Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

171–180 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#171
post #39

Earlier quoted context omitted.

> My house's front door lock is broadly the same interface as my great-grandparent's front door lock True, but your house's front door lock is very likely to offer quite poor security. Most house locks are vulnerable to bumping attacks that are almost trivial to pull off. The only reason this is acceptable is the threat model you're dealing with when securing a physical house is very different from securing an intern…

If someone _really_ wants in, the windows are an even weaker point. Obvious at a glance breakage probably not even necessary... (those latches seem awfully flimsy).

Would a keychain window breaker (sold as an emergency escape for a car) work on home windows? Or is the glass handled differently somehow?

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#172
post #57

Earlier quoted context omitted.

What's embarrassing about a nickname? Having a disconnected online entity means less-than-pleasant jackasses can't pull something from years or even decades ago, put it out of context, and proceed to troll your life. Not putting your real life identity on public display for the world to see means you maintain tighter control over how, when, and where your information gets out. Do you really need your real name, face,…

I assume that Reddit keeps a list of IP addresses and advertising buyers can correlate them with data from other sources to associates accounts with real people. Presumably, a Reddit leak means even more opportunity to unmask (dox) users who have responded truthfully to threads that say things like "what's the worst thing you ever did". Lots of blackmail opportunities.

[deleted]

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#173
post #111
post #93

Earlier quoted context omitted.

>Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss". After what lastpass did I cannot trust any self reporting.

I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?

Reddit is a shady company. Doing everything they can on the browser experience including interrupting me while I'm typing to try to shunt me over to the app is shady. I don't want the app. I have clicked 'continue in browser' at least 200 times. My preference ought to be clear and recorded by now.

I'd stop visiting altogether if I didn't have a general problem with compulsive browsing.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#174

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

This. 2FA (implying a phone number which is most likely most important number in your life) for a link sharing web site? You must be joking.

> This. 2FA (implying a phone number which is most likely most important number in your life) for a link sharing web site? You must be joking.

SMS is no longer recommended as a means of 2FA, as it's very vulnerable. Some sites still rely on it, unfortunately. However, it appears Reddit does support TOTP.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#175

Earlier quoted context omitted.

And apparently the phishing attack phished both password and 2FA for getting into the intranet. So whatever 2FA they used internally didn't help.

Yeah, but every crisis is an opportunity and this is an opportunity to scare people into coughing up PII that advertisers love so much.

TOTP doesn’t expose PII.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#176

Earlier quoted context omitted.

This. 2FA (implying a phone number which is most likely most important number in your life) for a link sharing web site? You must be joking.

> This. 2FA (implying a phone number which is most likely most important number in your life) for a link sharing web site? You must be joking. SMS is no longer recommended as a means of 2FA, as it's very vulnerable. Some sites still rely on it, unfortunately. However, it appears Reddit does support TOTP.

Somehow this reminds me of a wise saying: "Every problem in CS can be solved by adding level of indirection. Except for the problem of excessive number of indirections".

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#177

Earlier quoted context omitted.

Ideally yes, but let's not let the perfect become the enemy of good. If that's what available right now, it should still be used and recommended.

In practice in many services 2FA is about hoarding PI to target ads, not improve security. I don't buy into that.

TOTP doesn’t expose PII.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#178
post #116

Earlier quoted context omitted.

Specifically with regards to Reddit, spez is now known to have edited the database holding comments without making that fact known in any way. So absolutely nothing coming out of Reddit should be trusted or quoted.

Yup, I don't trust spez, I don't trust reddit's management (even less after the Chinese investments). This is a case to be cynical, reddit is not transparent and their leadership has been riddled with stupid politics, including the whole weird saga they did with Ellen Pao.

[dead]

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#179
post #155
post #151

Earlier quoted context omitted.

Reddit doesn't require an email. They use dark patterns to make it look like you do, but anywhere it asks for an email in signup can be left blank.

I think the mods can see if your account has a verified email attached to it though? At least it seems like subs can choose to not let unverified accounts post.

Yea, you cannot post in /r/news for instance without a verified e-mail. Automod will remove your posts/comments.

I don't know what they think they are accomplishing since burner e-mails are trivial, but perhaps it gives a semblance of doing something.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#180
post #148

You used to be able to create a reddit account without an email address. If all they can get is a username and password, by and large, who cares? Just create another account and you're on your way. It's way less likely hackers will figure out your creds on other sites if they don't have an email address to act as a key. Why require email for dumb social media sites? You can talk about password recovery, but emails ar…

There are legitimate reasons for requiring an email, e.g. increasing the difficult of making bots and for banned people to make a new account.

Phone verification raises account creation costs to at least 20-30 cents an account (assuming you ban VOIP and only take first world countries, can be lower otherwise), email verification if you still allow yandex rambler outlook hotmail addresses raises it to a cent at max.
Post reply on HN