The other site, OH2, has had SSL certificate issues all this week. This is typically something sysadmins can briefly struggle with, so maybe it's the cause, but it's typically an 'oops I forgot that certificate' and quickly gets fixed. I'd estimate one business day even for a newbie to get this fixed, at most if there are skills and $ to fix it.
But this duration is strange....So it got me thinking of other potential causes-
1) The site has been hacked-More in a moment
2) OH2 has an inept or no sysadmin
3) No $ to buy the replacement certificate ($50+).
So #2 is unlikely, it took somebody to create the site after all and even if things went sideways with the old guy, a hire can be addressed online. #3-it's just too low of a bar to cross, they surely earn plenty of $ from ads, waaaaayyyyy way more than $50.
So #1 got me thinking-why. What do you have to gain as a hacker from a site like OH2/Eccie? Not much direct revenue, not like putting ransomware out there. You can't embed viruses/worms and effect everybody, even Google would mark Eccie as a threat. So it leads to my last conclusion, and I'm typically not this conspiracy minded: State sponsored hacking.
A brief tech background: If you visit a site with an SSL certificate (cert) the data between you and the site is encrypted, or scrambled, so an eavesdropper can't hear your conversation. If you spoke an extinct language only you and your buddy knew, it doesn't matter if an eavesdropper is there, they won't understand your dead language. This is a decent enough analogy to encryption of the site to your PC or phone.
So as it stands today, if I'm LE, I don't need a warrant to get everybody's passwords and info. I just have to break their SSL certificate, prevent it from being corrected, and then work with the Internet provider to get everybody's username, pw, and any other critical info. Most Internet providers will have a low bar and most already work with LE. Since this has been down all week, and other sites as noted in another thread, I think something else is going on that's bigger and why I wrote this novella.
If I were you I wouldn't do any interactions on OH2 or login again unless you understand that somebody can see your actions and words. Hope you have a separate username there vs. here and a unique password. I'd stay OFF of OH2 until this is fixed and even then I'm suspicious.
Be careful out there. I hope to hell I'm wrong as can be but this is pretty damn fishy by this point.