Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

211–220 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#211
post #111

Earlier quoted context omitted.

I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?

Never trust any company with a PR department at all, they're all opportunistic liars who's priority is limited damage to the company, not telling the truth. They only do the latter when they think it will have the effect of the former. Really, don't trust corporations at all. Even if the circumstances of life force you to do business with them and hope nothing goes wrong, that's no reason to ever trust them. The bigg…

> Never trust any company with a PR department at all

So you're saying we should trust Twitter? :)

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#212
post #116

Earlier quoted context omitted.

Yup, I don't trust spez, I don't trust reddit's management (even less after the Chinese investments). This is a case to be cynical, reddit is not transparent and their leadership has been riddled with stupid politics, including the whole weird saga they did with Ellen Pao.

Ehh. Spez being human makes me inclined to trust him a little more. I’m neutral in politics, but editing those comments was objectively funny. Stupid, yes — astonishingly so. But it finally broke the illusion that users own their comments. That’s all it ever was: an illusion. I don’t trust authority in general. But given the choice between spez and musk, I’d take spez any day. He’s at least not hopped up on drugs run…

How hard is it to resist directly editing user data on your site? It's a pretty clear-cut case of abuse of power.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#213
post #181

Earlier quoted context omitted.

Yes I agree. This just emphasizes OP's point about how we can't make these accounts throwaway as there would be no content to judge.

You judge each comment by its own merits. Online forums like HN are a source of ideas, not necessarily correct ideas.

Eh in many ways that is not how humans work. We tend to build close in groups with higher trust level, because not trusting everything any anyone is physically and mentally exhausting. If you met a person that behaved in this manner in real life most people would conclude they had a mental illness or were an abuse victim.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#214
post #49

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

> treat online accounts as throwaway wherever possible I don't need to know who you actually are, but over time interacting with other people here I've started to get a feel for several hundred accounts. This makes HN more pleasant because I have some sense of what sort of person they are to talk with, and what is likely to go well or poorly. When there have been subreddits I was really into, I would start to get a s…

Of course Reddit lets is political allies doxx and harass Reddit's political enemies without reservation, so this will likely affect those accounts more so.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#215

Earlier quoted context omitted.

Never trust any company with a PR department at all, they're all opportunistic liars who's priority is limited damage to the company, not telling the truth. They only do the latter when they think it will have the effect of the former. Really, don't trust corporations at all. Even if the circumstances of life force you to do business with them and hope nothing goes wrong, that's no reason to ever trust them. The bigg…

> Never trust any company with a PR department at all So you're saying we should trust Twitter? :)

Heh, but what is Elon, if not a one-man PR department?

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#216

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

Even if I don't want to throw my reddit account away as such, it's hard for me to imagine ever thinking I'd care more about its security than I would about not giving Reddit my phone contact!

Yep. Looking forward to buying /u/maxwellhill off the dark web, so we can read all those private messages, and finally put to rest all the speculation of it being Ghislaine Maxwell's account (which went dark the day she was arrested).

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#217

Earlier quoted context omitted.

We're in a crisis of trust. "You have nothing to lose" is wrong. You and the community both have something to lose if identity is not valued. A throwaway is indistinct from a bot paid for by some rich mustache-twirling billionaire or state actor trying to control narrative.

Trusting an anonymous redditor because they have lots of "karma" is extremely foolish. For one, they probably got those internet points by reposting other people's cat pictures and now you're in a conversation with them about something that has nothing to do with the subject of stealing cat photos, so why should the internet points they earned doing that count for anything ? Secondly, it's easy to farm up these inter…

All of these trust systems and platforms are a centralized target for the behavior you describe. It makes it easier for those with bad intentions to rinse and repeat. Naive users may be left behind by those who have optimized their strategy.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#218
post #105

Earlier quoted context omitted.

Those are very low thresholds.

You are right, but it is still annoying when cycling accounts.

Yea, you have to precycle effectively and create accounts before hand and let them build at least a small amount of karma.

These days I don't even log into reddit. After wide spread banning from subreddits for random reasons it's not worthwhile. I'll keep browsing old.red as long as it exists but if it goes away I'll DNS block all reddit at the router.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#219

The hacker stole the source code and shortly thereafter died of radiation poisoning

I'd love to see the source code and compare it to the open source code, before they went closed source. I bet there are some real fun things in there, from an attack surface standpoint.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#220
post #139

Earlier quoted context omitted.

The sophisticated aspect of these types of attacks typically isn't in the technical aspects, but the social engineering involved. It usually involves meticulous research on the target, what and who they work with, and have crafted an email that plausibly looks and sounds like an internal email, that talks about company stuff in company language, mentions coworkers and so on. Add a note of urgency, make it someone who…

Cloning an intranet site is also a nice wrinkle that probably trips up a lot of less-tech-savvy employees who are trained to recognize phishing attempts that use replicas of Amazon, Google, Facebook, and other big well-known public web sites, which they mentally categorize as a different thing from their company's internal tools.

It doesn't help companies have so many internal tools. It seems like once a month I'm asking my team if the invite to X service is something we're doing or a phish.
Post reply on HN