Earlier quoted context omitted.
Reddit doesn't require an email. They use dark patterns to make it look like you do, but anywhere it asks for an email in signup can be left blank.
Doesn’t work for me. The Continue button is only enabled once you enter an email address. Furthermore, activating 2FA requires a verified email address. Edit: It works when using the right URL, see https://news.ycombinator.com/item?id=34742134 below.
Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
231–240 of 301 posts
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#232Earlier quoted context omitted.
Even if I don't want to throw my reddit account away as such, it's hard for me to imagine ever thinking I'd care more about its security than I would about not giving Reddit my phone contact!
Yeah, this was my first reaction. "Huh, I guess I better change my password." "Hmm, give reddit my phone number .... no."
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#233Earlier quoted context omitted.
Yup, I don't trust spez, I don't trust reddit's management (even less after the Chinese investments). This is a case to be cynical, reddit is not transparent and their leadership has been riddled with stupid politics, including the whole weird saga they did with Ellen Pao.
Ehh. Spez being human makes me inclined to trust him a little more. I’m neutral in politics, but editing those comments was objectively funny. Stupid, yes — astonishingly so. But it finally broke the illusion that users own their comments. That’s all it ever was: an illusion. I don’t trust authority in general. But given the choice between spez and musk, I’d take spez any day. He’s at least not hopped up on drugs run…
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#234Earlier quoted context omitted.
Yup, I don't trust spez, I don't trust reddit's management (even less after the Chinese investments). This is a case to be cynical, reddit is not transparent and their leadership has been riddled with stupid politics, including the whole weird saga they did with Ellen Pao.
Ehh. Spez being human makes me inclined to trust him a little more. I’m neutral in politics, but editing those comments was objectively funny. Stupid, yes — astonishingly so. But it finally broke the illusion that users own their comments. That’s all it ever was: an illusion. I don’t trust authority in general. But given the choice between spez and musk, I’d take spez any day. He’s at least not hopped up on drugs run…
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#235Earlier quoted context omitted.
Doesn’t work for me. The Continue button is only enabled once you enter an email address. Furthermore, activating 2FA requires a verified email address. Edit: It works when using the right URL, see https://news.ycombinator.com/item?id=34742134 below.
It only works on the desktop site. Did you try on mobile?
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#236Earlier quoted context omitted.
Yeah, but every crisis is an opportunity and this is an opportunity to scare people into coughing up PII that advertisers love so much.
TOTP doesn’t expose PII.
Reddit is far from the worst offender in this area. I should have specified my opinion as a more general one.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#237Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#238Earlier quoted context omitted.
>On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens. It doesn't seem to me that much sophisticated, rather "normal", unless they are…
The "sophisticated" term maybe (100% for sure) was meant to save face. As in reddit staff should have known better and were supposed to be IT, social media, Internet culture experts. But fell for it anyway.
The employee's password was probably passw0rd, and that's being generous for reddit.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#239Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#240You used to be able to create a reddit account without an email address. If all they can get is a username and password, by and large, who cares? Just create another account and you're on your way. It's way less likely hackers will figure out your creds on other sites if they don't have an email address to act as a key. Why require email for dumb social media sites? You can talk about password recovery, but emails ar…
I was able to get the old account disabled, but couldn't get it back because I couldn't prove I'd ever owned it. So I created a new account, and it wasn't a big deal, but I was annoyed that I lost my preferred username. Fortunately I'm not a moderator for any subreddits.
Don't get the privacy concerns. I'm totally fine if people know what I post on Reddit. It's public. I wouldn't want any friends to get confused by private messages sent as me, though.
People who don't care about losing their account probably aren't doing anything they care about with it, and that's okay, but it's not everyone.