We're not quite done investigating the issue and resetting passwords; once that's done, though, we will have a mass email going out.
I won't be the only person doing this.
Or do I need to go through all 20 right this moment and change them from their old value to a new value?
Basically do the hackers possibly have access to my ftp accounts or have you already switched my passwords to random strings?
As it was I found out about 4 hours after your first blog post via HN.
We're still hashing out what we're going to do with folks who, last time we instituted a password/process change, wanted a 3-weeks heads-up.
FML.
The DreamHost engineer who's been commenting here says the web panel passwords haven't been compromised (I changed ours anyhow).