel has always irked me, and that has gone unchanged even after past breaches. I have been quite happy with their service, but maybe this my queue to leave... :(
EDIT: To their credit, I see this when logging in to the panel: "Due to some unauthorized activity we detected within one of our databases, we have forced a reset of all FTP/SFTP and shell passwords as a precaution."