Due to recent events and rumors, we would like to make a statement on the subject. We have delayed this step so we could gather information and investigate thoroughly first.
To clarify the most important thing first: The personal data posted in some chats did not come from our database or from any of the services we provide. Even if a hacker could get full access to the chat server they could not even read the information, as all the information stored is encrypted.
Several users from our community could also confirm that the information was not leaked from our end. We have found that an harassing individual is posting malicious links in chats to get users into clicking them. Remember, Never click on unfamiliar links sent by unknown users! Even if it looks familiar make sure to read the link thoroughly to ensure it is not a fake copy of a known site.
Further evidence that the data does not originate from us is that the harasser has published information that we do not ask for or hold in our database, such as age, birthday, education, work and discord details.
It has also been confirmed to us that this type of harassment has occurred to users on other platforms as well. these kind of incidents are not specific to picarto and unfortunately can happen in every public social platform.
If you use paypal for donations and commissions, we recommend upgrading to paypal business. Its free and it lets you hide your name to prevent any malicious acts of getting your personal information through refund exploits. If you use Ko-fi make sure to connect your business paypal to it as well, as donating to Ko-fi can also be used to reveal your name.
Incase of DDoS attacks, if you believe your IP was compromised and you are currently subjected to a DDoS attack, we highly recommend contacting your ISP to issue you a new IP address for free.
If your personal information has been posted online, unfortunately there is not much to be done but we still recommend changing your passwords and remove as many ties and references of your identity from public services online.
Regarding our chat restrictions settings, we are currently working to improve the banning mechanism even more. We already operate with Account and IP based banning mechanism similar to other platforms, However with VPN services it is unfortunately easy to get a new IP and evade the ban. What was meant to be an important tool for privacy on the internet is unfortunately also abused here by people with bad intentions.
Currently if you are in a Multistream:
All streamers in the multistream must have the same chat restrictions active in order for them to apply globally. We will change this in the future so that only the hosts settings will apply to improve the effectiveness of chat restrictions in multistreams.
Here is what we have done so far:
Our first update regarding the chat was published two days ago. Further security measures have been added there. Furthermore the guest function has been temporarily disabled due to abuse from harassing users who use a VPN to easily evade bans with guest accounts.
Here is what you can do for now:
Enable the white list function or 14 days registered mode for your chat.
Do not click on any suspicious links.
If you are in a multistream, make sure, that everyone has the same chat restrictions you have.
If you use services like Ko-fi upgrade your paypal to paypal business and hide your info.
We are planning to take legal action against this individual, as we have collected some information. We take harassment very seriously and everyone should feel safe, no matter what website they are on.
Our focus currently is finding a solution to give you more security, but we must also ask for your patience. We monitor the situation very closely and also monitor all access to our servers 24/7. Further security precautions were taken as well.
We always do our best to provide our artists a nice place to share their creative content. We have done so in the past and will continue to do so even more in the future. The security and well being of our community is our top priority.
Apologies that you had to wait so long for this statement, and we thank you for your patience.