Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

91–100 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#91

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

> there's no benefit to the user to have an old account

I used to think so until I decided to reroll my old account into a new one, and it was such a pain re-subscribing to all my subreddits again.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#92
post #38

The setup 2FA advice is kind of weird. I mean its fine in general, but it was an employee who was breached not a user, and there is no indication that the attackers got account data.

And apparently the phishing attack phished both password and 2FA for getting into the intranet. So whatever 2FA they used internally didn't help.

Yeah, but every crisis is an opportunity and this is an opportunity to scare people into coughing up PII that advertisers love so much.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#93
post #59

>Reddit also stated that there was no evidence the systems used to run Reddit itself and store the majority of data, the primary production systems in other words, was breached. Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss".

>Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss".

After what lastpass did I cannot trust any self reporting.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#94
post #63
post #39

Earlier quoted context omitted.

If someone _really_ wants in, the windows are an even weaker point. Obvious at a glance breakage probably not even necessary... (those latches seem awfully flimsy).

A similar argument I have with my wife: She insists on only living in gated communities. I'm like, "it's just a PVC pipe that goes up and down, it's not fort knox." But for some reason that gives her peace of mind, and worth the HOA fee of $350/mo.

My God. My condo complex is responsible for all external maintenance. It has steel gates that would stop an f150. They handle water, gas and trash pickup and it only costs $230/mo. It's in a fairly pricey area. I feel like you're getting robbed.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#95
post #91

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

> there's no benefit to the user to have an old account I used to think so until I decided to reroll my old account into a new one, and it was such a pain re-subscribing to all my subreddits again.

That seems like a solvable thing with a 3rd party app/script.

I reroll every time I am banned from a sub I like because that sub notices I play in other subs - that whole “thing” is horseshit to me. So I just reroll to get around that autoban bot.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#96

I'm not giving reddit my phone number, I get enough junk calls as it is. Edit: Reads comment by Maxburn, googles TOTP and Authy Why the heck do I need a 3rd party involved? Ugh

You're welcome to calculate the code yourself by hand!

Those apps keep track of it for you, you can use any 2FA app that supports TOTP. You could even make your own if you want.

https://en.wikipedia.org/wiki/Time-based_one-time_password

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#97
post #3

Earlier quoted context omitted.

>On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens. It doesn't seem to me that much sophisticated, rather "normal", unless they are…

If any e-mail contains a link to a login webpage, I treat it as a Phishing attempt. Only ever log in on the page you have bookmarked.

That's easier in your private life than in business. A lot of common tools (especially jira, confluence, etc.) have the flimsiest sessions along with just atrocious navigation.

Means almost every other time you're sent a link, you have to log in yet again. And man are you sent jira tickets often in tech.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#98
post #91

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

> there's no benefit to the user to have an old account I used to think so until I decided to reroll my old account into a new one, and it was such a pain re-subscribing to all my subreddits again.

See, I don’t mind this process.

It gives you a chance to re-evaluate what is actually giving you value. It’s like spring cleaning.

It’s the same reason I enjoy setting up a new or freshly reformatted phone or laptop. Feels good to clean out the cobwebs.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#99
post #39

Earlier quoted context omitted.

> My house's front door lock is broadly the same interface as my great-grandparent's front door lock True, but your house's front door lock is very likely to offer quite poor security. Most house locks are vulnerable to bumping attacks that are almost trivial to pull off. The only reason this is acceptable is the threat model you're dealing with when securing a physical house is very different from securing an intern…

If someone _really_ wants in, the windows are an even weaker point. Obvious at a glance breakage probably not even necessary... (those latches seem awfully flimsy).

At a certain point the walls will be the weak point to a dedicated attacker. Time to dig a moat to scare off the backhoes!

Something I found out recently is that my lockable desk drawer can be thwarted by giving it a sharp shove to the right while pulling the drawer. It juuust about pops the metal locking rod out of the mechanism for a moment, if you're pulling on the drawer it'll just open.. Found it out when I misplaced the key, haha.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#100
post #91

Earlier quoted context omitted.

> there's no benefit to the user to have an old account I used to think so until I decided to reroll my old account into a new one, and it was such a pain re-subscribing to all my subreddits again.

That seems like a solvable thing with a 3rd party app/script. I reroll every time I am banned from a sub I like because that sub notices I play in other subs - that whole “thing” is horseshit to me. So I just reroll to get around that autoban bot.

Do you happen to have a script for this? If so, I’d love to have it as it’s about time I reroll too.
Post reply on HN