Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

131–140 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#132
post #116

Earlier quoted context omitted.

Specifically with regards to Reddit, spez is now known to have edited the database holding comments without making that fact known in any way. So absolutely nothing coming out of Reddit should be trusted or quoted.

Yup, I don't trust spez, I don't trust reddit's management (even less after the Chinese investments). This is a case to be cynical, reddit is not transparent and their leadership has been riddled with stupid politics, including the whole weird saga they did with Ellen Pao.

Ehh. Spez being human makes me inclined to trust him a little more. I’m neutral in politics, but editing those comments was objectively funny. Stupid, yes — astonishingly so. But it finally broke the illusion that users own their comments. That’s all it ever was: an illusion.

I don’t trust authority in general. But given the choice between spez and musk, I’d take spez any day. He’s at least not hopped up on drugs running around making crazy decisions.

And in terms of Reddit’s trustworthiness, it makes even less sense that editing comments would be of any consequence. If they detect a hacker and have the logs to prove it, they’d gain nothing by modifying the logs. And if they don’t, they gain nothing by fabricating the logs. So it seems reasonable to conclude that they just don’t have the logs.

Which is also reasonable. When I was hacking into systems at Matasano, it always made me uncomfortable just how undetectable I was. I wasn’t trying particularly hard to conceal myself, but a few well-chosen bash incantations and opening things in vi means all anyone sees is that a vi process is running.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#133
post #88

Earlier quoted context omitted.

Using a weird nickname for professional things seems strange to me. I would rather use my name.

buy a domain name (~$9/yr) and get managed e-mail provider that supports wildcard emails (~$50/yr). Now you have unlimited email options.

I have that and do that, but it doesn't solve the Google Drive thing.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#134
post #104

Earlier quoted context omitted.

If I attended a social club and my comments from 10 years ago were permanently engraved on the walls, I'd be much less honest and open.

You can use alts and delete old comments.

Yeah. Let's delete old blogs and shut down the internet archive as well.

Personally I value the web as a knowledge store that persists.

Use a non-logged chat service if you want a transient medium.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#135

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

We're in a crisis of trust. "You have nothing to lose" is wrong. You and the community both have something to lose if identity is not valued. A throwaway is indistinct from a bot paid for by some rich mustache-twirling billionaire or state actor trying to control narrative.

The internet was always about judging the content and quality of user's posts/comments, while being unaware of their race, sex, origin, religion, and any other traits they didn't explicitly mention.

Nowhere else can you have in-depth technical discussions about the implications of Humean Projectivism on p2p network architecture, with a cybernetic dragonfly, a flying squirrel, and with distracting interjections by a literal fantasy troll. A bit of personal QA/QC, and individual filtering options, are all you need. Anything else is just censorious control of the narrative.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#136
post #3

Earlier quoted context omitted.

>On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens. It doesn't seem to me that much sophisticated, rather "normal", unless they are…

The sophisticated aspect of these types of attacks typically isn't in the technical aspects, but the social engineering involved. It usually involves meticulous research on the target, what and who they work with, and have crafted an email that plausibly looks and sounds like an internal email, that talks about company stuff in company language, mentions coworkers and so on. Add a note of urgency, make it someone who…

Yep. We had a charming English fellow at NCC Group in charge of doing this for a living. He had it down to a science. Everything from the phrasing to the phishing.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#137
post #104

Earlier quoted context omitted.

If I attended a social club and my comments from 10 years ago were permanently engraved on the walls, I'd be much less honest and open.

You can use alts and delete old comments.

There's no deleting beyond a time limit on HN

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#138
post #111

Earlier quoted context omitted.

I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?

Specifically with regards to Reddit, spez is now known to have edited the database holding comments without making that fact known in any way. So absolutely nothing coming out of Reddit should be trusted or quoted.

[deleted]

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#139
post #3

Earlier quoted context omitted.

>On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens. It doesn't seem to me that much sophisticated, rather "normal", unless they are…

The sophisticated aspect of these types of attacks typically isn't in the technical aspects, but the social engineering involved. It usually involves meticulous research on the target, what and who they work with, and have crafted an email that plausibly looks and sounds like an internal email, that talks about company stuff in company language, mentions coworkers and so on. Add a note of urgency, make it someone who…

Cloning an intranet site is also a nice wrinkle that probably trips up a lot of less-tech-savvy employees who are trained to recognize phishing attempts that use replicas of Amazon, Google, Facebook, and other big well-known public web sites, which they mentally categorize as a different thing from their company's internal tools.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#140
post #37

Kind of weird posting this here. Hacker News provides little ability to manage an account, much less setup 2FA.

No 2FA, no muting/blocking or following, non-transparent moderation using long-discredited techniques, security through obscurity. For a site devoted to discussing the latest tech, the site itself is curiously stuck in the 90s and the grognards like it that way.
Post reply on HN