https://old.reddit.com/r/reddit/comments/10y427y/we_had_a_se...
>On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens. It doesn't seem to me that much sophisticated, rather "normal", unless they are…
Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
31–40 of 301 posts
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#32And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.
10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…
True, but your house's front door lock is very likely to offer quite poor security. Most house locks are vulnerable to bumping attacks that are almost trivial to pull off. The only reason this is acceptable is the threat model you're dealing with when securing a physical house is very different from securing an internet-connected computer.
Moreover, while the threats against your front door have remained marginally the same as those against your great-grandparent's door, computers and the network they are operating in change extremely frequently. All the security recommendations you're naming were quite reasonable for their time but rapidly became outdated.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#33Earlier quoted context omitted.
I don't know if you are implying that it's related to the war or something. Sadly, I am more of the belief that it's a trend. I think we will see much more of it.
"to the war", I smeel a singularity. Can you be more specific, to which war exactly are you refering to? https://en.wikipedia.org/wiki/List_of_ongoing_armed_conflict...
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#34So many hacks lately, it's hard to believe that it's a coincidence ?
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#35Earlier quoted context omitted.
This isn't really the way that advice played out: Nobody should ever suggest you use TOTP or SMS 2fa to prevent phishing. > 6 years ago "ok but you need to use different passwords on each site" Really the only one that matters in practise. TOTP is basically just a work around to get users to actually do this. Edit: i would also add this is a corporate environment where its reasonable to be more picky. And webauth rea…
Well, if you use a compromised device temporarily and your password gets stolen and you have 2FA, it will sort of be ok once you stop using that device.
It also depends on how sophisticated the attacker is. Do they fake log you out so they could capture a second 2fa token in order to change the totp token to a new device and change your email?
And of course, for the most part damage can usually be done in minutes - copying confidential files does not need long term access.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#36And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.
10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#37Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#38Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#39Earlier quoted context omitted.
10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…
> My house's front door lock is broadly the same interface as my great-grandparent's front door lock True, but your house's front door lock is very likely to offer quite poor security. Most house locks are vulnerable to bumping attacks that are almost trivial to pull off. The only reason this is acceptable is the threat model you're dealing with when securing a physical house is very different from securing an intern…
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#40https://old.reddit.com/r/reddit/comments/10y427y/we_had_a_se...
>On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens. It doesn't seem to me that much sophisticated, rather "normal", unless they are…