Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

41–50 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#41

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

That's a good idea and I've thought about it but I think many feel attached to their usernames and account history "15 yeas with.." site X. And sites often balk and say "username or email already has an account here".

It's a bit funny since alias was meant to hide who you were or at least make ire less formal than a person's full name. Then I go and use my name for an alias!

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#42
post #20
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…

For applications where it really mattered, harware authenticators have long been established. Big companies use smart cards, and my bank has always offered the choice between the 2FA-du-jour (switching from pre-distributed TAN lists to SMS 2FA to various iterations of 2FA apps, currently push tan) or just getting a $20 reader for my existing bank card (which has a chip since forever in europe).

The list you are describing could as well be seen as every service trying to implement the simplest and least disruptive technology, only to find out two years later that it was insufficient and switching to the next best thing, only for the cycle to repeat each time.

Which of course from the users perspective doesn't make a difference, but it gives a different perspective on how to solve it for the future.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#43

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

Just FYI while they suggest updating passwords they also claim that user accounts are safe at this time.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#44
post #3
post #2

https://old.reddit.com/r/reddit/comments/10y427y/we_had_a_se...

>On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens. It doesn't seem to me that much sophisticated, rather "normal", unless they are…

The "sophisticated" term maybe (100% for sure) was meant to save face. As in reddit staff should have known better and were supposed to be IT, social media, Internet culture experts. But fell for it anyway.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#45

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

>there's no benefit to the user to have an old account with lots of karma

Some subs have a minimum amount age or karma requirement to post. This is ostensibly to combat bots.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#46
post #20
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…

The Egyptians has wooden door lock mechanisms. It took thousands of years to develop modern door locks. We went from lever tumbler locks in 1778 to the modern Yale lock in 1861 (which fundamentally still operates on similar principles to the Egyptian wooden pin lock).

I'm sure authentication technology will settle down in a decade or two.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#47
post #3

Earlier quoted context omitted.

>On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens. It doesn't seem to me that much sophisticated, rather "normal", unless they are…

Every company describes successful breaches as "sophisticated," because if it wasn't sophisticated then it's their own failure.

was it the north korean government using military level hacking technology? yes. i mean, we don't know. but probably.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#48
post #38

The setup 2FA advice is kind of weird. I mean its fine in general, but it was an employee who was breached not a user, and there is no indication that the attackers got account data.

And apparently the phishing attack phished both password and 2FA for getting into the intranet. So whatever 2FA they used internally didn't help.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#49

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

> treat online accounts as throwaway wherever possible

I don't need to know who you actually are, but over time interacting with other people here I've started to get a feel for several hundred accounts. This makes HN more pleasant because I have some sense of what sort of person they are to talk with, and what is likely to go well or poorly. When there have been subreddits I was really into, I would start to get a sense for the more prolific commenters there too.

If I regularly attended some sort of social club and it was common for people to replace their faces I would find it frustrating as well.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#50

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

That's a good idea and I've thought about it but I think many feel attached to their usernames and account history "15 yeas with.." site X. And sites often balk and say "username or email already has an account here". It's a bit funny since alias was meant to hide who you were or at least make ire less formal than a person's full name. Then I go and use my name for an alias!

The "don't use your real name on the internet" advice wasn't great. When I set up a Google account as a kid I used a made up handle because all the adults told me to not use my name on the internet.

Decades later and it's still my main account and I often need to either switch accounts to the one with my real name or embarassingly ask people to invite my nickname account to various shared documents, calendars, etc. No way to migrate my YouTube channel either…

Post reply on HN