Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

191–200 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#191
post #111
post #93

Earlier quoted context omitted.

>Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss". After what lastpass did I cannot trust any self reporting.

I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?

Never trust any company with a PR department at all, they're all opportunistic liars who's priority is limited damage to the company, not telling the truth. They only do the latter when they think it will have the effect of the former.

Really, don't trust corporations at all. Even if the circumstances of life force you to do business with them and hope nothing goes wrong, that's no reason to ever trust them. The bigger the corporation the more true this is, since the structure of corporations makes people feel less personally responsible for the bad things they might do to you, like lying to you about the scope of a data breach. The "just following orders" mentality allows workers to do things they'd never otherwise do to you, and that's just one example.

If any sort of business is safe to trust, it's the one-man-shop owner-operator kind of business and you can only trust those guys insofar as you can trust any other person at all. In that case you have to consider it on a case-by-case basis.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#192

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

> Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for your profile, there's no benefit to the user to have an old account with lots of karma. Just keep re-rolling with strong random passwords and you have nothing to lose.

I (used to, i guess) do the same. I must have 40 accounts in total over the years. Funny enough i didn't even make a strong password - a stupidly bad one, unique for each account, actually. I had almost hoped it was hacked because it would be interesting to be hacked and not care.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#193
post #116

Earlier quoted context omitted.

Yup, I don't trust spez, I don't trust reddit's management (even less after the Chinese investments). This is a case to be cynical, reddit is not transparent and their leadership has been riddled with stupid politics, including the whole weird saga they did with Ellen Pao.

Ehh. Spez being human makes me inclined to trust him a little more. I’m neutral in politics, but editing those comments was objectively funny. Stupid, yes — astonishingly so. But it finally broke the illusion that users own their comments. That’s all it ever was: an illusion. I don’t trust authority in general. But given the choice between spez and musk, I’d take spez any day. He’s at least not hopped up on drugs run…

So basically "he lied to me, lying is a human behavior, so I trust him."

Wew.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#194
post #181

Earlier quoted context omitted.

The internet was always about judging the content and quality of user's posts/comments, while being unaware of their race, sex, origin, religion, and any other traits they didn't explicitly mention. Nowhere else can you have in-depth technical discussions about the implications of Humean Projectivism on p2p network architecture, with a cybernetic dragonfly, a flying squirrel, and with distracting interjections by a l…

Yes I agree. This just emphasizes OP's point about how we can't make these accounts throwaway as there would be no content to judge.

You judge each comment by its own merits. Online forums like HN are a source of ideas, not necessarily correct ideas.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#195

Earlier quoted context omitted.

This. 2FA (implying a phone number which is most likely most important number in your life) for a link sharing web site? You must be joking.

> This. 2FA (implying a phone number which is most likely most important number in your life) for a link sharing web site? You must be joking. SMS is no longer recommended as a means of 2FA, as it's very vulnerable. Some sites still rely on it, unfortunately. However, it appears Reddit does support TOTP.

They do, but TOTP is only as secure as the seed stored by reddit.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#196

Earlier quoted context omitted.

Ehh. Spez being human makes me inclined to trust him a little more. I’m neutral in politics, but editing those comments was objectively funny. Stupid, yes — astonishingly so. But it finally broke the illusion that users own their comments. That’s all it ever was: an illusion. I don’t trust authority in general. But given the choice between spez and musk, I’d take spez any day. He’s at least not hopped up on drugs run…

I'd take the devil over musk! At least he is not hopped up on drugs and running around making crazy bad decisions

Getting some Poe's Law vibes here.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#197

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

Reads like an 8th grader's report trying to meet the teacher's word count.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#198

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

We're in a crisis of trust. "You have nothing to lose" is wrong. You and the community both have something to lose if identity is not valued. A throwaway is indistinct from a bot paid for by some rich mustache-twirling billionaire or state actor trying to control narrative.

Trusting an anonymous redditor because they have lots of "karma" is extremely foolish. For one, they probably got those internet points by reposting other people's cat pictures and now you're in a conversation with them about something that has nothing to do with the subject of stealing cat photos, so why should the internet points they earned doing that count for anything?

Secondly, it's easy to farm up these internet points and sell the account to somebody else who's keen on exploiting the tendency of people like you to think that the internet points confer trustworthiness.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#199

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

Even if I don't want to throw my reddit account away as such, it's hard for me to imagine ever thinking I'd care more about its security than I would about not giving Reddit my phone contact!

Yeah, this was my first reaction.

"Huh, I guess I better change my password."

"Hmm, give reddit my phone number .... no."

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#200
post #111
post #93

Earlier quoted context omitted.

>Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss". After what lastpass did I cannot trust any self reporting.

I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?

The difficulty of verifying the claim is not somehow a justification for making it - quite the opposite, in fact.

As it happens, there is something that would help, though if and only if they can do it: Explain what evidence they would have if the breach had occurred.

Post reply on HN