Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

101–110 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#101
post #59

>Reddit also stated that there was no evidence the systems used to run Reddit itself and store the majority of data, the primary production systems in other words, was breached. Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss".

That's always true of everything. How do you know you weren't hacked yesterday?

Reddit also said they haven't seen the data advertised at data-selling sites.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#102
post #20
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…

> Average person reluctantly moves from (…)

A reluctant move is still a move, and thus beneficial. But we definitely have different ideas of the “average person”. I sincerely doubt the average has moved on from P@55word, and even then only because the website they’re trying to register an account with imposes the rule. I’d be happy to be proven wrong; do we have data on it?

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#103
post #100

Earlier quoted context omitted.

That seems like a solvable thing with a 3rd party app/script. I reroll every time I am banned from a sub I like because that sub notices I play in other subs - that whole “thing” is horseshit to me. So I just reroll to get around that autoban bot.

Do you happen to have a script for this? If so, I’d love to have it as it’s about time I reroll too.

No, but I have thought about trying to make one. Hrm.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#104
post #49

Earlier quoted context omitted.

> treat online accounts as throwaway wherever possible I don't need to know who you actually are, but over time interacting with other people here I've started to get a feel for several hundred accounts. This makes HN more pleasant because I have some sense of what sort of person they are to talk with, and what is likely to go well or poorly. When there have been subreddits I was really into, I would start to get a s…

If I attended a social club and my comments from 10 years ago were permanently engraved on the walls, I'd be much less honest and open.

You can use alts and delete old comments.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#105

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

>there's no benefit to the user to have an old account with lots of karma Some subs have a minimum amount age or karma requirement to post. This is ostensibly to combat bots.

Those are very low thresholds.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#106
post #71

Earlier quoted context omitted.

Not a UX improvement. Most users need a yubikey for the computer unless they have a new Mac. Asking my 65 year old dad to keep up with a yubikey is not just bad UX, it's failing UX. It simply will not happen. I don't even think it's realistic to get him to use a smartphone for this, he hates the things. WebAuthn works great for your Web 3.0 startup but as soon as you're talking about the average user, who is likely d…

I thought Windows machines just used the TPM to store WebAuthN keys? No yubikey necessary. Just a click on some popup dialog to select your credential for login.

Windows has a service called "Windows Hello" which can work with WebAuthn (otherwise it's hardware keys). It requires your computer to have various biometric or camera technology built in, such as a finger print scanner. I'm sure windows laptops are more equipped for this, but desktops obviously are not, and I'm certainly not advising folks to leave some insecure cheap imported webcam hooked up 24/7 "for security purposes".

I don't know anyone using "Hello" but I suppose it's an option. Most Windows users would likely have to use a hardware key though.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#107

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

The last time I tried to change the password of a reddit account I lost access to it. I attempted to change the password, got an error saying something went wrong. I figured I'd try again later. so I also didn't save the newly generated password. Got logged out, and couldn't log back in with the old password. And there's no way that I know of to contact anyone at reddit to try and get help.

Try the Forgot Password link?

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#108
post #88
post #57

Earlier quoted context omitted.

What's embarrassing about a nickname? Having a disconnected online entity means less-than-pleasant jackasses can't pull something from years or even decades ago, put it out of context, and proceed to troll your life. Not putting your real life identity on public display for the world to see means you maintain tighter control over how, when, and where your information gets out. Do you really need your real name, face,…

Using a weird nickname for professional things seems strange to me. I would rather use my name.

You can use a neutral nickname.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#110
post #90
post #49

Earlier quoted context omitted.

> treat online accounts as throwaway wherever possible I don't need to know who you actually are, but over time interacting with other people here I've started to get a feel for several hundred accounts. This makes HN more pleasant because I have some sense of what sort of person they are to talk with, and what is likely to go well or poorly. When there have been subreddits I was really into, I would start to get a s…

Interesting. Here I am thinking one of the best things about HN is how the usernames being a lighter shade makes them easy to ignore entirely and focus only on what's being said instead of the speaker.

That's what makes it so awesome when you start recognizing the same username on comments where you subconsciously bother to check the name because it was so interesting
Post reply on HN