Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

121–130 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#121

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

Nothing to lose..? Old and popular reddit accounts are worth more when sold for a reason. If I'm sharing an idea or business update, it's useful to show mods and algorithms that I'm a decade old user and not a bot created this month.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#122
post #68
post #20

Earlier quoted context omitted.

10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…

WebAuthn is an UX improvement as well as a security improvement. I sympathize with your point, but in this case it’s easily sellable as the cure to the rest of your list … unless you somehow lose your key.

That is a "when" event rather than an "if" event.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#123

I'm not giving reddit my phone number, I get enough junk calls as it is. Edit: Reads comment by Maxburn, googles TOTP and Authy Why the heck do I need a 3rd party involved? Ugh

No 3rd party is involved. You're localizing the 2nd factor of authentication. Google could burn down tomorrow andb cease to exist, you could still use authenticator. It's a cryptographic verification scheme, not a service. RSA was a big one that was similar. Not sure if it's still used today but there was a little hardware fob that wasn't connected to the internet or anything, the whole thing works on Time. The only…

RSA SecurId - big problem with that was RSA had the tokens’ seeds, as well as their customers. Recalling all their customers’ tokens after getting hacked back in 2011 must have been expensive.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#124
post #62

Earlier quoted context omitted.

> My house's front door lock is broadly the same interface as my great-grandparent's front door lock True, but your house's front door lock is very likely to offer quite poor security. Most house locks are vulnerable to bumping attacks that are almost trivial to pull off. The only reason this is acceptable is the threat model you're dealing with when securing a physical house is very different from securing an intern…

Also, people should definitely upgrade their front door locks! A three star euro cylinder will snap, instead of letting the intruder in. While surely nothing offers complete security, it massively increases the effort required to break in (from essentially zero).

Well constructed deadbolt on inside only. Much more concerned with a break in when I'm home than when I'm away and this will help dramatically.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#125

So many hacks lately, it's hard to believe that it's a coincidence ?

It's feasible it's related to layoffs. I dunno if it is actually related but no time like the present if everyone's on edge.

Want to phish someone in 2023? Send an email saying they've been laid off. Link to an article (which requires auth to read, of course) for full details of their redundancy payout.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#127

Earlier quoted context omitted.

If any e-mail contains a link to a login webpage, I treat it as a Phishing attempt. Only ever log in on the page you have bookmarked.

That's easier in your private life than in business. A lot of common tools (especially jira, confluence, etc.) have the flimsiest sessions along with just atrocious navigation. Means almost every other time you're sent a link, you have to log in yet again. And man are you sent jira tickets often in tech.

I’m always logged into Jira and Confluence. And if not, the browser has the password stored, so an unknown host would be obvious.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#128
post #121

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

Nothing to lose..? Old and popular reddit accounts are worth more when sold for a reason. If I'm sharing an idea or business update, it's useful to show mods and algorithms that I'm a decade old user and not a bot created this month.

If you're a spammer then yeah, there's value to be had. But for moral people there really isn't any.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#129
> Reddit recommends users set up 2FA to protect accounts

How about Reddit follows their own recommendation and forces 2FA for their employees?

Those kinds of attacks are 100% avoidable. Nobody with my company username and password can do ANYTHING, unless they have physical access to my computer...

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#130
post #128
post #121

Earlier quoted context omitted.

Nothing to lose..? Old and popular reddit accounts are worth more when sold for a reason. If I'm sharing an idea or business update, it's useful to show mods and algorithms that I'm a decade old user and not a bot created this month.

If you're a spammer then yeah, there's value to be had. But for moral people there really isn't any.

I'm mostly a "moral person" whatever that means and I disagree. My Reddit account has value to me for multiple reasons.
Post reply on HN