Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

161–170 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#161
post #63
post #39

Earlier quoted context omitted.

If someone _really_ wants in, the windows are an even weaker point. Obvious at a glance breakage probably not even necessary... (those latches seem awfully flimsy).

A similar argument I have with my wife: She insists on only living in gated communities. I'm like, "it's just a PVC pipe that goes up and down, it's not fort knox." But for some reason that gives her peace of mind, and worth the HOA fee of $350/mo.

Funnily enough where I live those gated communities have actually ended up being specifically targeted, because funnily enough people assume that if you can afford to live there you probably have stuff worth taking.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#163
post #133

Earlier quoted context omitted.

buy a domain name (~$9/yr) and get managed e-mail provider that supports wildcard emails (~$50/yr). Now you have unlimited email options.

I have that and do that, but it doesn't solve the Google Drive thing.

You can create a new Google account tied to your domain and use that to collaborate with others. You can elect to stop using Gmail and your old nickname, unless I’ve missed something.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#164
post #104

Earlier quoted context omitted.

You can use alts and delete old comments.

Yeah. Let's delete old blogs and shut down the internet archive as well. Personally I value the web as a knowledge store that persists. Use a non-logged chat service if you want a transient medium.

[dead]

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#165
post #50

Earlier quoted context omitted.

That's a good idea and I've thought about it but I think many feel attached to their usernames and account history "15 yeas with.." site X. And sites often balk and say "username or email already has an account here". It's a bit funny since alias was meant to hide who you were or at least make ire less formal than a person's full name. Then I go and use my name for an alias!

The "don't use your real name on the internet" advice wasn't great. When I set up a Google account as a kid I used a made up handle because all the adults told me to not use my name on the internet. Decades later and it's still my main account and I often need to either switch accounts to the one with my real name or embarassingly ask people to invite my nickname account to various shared documents, calendars, etc. N…

In the time that has passed since that advice better name generators have been developed so you don't have to make something up.

https://github.com/moby/moby/blob/master/pkg/namesgenerator/...

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#167
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

Are you really suggesting that a billion netizens should stop using TOTP on their smartphones and go buy another hardware device?

Both latest versions of Android and iOS support passkeys plus support on Chrome/Brave/Edge/Safari.

While not as secure or convenient as a security key for initially logging in there is no need for a new device in many cases.

besides the fact that the webauthn yubikey is $20 vs $50-70 for it's more popular and well known versions.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#168

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

This. 2FA (implying a phone number which is most likely most important number in your life) for a link sharing web site? You must be joking.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#169
post #57

Earlier quoted context omitted.

What's embarrassing about a nickname? Having a disconnected online entity means less-than-pleasant jackasses can't pull something from years or even decades ago, put it out of context, and proceed to troll your life. Not putting your real life identity on public display for the world to see means you maintain tighter control over how, when, and where your information gets out. Do you really need your real name, face,…

I assume that Reddit keeps a list of IP addresses and advertising buyers can correlate them with data from other sources to associates accounts with real people. Presumably, a Reddit leak means even more opportunity to unmask (dox) users who have responded truthfully to threads that say things like "what's the worst thing you ever did". Lots of blackmail opportunities.

It’s worse than this. Reddit, several years ago, introduced outbound click tracking.

All outbound clicks from the site are redirected via out.reddit.com which ties click activity to an individual (username / IP / device fingerprint based). This can only be blocked with aggressive old.reddit script blocking which breaks portions of the site.

The outbound click data is used for profiling and interest based advertising, but the data can be much worse than simply linking comments to identity.

They also tie IP/identity to individuals to serve relevant ads and this is the push to get people installing reddit on phones, where deviceIDs is an easy UUID for ads.

Post reply on HN