Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

21–30 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#21
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

Ideally yes, but let's not let the perfect become the enemy of good. If that's what available right now, it should still be used and recommended.

In practice in many services 2FA is about hoarding PI to target ads, not improve security. I don't buy into that.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#22
post #20
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…

I'm not sure what your point is, the recommendations improve and evolve over time.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#23

So many hacks lately, it's hard to believe that it's a coincidence ?

I don't know if you are implying that it's related to the war or something. Sadly, I am more of the belief that it's a trend. I think we will see much more of it.

It might be related to layoffs too? Maybe you're implying something :)

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#24
>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage.

What inelegant phrasing.

Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for your profile, there's no benefit to the user to have an old account with lots of karma. Just keep re-rolling with strong random passwords and you have nothing to lose.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#25
post #20
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…

That's fine, but don't be a hypocrite who comes complaining when they get hacked. It's your personal responsibility to maintain your own security.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#26
post #20
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…

This isn't really the way that advice played out:

Nobody should ever suggest you use TOTP or SMS 2fa to prevent phishing.

> 6 years ago "ok but you need to use different passwords on each site"

Really the only one that matters in practise. TOTP is basically just a work around to get users to actually do this.

Edit: i would also add this is a corporate environment where its reasonable to be more picky. And webauth really is the best (only?) Solution to phishing.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#27

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

These days it seems you should change your password (and your 2FA token) every now and then not because you are the one getting hacked but the sites you sign up at.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#28
post #17
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

Is this similar to how hardware wallets show the true addresses on their displays?

Webauth checks the http origin so it only gives the code to the correct website, taking the human out of the decision loop.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#29
post #26
post #20

Earlier quoted context omitted.

10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…

This isn't really the way that advice played out: Nobody should ever suggest you use TOTP or SMS 2fa to prevent phishing. > 6 years ago "ok but you need to use different passwords on each site" Really the only one that matters in practise. TOTP is basically just a work around to get users to actually do this. Edit: i would also add this is a corporate environment where its reasonable to be more picky. And webauth rea…

Well, if you use a compromised device temporarily and your password gets stolen and you have 2FA, it will sort of be ok once you stop using that device.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#30
post #16

Earlier quoted context omitted.

I don't know if you are implying that it's related to the war or something. Sadly, I am more of the belief that it's a trend. I think we will see much more of it.

"to the war", I smeel a singularity. Can you be more specific, to which war exactly are you refering to? https://en.wikipedia.org/wiki/List_of_ongoing_armed_conflict...

I suppose you're trying to make a point about the relative attention devoted to Ukraine vs other conflicts, but in this case there really is only one war with large state actors who have the motive and cyberwarfare ability for mass hacking campaigns.
Post reply on HN