Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
131–140 of 301 posts
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#132Earlier quoted context omitted.
Specifically with regards to Reddit, spez is now known to have edited the database holding comments without making that fact known in any way. So absolutely nothing coming out of Reddit should be trusted or quoted.
Yup, I don't trust spez, I don't trust reddit's management (even less after the Chinese investments). This is a case to be cynical, reddit is not transparent and their leadership has been riddled with stupid politics, including the whole weird saga they did with Ellen Pao.
I don’t trust authority in general. But given the choice between spez and musk, I’d take spez any day. He’s at least not hopped up on drugs running around making crazy decisions.
And in terms of Reddit’s trustworthiness, it makes even less sense that editing comments would be of any consequence. If they detect a hacker and have the logs to prove it, they’d gain nothing by modifying the logs. And if they don’t, they gain nothing by fabricating the logs. So it seems reasonable to conclude that they just don’t have the logs.
Which is also reasonable. When I was hacking into systems at Matasano, it always made me uncomfortable just how undetectable I was. I wasn’t trying particularly hard to conceal myself, but a few well-chosen bash incantations and opening things in vi means all anyone sees is that a vi process is running.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#133Earlier quoted context omitted.
Using a weird nickname for professional things seems strange to me. I would rather use my name.
buy a domain name (~$9/yr) and get managed e-mail provider that supports wildcard emails (~$50/yr). Now you have unlimited email options.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#134Earlier quoted context omitted.
If I attended a social club and my comments from 10 years ago were permanently engraved on the walls, I'd be much less honest and open.
You can use alts and delete old comments.
Personally I value the web as a knowledge store that persists.
Use a non-logged chat service if you want a transient medium.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#135>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…
We're in a crisis of trust. "You have nothing to lose" is wrong. You and the community both have something to lose if identity is not valued. A throwaway is indistinct from a bot paid for by some rich mustache-twirling billionaire or state actor trying to control narrative.
Nowhere else can you have in-depth technical discussions about the implications of Humean Projectivism on p2p network architecture, with a cybernetic dragonfly, a flying squirrel, and with distracting interjections by a literal fantasy troll. A bit of personal QA/QC, and individual filtering options, are all you need. Anything else is just censorious control of the narrative.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#136Earlier quoted context omitted.
>On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens. It doesn't seem to me that much sophisticated, rather "normal", unless they are…
The sophisticated aspect of these types of attacks typically isn't in the technical aspects, but the social engineering involved. It usually involves meticulous research on the target, what and who they work with, and have crafted an email that plausibly looks and sounds like an internal email, that talks about company stuff in company language, mentions coworkers and so on. Add a note of urgency, make it someone who…
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#137Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#138Earlier quoted context omitted.
I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?
Specifically with regards to Reddit, spez is now known to have edited the database holding comments without making that fact known in any way. So absolutely nothing coming out of Reddit should be trusted or quoted.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#139Earlier quoted context omitted.
>On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens. It doesn't seem to me that much sophisticated, rather "normal", unless they are…
The sophisticated aspect of these types of attacks typically isn't in the technical aspects, but the social engineering involved. It usually involves meticulous research on the target, what and who they work with, and have crafted an email that plausibly looks and sounds like an internal email, that talks about company stuff in company language, mentions coworkers and so on. Add a note of urgency, make it someone who…
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#140Kind of weird posting this here. Hacker News provides little ability to manage an account, much less setup 2FA.