Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

201–210 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#201

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

> What inelegant phrasing.

Reddit's own phrasing is much better:

Since we’re talking about security and safety, this is a good time to remind you how to protect your Reddit account. The most important (and simple) measure you can take is to set up 2FA (two-factor authentication) which adds an extra layer of security when you access your Reddit account. Learn how to enable 2FA in Reddit Help. And if you want to take it a step further, it’s always a good idea to update your password every couple of months – just make sure it’s strong and unique for greater protection.

Also: use a password manager! Besides providing great complicated passwords, they provide an extra layer of security by warning you before you use your password on a phishing site… because the domains won’t match!

-- https://www.reddit.com/r/reddit/comments/10y427y/we_had_a_se...

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#203
post #104

Earlier quoted context omitted.

If I attended a social club and my comments from 10 years ago were permanently engraved on the walls, I'd be much less honest and open.

You can use alts and delete old comments.

Changing alts is a lot more pro-social than deleting your comments: with alt rotation your old writing is still available for others to learn from.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#204

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

We're in a crisis of trust. "You have nothing to lose" is wrong. You and the community both have something to lose if identity is not valued. A throwaway is indistinct from a bot paid for by some rich mustache-twirling billionaire or state actor trying to control narrative.

It's interesting; with many sites I'd agree with you, but on Reddit, I don't look at usernames much. I recognize a few usernames in most of the subreddits I visit, just from repeated exposure, but I don't value my own accounts or the karma they accumulate. I use different accounts for different subsets of subreddits the way I wear different clothes for different occasions. If I lost an account I'd sign up for a new one like buying a new outfit. I wonder why it's different.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#205
post #173
post #111

Earlier quoted context omitted.

I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?

Reddit is a shady company. Doing everything they can on the browser experience including interrupting me while I'm typing to try to shunt me over to the app is shady. I don't want the app. I have clicked 'continue in browser' at least 200 times. My preference ought to be clear and recorded by now. I'd stop visiting altogether if I didn't have a general problem with compulsive browsing.

[dead]

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#206
post #49

Earlier quoted context omitted.

> treat online accounts as throwaway wherever possible I don't need to know who you actually are, but over time interacting with other people here I've started to get a feel for several hundred accounts. This makes HN more pleasant because I have some sense of what sort of person they are to talk with, and what is likely to go well or poorly. When there have been subreddits I was really into, I would start to get a s…

If I attended a social club and my comments from 10 years ago were permanently engraved on the walls, I'd be much less honest and open.

There is also the aspect of upvoting/downvoting that completely skews honest opinion.

Instead of acting like a bullshit filter, upvote/downvote tends to act like a dog getting petted for echoing back a popular opinion to the group or the dog being scolded for echoing an unpopular opinion. Dogs like to get pats on the head and don't like being yelled at.

It is really one of the dumbest ideas of the last 30 years. Total disregard for human behavior and total disregard for the truth considering how often the truth is an unpopular opinion at a specific moment in time.

Throwaway accounts to me are a small protest to this ridiculous system.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#207
post #197

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

Reads like an 8th grader's report trying to meet the teacher's word count.

I've actually noticed how _bad_ the writing of some articles can be. I'm not a good writer by any means... but the best I can say is it sounds like an essay cranked out by someone in high school.

Just reminded me of my first "wtf." A journalist for our local university wrote a review for the movie "Hustlers" where they justified sexually assaulting and robbing men in New York because "men in New York were responsible for the 2008 financial crisis." All without missing a beat. Can't believe what passes these days.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#208
post #173
post #111

Earlier quoted context omitted.

I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?

Reddit is a shady company. Doing everything they can on the browser experience including interrupting me while I'm typing to try to shunt me over to the app is shady. I don't want the app. I have clicked 'continue in browser' at least 200 times. My preference ought to be clear and recorded by now. I'd stop visiting altogether if I didn't have a general problem with compulsive browsing.

Sounds like a job for uBlock Origin. Just block the element.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#209
post #173
post #111

Earlier quoted context omitted.

I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?

Reddit is a shady company. Doing everything they can on the browser experience including interrupting me while I'm typing to try to shunt me over to the app is shady. I don't want the app. I have clicked 'continue in browser' at least 200 times. My preference ought to be clear and recorded by now. I'd stop visiting altogether if I didn't have a general problem with compulsive browsing.

Sure, shady companies exist. And you shouldn’t trust shady companies to self report. But… you already know that, it’s in the name! “Shady”. So I think the idea that you should never trust self reporting is indeed an over reaction.

However, having been at (what I deemed) non-shady companies, there’s still the very human desire to downplay as much as is reasonable. Shady companies overstep reasonability on purpose.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#210
post #111

Earlier quoted context omitted.

I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?

Never trust any company with a PR department at all, they're all opportunistic liars who's priority is limited damage to the company, not telling the truth. They only do the latter when they think it will have the effect of the former. Really, don't trust corporations at all. Even if the circumstances of life force you to do business with them and hope nothing goes wrong, that's no reason to ever trust them. The bigg…

Not trusting corporations is possibly the best advice available. I used to work for the largest insurer on Earth, a "health insurance" company. They quit paying for my insulin, which I need to live. They have enough lawyers they could just pile them physically on my house and suffocate me. They then laid me off due to age. My group of layoffs was 155, and of those 17 were under 40. They did give me a pile of cash not to sue - which I took like the opportunistic bastard I am in the end.
Post reply on HN