Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

221–230 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#221

Earlier quoted context omitted.

I assume that Reddit keeps a list of IP addresses and advertising buyers can correlate them with data from other sources to associates accounts with real people. Presumably, a Reddit leak means even more opportunity to unmask (dox) users who have responded truthfully to threads that say things like "what's the worst thing you ever did". Lots of blackmail opportunities.

It’s worse than this. Reddit, several years ago, introduced outbound click tracking. All outbound clicks from the site are redirected via out.reddit.com which ties click activity to an individual (username / IP / device fingerprint based). This can only be blocked with aggressive old.reddit script blocking which breaks portions of the site. The outbound click data is used for profiling and interest based advertising,…

Did that finally go out to all subs, because for a while it was only on certain subs? I don't use Reddit anymore, after they suspended my account for promoting a peaceful protest of the Billionaire's Summer Camp, where the corporate media meets every year to consolidate the industry and plan the years narrative. This, after they allowed me to be harassed, threatened with sexual violence and doxxed. Good times!

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#222
post #20
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…

More realistically:

8 years ago "no passwords, use a pass phrase"

Average person reluctantly moves from "P@55word!" to "P@55word! P@55word! P@55word!"

6 years ago "different passwords on each set"

Average person shrugs and changes nothing

2 years ago "use TOTP 2FA"

Average person already using SMS changes nothing, and the sites allow this as a grandfathered exception effectively indefinitely

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#223
post #190
post #185

Earlier quoted context omitted.

I would hope most people. I can't imagine being so incurious that I'd read an awesome comment and not wonder who wrote it.

Why should it matter who wrote it?

One big reason I care about who wrote things is expertise. Ex: I've consistently seen informed and sensible security-related commentary from tptacek, so I would pay more attention to security-related advice with his name on it than if it was a name I didn't recognize.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#224

Earlier quoted context omitted.

No 3rd party is involved. You're localizing the 2nd factor of authentication. Google could burn down tomorrow andb cease to exist, you could still use authenticator. It's a cryptographic verification scheme, not a service. RSA was a big one that was similar. Not sure if it's still used today but there was a little hardware fob that wasn't connected to the internet or anything, the whole thing works on Time. The only…

RSA SecurId - big problem with that was RSA had the tokens’ seeds, as well as their customers. Recalling all their customers’ tokens after getting hacked back in 2011 must have been expensive.

Big oooof, wasn't aware of that. I believe TOTP works much differently based on my CLI interaction with it, but an expert would need to confirm.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#225

Earlier quoted context omitted.

Ehh. Spez being human makes me inclined to trust him a little more. I’m neutral in politics, but editing those comments was objectively funny. Stupid, yes — astonishingly so. But it finally broke the illusion that users own their comments. That’s all it ever was: an illusion. I don’t trust authority in general. But given the choice between spez and musk, I’d take spez any day. He’s at least not hopped up on drugs run…

How hard is it to resist directly editing user data on your site? It's a pretty clear-cut case of abuse of power.

I've always strongly believed in "ignorance is bliss", and "if somebody wants me to know something they will tell me".

The idea of snooping barely crosses my mind, let alone editing.

Maybe it is different because Reddit comments are intended to be public.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#226
post #173
post #111

Earlier quoted context omitted.

I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?

Reddit is a shady company. Doing everything they can on the browser experience including interrupting me while I'm typing to try to shunt me over to the app is shady. I don't want the app. I have clicked 'continue in browser' at least 200 times. My preference ought to be clear and recorded by now. I'd stop visiting altogether if I didn't have a general problem with compulsive browsing.

Why use reddit's official app? There are several decent opensource apps. (BTW, you can use libredd.it to just read-only reddit)

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#227
post #199

Earlier quoted context omitted.

Even if I don't want to throw my reddit account away as such, it's hard for me to imagine ever thinking I'd care more about its security than I would about not giving Reddit my phone contact!

Yeah, this was my first reaction. "Huh, I guess I better change my password." "Hmm, give reddit my phone number .... no."

Reddit's TFA is not phone number based. You use a one time password generator.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#228
post #116

Earlier quoted context omitted.

Specifically with regards to Reddit, spez is now known to have edited the database holding comments without making that fact known in any way. So absolutely nothing coming out of Reddit should be trusted or quoted.

Yup, I don't trust spez, I don't trust reddit's management (even less after the Chinese investments). This is a case to be cynical, reddit is not transparent and their leadership has been riddled with stupid politics, including the whole weird saga they did with Ellen Pao.

>Yup, I don't trust spez, I don't trust reddit's management (even less after the Chinese investments)

I think you (and many other people) are overestimating how much chinese influence there is on reddit, considering that they have < 10% stake (according to wikipedia they "led" a funding round that raised 10% of valuation, and since then there was another funding round that presumably diluted their stake).

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#229
post #15
post #3

Earlier quoted context omitted.

>On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens. It doesn't seem to me that much sophisticated, rather "normal", unless they are…

"One of our employees was tricked. The attack must have been sophisticated, because we are a cool gang." Basically applies to every team there is.

I'd say it depends on how much homework was done by an attacker. The company I work for was adding some new services. One of the service setup emails came in and was off just enough that I reported it rather than following it, and yes, it was an internal phishing test, but one I found very valuable because the service providers could be hacked, and the URLs that are used are generally terrible if you're trying to figure out where you're going.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#230

Earlier quoted context omitted.

We're in a crisis of trust. "You have nothing to lose" is wrong. You and the community both have something to lose if identity is not valued. A throwaway is indistinct from a bot paid for by some rich mustache-twirling billionaire or state actor trying to control narrative.

The internet was always about judging the content and quality of user's posts/comments, while being unaware of their race, sex, origin, religion, and any other traits they didn't explicitly mention. Nowhere else can you have in-depth technical discussions about the implications of Humean Projectivism on p2p network architecture, with a cybernetic dragonfly, a flying squirrel, and with distracting interjections by a l…

That's great, in theory.

When it comes to political discussions or any kind of politically biased graphic, particularly if it is something I disagree with, I assume it is astroturf/agitprop. When misinformation and propaganda are mainstream, why can I trust some random account on the internet for facts?

Tech is certainly different.

Post reply on HN