And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.
10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…
Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
61–70 of 301 posts
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#62Earlier quoted context omitted.
10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…
> My house's front door lock is broadly the same interface as my great-grandparent's front door lock True, but your house's front door lock is very likely to offer quite poor security. Most house locks are vulnerable to bumping attacks that are almost trivial to pull off. The only reason this is acceptable is the threat model you're dealing with when securing a physical house is very different from securing an intern…
While surely nothing offers complete security, it massively increases the effort required to break in (from essentially zero).
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#63Earlier quoted context omitted.
> My house's front door lock is broadly the same interface as my great-grandparent's front door lock True, but your house's front door lock is very likely to offer quite poor security. Most house locks are vulnerable to bumping attacks that are almost trivial to pull off. The only reason this is acceptable is the threat model you're dealing with when securing a physical house is very different from securing an intern…
If someone _really_ wants in, the windows are an even weaker point. Obvious at a glance breakage probably not even necessary... (those latches seem awfully flimsy).
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#64And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#65Earlier quoted context omitted.
was it the north korean government using military level hacking technology? yes. i mean, we don't know. but probably.
"Military level" is another means-nothing term. Could be anything from average phishing or some 0-day that happened to be found by gov employee or phishing email, to "a bunch of men kidnapped target and beat them till they gave them access
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#66Edit: Reads comment by Maxburn, googles TOTP and Authy
Why the heck do I need a 3rd party involved? Ugh
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#67>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…
> treat online accounts as throwaway wherever possible I don't need to know who you actually are, but over time interacting with other people here I've started to get a feel for several hundred accounts. This makes HN more pleasant because I have some sense of what sort of person they are to talk with, and what is likely to go well or poorly. When there have been subreddits I was really into, I would start to get a s…
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#68And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.
10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#69Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#70And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.
And if you are stuck using TOTP, you can mitigate with a password manager that fills it for you only when the domain matches.