Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

31–40 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#31
post #3
post #2

https://old.reddit.com/r/reddit/comments/10y427y/we_had_a_se...

>On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens. It doesn't seem to me that much sophisticated, rather "normal", unless they are…

Its sophisticated in the sense it sounds targeted. They had to do research, setup a clone of an internal site, etc. That's on the high end of sophistication for phishing, which in general is usually not the most sophisticated of attacks.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#32
post #20
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…

> My house's front door lock is broadly the same interface as my great-grandparent's front door lock

True, but your house's front door lock is very likely to offer quite poor security. Most house locks are vulnerable to bumping attacks that are almost trivial to pull off. The only reason this is acceptable is the threat model you're dealing with when securing a physical house is very different from securing an internet-connected computer.

Moreover, while the threats against your front door have remained marginally the same as those against your great-grandparent's door, computers and the network they are operating in change extremely frequently. All the security recommendations you're naming were quite reasonable for their time but rapidly became outdated.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#33
post #16

Earlier quoted context omitted.

I don't know if you are implying that it's related to the war or something. Sadly, I am more of the belief that it's a trend. I think we will see much more of it.

"to the war", I smeel a singularity. Can you be more specific, to which war exactly are you refering to? https://en.wikipedia.org/wiki/List_of_ongoing_armed_conflict...

Parent is pretty obviously referring to the 2022 Russian invasion of Ukraine, the single biggest (regarding media coverage) armed conflict right now.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#34

So many hacks lately, it's hard to believe that it's a coincidence ?

You've been downvoted, but of course it's reasonable to think 'not a coincidence'. But I'd actually say that it's not a particularly interesting observation given how many nation state backed intelligence (or even crime, assuming a difference) groups there are that do frequently hack large companies and government agencies. The pertinent thing here is that we simply don't know, and there are also plenty of boring criminal groups that also hack.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#35
post #29
post #26

Earlier quoted context omitted.

This isn't really the way that advice played out: Nobody should ever suggest you use TOTP or SMS 2fa to prevent phishing. > 6 years ago "ok but you need to use different passwords on each site" Really the only one that matters in practise. TOTP is basically just a work around to get users to actually do this. Edit: i would also add this is a corporate environment where its reasonable to be more picky. And webauth rea…

Well, if you use a compromised device temporarily and your password gets stolen and you have 2FA, it will sort of be ok once you stop using that device.

Depends how long your session cookie lasts for the site. Some high security sites are paranoid, but most of the time they last for like a year.

It also depends on how sophisticated the attacker is. Do they fake log you out so they could capture a second 2fa token in order to change the totp token to a new device and change your email?

And of course, for the most part damage can usually be done in minutes - copying confidential files does not need long term access.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#36
post #20
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…

Ten years ago, everyone got hacked all the time. Today, basically the only way to get you hacked is to hack the actual site you're using. I'd say that's progress.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#39
post #20

Earlier quoted context omitted.

10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…

> My house's front door lock is broadly the same interface as my great-grandparent's front door lock True, but your house's front door lock is very likely to offer quite poor security. Most house locks are vulnerable to bumping attacks that are almost trivial to pull off. The only reason this is acceptable is the threat model you're dealing with when securing a physical house is very different from securing an intern…

If someone _really_ wants in, the windows are an even weaker point. Obvious at a glance breakage probably not even necessary... (those latches seem awfully flimsy).

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#40
post #3
post #2

https://old.reddit.com/r/reddit/comments/10y427y/we_had_a_se...

>On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens. It doesn't seem to me that much sophisticated, rather "normal", unless they are…

If any e-mail contains a link to a login webpage, I treat it as a Phishing attempt. Only ever log in on the page you have bookmarked.
Post reply on HN