Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

141–150 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#141
post #93
post #59

>Reddit also stated that there was no evidence the systems used to run Reddit itself and store the majority of data, the primary production systems in other words, was breached. Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss".

>Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss". After what lastpass did I cannot trust any self reporting.

Maybe I missed that - did they misreport anything? I know they royally fucked up, put they didn't really hide the fact that the (encrypted) vault data was stolen.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#142

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

>> to treat online accounts as throwaway wherever possible

works for me everywhere except HN, because of the silly requirement of 500 karma to be able to downvote.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#143
post #116

Earlier quoted context omitted.

Yup, I don't trust spez, I don't trust reddit's management (even less after the Chinese investments). This is a case to be cynical, reddit is not transparent and their leadership has been riddled with stupid politics, including the whole weird saga they did with Ellen Pao.

Ehh. Spez being human makes me inclined to trust him a little more. I’m neutral in politics, but editing those comments was objectively funny. Stupid, yes — astonishingly so. But it finally broke the illusion that users own their comments. That’s all it ever was: an illusion. I don’t trust authority in general. But given the choice between spez and musk, I’d take spez any day. He’s at least not hopped up on drugs run…

I'd take the devil over musk! At least he is not hopped up on drugs and running around making crazy bad decisions

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#144

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

We're in a crisis of trust. "You have nothing to lose" is wrong. You and the community both have something to lose if identity is not valued. A throwaway is indistinct from a bot paid for by some rich mustache-twirling billionaire or state actor trying to control narrative.

If a website or platform doesn't have sufficient measures, technological or otherwise, to deal with bots, spam, low effort posting, astroturfing, advertising, etc, it's the platform that shouldn't be trusted. If a platform could deal with bots entirely, or associate accounts with a real identity, it still doesn't mean that the platform or the user can be trusted, as identity and trust are not the same thing.

When millionaires, state actors, politicians, corporations, etc, switch from using bot farms to manipulate public opinion to paying influencers to do the same thing, people whose identity is inherently valued and trusted, you end up in the same position as we're currently in.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#145

Earlier quoted context omitted.

I thought Windows machines just used the TPM to store WebAuthN keys? No yubikey necessary. Just a click on some popup dialog to select your credential for login.

Windows has a service called "Windows Hello" which can work with WebAuthn (otherwise it's hardware keys). It requires your computer to have various biometric or camera technology built in, such as a finger print scanner. I'm sure windows laptops are more equipped for this, but desktops obviously are not, and I'm certainly not advising folks to leave some insecure cheap imported webcam hooked up 24/7 "for security pur…

I would be weary of using this, I have been using Windows since Windows 95 and seen enough things go wrong that I wouldn't want to be locked out of my online accounts. For example one thing I noticed is that by simply updating my BIOS in Windows 11 causes havoc and everything gets signed out. A cross-platform hardware token sounds more appealing to me. I could see Hello being something to secure corporate laptops/accounts in an enterprise environment though.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#146
post #141
post #93

Earlier quoted context omitted.

>Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss". After what lastpass did I cannot trust any self reporting.

Maybe I missed that - did they misreport anything? I know they royally fucked up, put they didn't really hide the fact that the (encrypted) vault data was stolen.

After their initial announcement, they updated the same post after months as they had since discovered it was worse. And in some cases it turns out the vault data was not as encrypted as they had ever said. Here's one of the better write-ups I've seen: https://palant.info/2022/12/26/whats-in-a-pr-statement-lastp...

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#147

Just what I need: Another big social media platform connecting one of my many anonymous pseudonyms to my phone number!

It's a ridiculous request. In short:

"We've been hacked, so you should give us your phone number."

Hilarious!

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#148
You used to be able to create a reddit account without an email address. If all they can get is a username and password, by and large, who cares? Just create another account and you're on your way. It's way less likely hackers will figure out your creds on other sites if they don't have an email address to act as a key.

Why require email for dumb social media sites? You can talk about password recovery, but emails aren't necessarily required for that, and it could be something to opt in to. It seems like email is required to make data collection, tracking and advertising easier. It sucks that all this creepy data collection is not only an annoyance, but also makes us less secure.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#150
post #148

You used to be able to create a reddit account without an email address. If all they can get is a username and password, by and large, who cares? Just create another account and you're on your way. It's way less likely hackers will figure out your creds on other sites if they don't have an email address to act as a key. Why require email for dumb social media sites? You can talk about password recovery, but emails ar…

There are legitimate reasons for requiring an email, e.g. increasing the difficult of making bots and for banned people to make a new account.
Post reply on HN