Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

111–120 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#111
post #93
post #59

>Reddit also stated that there was no evidence the systems used to run Reddit itself and store the majority of data, the primary production systems in other words, was breached. Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss".

>Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss". After what lastpass did I cannot trust any self reporting.

I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen.

Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#112

I'm not giving reddit my phone number, I get enough junk calls as it is. Edit: Reads comment by Maxburn, googles TOTP and Authy Why the heck do I need a 3rd party involved? Ugh

No 3rd party is involved. You're localizing the 2nd factor of authentication. Google could burn down tomorrow andb cease to exist, you could still use authenticator. It's a cryptographic verification scheme, not a service.

RSA was a big one that was similar. Not sure if it's still used today but there was a little hardware fob that wasn't connected to the internet or anything, the whole thing works on Time. The only thing that fob needed was a constant battery power, if it died you'd have to replace the battery and call the helpdesk to get it resynced with your account. The only thing your phone needs is a good time source like GPS or network time. I believe authenticator app works even if your phone doesn't have service. You could be on a landline in a remote region with no Internet, talking to your significant other on the other side of the world, have them log in to your account and give them the code displayed by the authenticator app and they could send that important email you forgot.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#113
post #105

Earlier quoted context omitted.

>there's no benefit to the user to have an old account with lots of karma Some subs have a minimum amount age or karma requirement to post. This is ostensibly to combat bots.

Those are very low thresholds.

You are right, but it is still annoying when cycling accounts.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#114
post #111
post #93

Earlier quoted context omitted.

>Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss". After what lastpass did I cannot trust any self reporting.

I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?

Specifically with regards to Reddit, spez is now known to have edited the database holding comments without making that fact known in any way.

So absolutely nothing coming out of Reddit should be trusted or quoted.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#115
post #71
post #68

Earlier quoted context omitted.

WebAuthn is an UX improvement as well as a security improvement. I sympathize with your point, but in this case it’s easily sellable as the cure to the rest of your list … unless you somehow lose your key.

Not a UX improvement. Most users need a yubikey for the computer unless they have a new Mac. Asking my 65 year old dad to keep up with a yubikey is not just bad UX, it's failing UX. It simply will not happen. I don't even think it's realistic to get him to use a smartphone for this, he hates the things. WebAuthn works great for your Web 3.0 startup but as soon as you're talking about the average user, who is likely d…

It also is a way worse UX if you lose the authorized device and you're traveling.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#116
post #111

Earlier quoted context omitted.

I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?

Specifically with regards to Reddit, spez is now known to have edited the database holding comments without making that fact known in any way. So absolutely nothing coming out of Reddit should be trusted or quoted.

Yup, I don't trust spez, I don't trust reddit's management (even less after the Chinese investments). This is a case to be cynical, reddit is not transparent and their leadership has been riddled with stupid politics, including the whole weird saga they did with Ellen Pao.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#117
post #91

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

> there's no benefit to the user to have an old account I used to think so until I decided to reroll my old account into a new one, and it was such a pain re-subscribing to all my subreddits again.

Just create a mutlireddit of your subscriptions by going on https://old.reddit.com/subreddits/ and clicking 'multireddit of your subscriptions' on the right. Bookmark that link and voila, you have a backup of your subreddits for your new account.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#119
post #57
post #50

Earlier quoted context omitted.

The "don't use your real name on the internet" advice wasn't great. When I set up a Google account as a kid I used a made up handle because all the adults told me to not use my name on the internet. Decades later and it's still my main account and I often need to either switch accounts to the one with my real name or embarassingly ask people to invite my nickname account to various shared documents, calendars, etc. N…

What's embarrassing about a nickname? Having a disconnected online entity means less-than-pleasant jackasses can't pull something from years or even decades ago, put it out of context, and proceed to troll your life. Not putting your real life identity on public display for the world to see means you maintain tighter control over how, when, and where your information gets out. Do you really need your real name, face,…

I assume that Reddit keeps a list of IP addresses and advertising buyers can correlate them with data from other sources to associates accounts with real people.

Presumably, a Reddit leak means even more opportunity to unmask (dox) users who have responded truthfully to threads that say things like "what's the worst thing you ever did". Lots of blackmail opportunities.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#120
post #88
post #57

Earlier quoted context omitted.

What's embarrassing about a nickname? Having a disconnected online entity means less-than-pleasant jackasses can't pull something from years or even decades ago, put it out of context, and proceed to troll your life. Not putting your real life identity on public display for the world to see means you maintain tighter control over how, when, and where your information gets out. Do you really need your real name, face,…

Using a weird nickname for professional things seems strange to me. I would rather use my name.

buy a domain name (~$9/yr) and get managed e-mail provider that supports wildcard emails (~$50/yr). Now you have unlimited email options.
Post reply on HN