Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

51–60 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#51
post #20
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…

You are talking about the average developer.

Most regular users never moved beyond using 'P@55word!' everywhere.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#52
post #31
post #3

Earlier quoted context omitted.

>On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens. It doesn't seem to me that much sophisticated, rather "normal", unless they are…

Its sophisticated in the sense it sounds targeted. They had to do research, setup a clone of an internal site, etc. That's on the high end of sophistication for phishing, which in general is usually not the most sophisticated of attacks.

Yep, but targeted doesn't have the same meaning as sophisticated, maybe the sophistication relates to obtaining a list of reddit employees, in that sense the sophistication is before and besides the phishing in itself.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#53
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

And if you are stuck using TOTP, you can mitigate with a password manager that fills it for you only when the domain matches.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#54
post #47

Earlier quoted context omitted.

Every company describes successful breaches as "sophisticated," because if it wasn't sophisticated then it's their own failure.

was it the north korean government using military level hacking technology? yes. i mean, we don't know. but probably.

"Military level" is another means-nothing term.

Could be anything from average phishing or some 0-day that happened to be found by gov employee or phishing email, to "a bunch of men kidnapped target and beat them till they gave them access

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#56

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

We're in a crisis of trust. "You have nothing to lose" is wrong. You and the community both have something to lose if identity is not valued. A throwaway is indistinct from a bot paid for by some rich mustache-twirling billionaire or state actor trying to control narrative.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#57
post #50

Earlier quoted context omitted.

That's a good idea and I've thought about it but I think many feel attached to their usernames and account history "15 yeas with.." site X. And sites often balk and say "username or email already has an account here". It's a bit funny since alias was meant to hide who you were or at least make ire less formal than a person's full name. Then I go and use my name for an alias!

The "don't use your real name on the internet" advice wasn't great. When I set up a Google account as a kid I used a made up handle because all the adults told me to not use my name on the internet. Decades later and it's still my main account and I often need to either switch accounts to the one with my real name or embarassingly ask people to invite my nickname account to various shared documents, calendars, etc. N…

What's embarrassing about a nickname?

Having a disconnected online entity means less-than-pleasant jackasses can't pull something from years or even decades ago, put it out of context, and proceed to troll your life.

Not putting your real life identity on public display for the world to see means you maintain tighter control over how, when, and where your information gets out. Do you really need your real name, face, place of employment, telephone number, email address (with your name in it), and maybe even your home address publicized? More than likely you don't.

Having online identities disconnected from real life means you can use them to safeguard your actually really-fucking-important real life things. Your bank account? Use an email that uses a nickname instead of your real name so any would be hackers have to second guess your email too.

Worst comes to shove and shit hits the fan, you can throw away an online identity and make another one. You can't throw away your real name and face.

There are nothing but benefits by keeping your online and real life identities separate, and if you ask me it's one of the first steps to being truly internet literate.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#58

So many hacks lately, it's hard to believe that it's a coincidence ?

This hack was very sophisticated and targeted ("plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway") but wasn't after the easily monetizable stuff (user emails, which in combination with their most used subreddits would be very valuable for targeted spam), but instead went for data on employees and business partners. This sure seems like a setup for attacking a more valuable target.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#59
>Reddit also stated that there was no evidence the systems used to run Reddit itself and store the majority of data, the primary production systems in other words, was breached.

Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss".

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#60
post #20
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…

Yeah, security is a cat and mouse game. You need to keep adapting.
Post reply on HN