Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

71–80 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#71
post #68
post #20

Earlier quoted context omitted.

10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…

WebAuthn is an UX improvement as well as a security improvement. I sympathize with your point, but in this case it’s easily sellable as the cure to the rest of your list … unless you somehow lose your key.

Not a UX improvement. Most users need a yubikey for the computer unless they have a new Mac. Asking my 65 year old dad to keep up with a yubikey is not just bad UX, it's failing UX. It simply will not happen.

I don't even think it's realistic to get him to use a smartphone for this, he hates the things.

WebAuthn works great for your Web 3.0 startup but as soon as you're talking about the average user, who is likely decades older than the commenters here, and far less interested in keeping up with these things, and far less patient with the hassles... asking them to carry hardware is a nonstarter for so many.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#72
post #20
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…

> My house's front door lock is broadly the same interface as my great-grandparent's front door lock,

It can also be defeated by any idiot with a bump key in about 10 seconds.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#76

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

The last time I tried to change the password of a reddit account I lost access to it.

I attempted to change the password, got an error saying something went wrong. I figured I'd try again later. so I also didn't save the newly generated password.

Got logged out, and couldn't log back in with the old password.

And there's no way that I know of to contact anyone at reddit to try and get help.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#79
post #74
post #37

Kind of weird posting this here. Hacker News provides little ability to manage an account, much less setup 2FA.

What's weird about posting news of a breach of a major site on a news aggregator?

Just that Hacker News doesn't provide the protections being discussed given the also discussed assumption that sites will be breached at some point.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#80
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

> And this is why we should all adopt webuathn, and get rid of totp based 2fa.

I'd be glad to personally, but if a site supports 2fa at all, then it's mostly likely TOTP. And some require TOTP first and allow webauth only in addition to it.

Post reply on HN