Minecraft Chick had the following to say on the matter:
Quote fromHi Guys,
We are aware of the security issues involved with the Minecraft authorization servers and are currently working to fix it.
Right now the authorization servers have been taken offline and will be down until further notice. The Mojangstas are working hard to make sure we get everything back to perfect working order.
We’ll keep you updated as we have a more clear timeline. We really are sorry about this and are working as fast as we can!
Happy Sunday
UPDATE: Authorization servers are back online, and the login exploit should no longer be possible.
It is not believed at this time that any account information - such as passwords, security info or any other sensitive information - was compromised. Players are, as in any similar situation, encouraged to change their password when the authorization servers come online, if they feel their information was compromised.
Redditor "barneygale" gave a very detailed breakdown of the process, which you can read by clicking here.
Under the circumstances this should not strictly speaking be necessary. As I understand the situation the exploit does not give them access to anything other than the account name. Password should still be secure, as they are just spoofing the username. It is still good practice to change the password often, but strictly speaking should be unnecessary this time.
But then anyone can log in as you, like in the exploit. So put up a temp world, client base stays, actual world stays safe.
This allows people with 'hacked' or 'non-paid-for' accounts to connect to smp. But when things like this happen, there are solutions....
That sort of thing happens to me regularly. Really annoying. Like the hours I wasted trying to sort out why our firewall was blocking traffic from a wireless site-to-site link, only to discover it was not the firewall but the computer I was targetting to test things was broken.... Doh!
Don't ask that sort of thing with computers. No one knows the answer.
Any answer would be a guess, and probably not a very good one. The only time they'd be able to give a close guess would be after it's fixed.
Glad this happened now though, and not a few hours later. I was able to take my server off the net - would hate to have it vandalised by some jerk.
well i hope it gets fixed
Yes. They disabled logons.
Also, good news apparently. Just spotted on xlson's Twitter that they've got it back online...
Good to hear, glad someone is keeping us updated.
Wha? I can still log on to servers with no errors...