Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

11–20 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#15
post #3
post #2

https://old.reddit.com/r/reddit/comments/10y427y/we_had_a_se...

>On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens. It doesn't seem to me that much sophisticated, rather "normal", unless they are…

"One of our employees was tricked. The attack must have been sophisticated, because we are a cool gang."

Basically applies to every team there is.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#16

So many hacks lately, it's hard to believe that it's a coincidence ?

I don't know if you are implying that it's related to the war or something. Sadly, I am more of the belief that it's a trend. I think we will see much more of it.

"to the war", I smeel a singularity. Can you be more specific, to which war exactly are you refering to?

https://en.wikipedia.org/wiki/List_of_ongoing_armed_conflict...

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#17
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

Is this similar to how hardware wallets show the true addresses on their displays?

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#18
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

Ideally yes, but let's not let the perfect become the enemy of good. If that's what available right now, it should still be used and recommended.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#19
post #17
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

Is this similar to how hardware wallets show the true addresses on their displays?

It's very vaguely similar to TLS connections with mutual authentication, you can't normally MITM/proxy it.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#20
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

10 years ago "use a strong password with all these symbols"

Average person reluctantly moves from 123456 to P@55word!

8 years ago "no passwords such, use a pass phrase"

Average person reluctantly moves from P@55word! to correct-horse-battery-staple

6 years ago "ok but you need to use different passwords on each site"

Average person reluctantly moves to different passwords per site

4 years ago "but you can be phished, you have to use 2FA"

Average person reluctantly moves to SMS

2 years ago "no in some countries it's easy to take over SMS, use TOTP"

Average person reluctantly moves to TOTP

Today "no TOTP is rubbish, you can be phished, use this hardware authenticator"

Normal people don't like new shiny ways of working every year or so. My house's front door lock is broadly the same interface as my great-grandparent's front door lock, but technologists think changing the way things work every couple of years is acceptable.

Post reply on HN