>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…
Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
241–250 of 301 posts
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#242Earlier quoted context omitted.
The last time I tried to change the password of a reddit account I lost access to it. I attempted to change the password, got an error saying something went wrong. I figured I'd try again later. so I also didn't save the newly generated password. Got logged out, and couldn't log back in with the old password. And there's no way that I know of to contact anyone at reddit to try and get help.
Try the Forgot Password link?
Fun fact: Reddit for the longest time didn't require an email address to create accounts.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#243Earlier quoted context omitted.
Why should it matter who wrote it?
One big reason I care about who wrote things is expertise. Ex: I've consistently seen informed and sensible security-related commentary from tptacek, so I would pay more attention to security-related advice with his name on it than if it was a name I didn't recognize.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#244Earlier quoted context omitted.
> treat online accounts as throwaway wherever possible I don't need to know who you actually are, but over time interacting with other people here I've started to get a feel for several hundred accounts. This makes HN more pleasant because I have some sense of what sort of person they are to talk with, and what is likely to go well or poorly. When there have been subreddits I was really into, I would start to get a s…
Interesting. Here I am thinking one of the best things about HN is how the usernames being a lighter shade makes them easy to ignore entirely and focus only on what's being said instead of the speaker.
My kingdom for an ignore-list.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#245>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#246Earlier quoted context omitted.
Reads like an 8th grader's report trying to meet the teacher's word count.
I've actually noticed how _bad_ the writing of some articles can be. I'm not a good writer by any means... but the best I can say is it sounds like an essay cranked out by someone in high school. Just reminded me of my first "wtf." A journalist for our local university wrote a review for the movie "Hustlers" where they justified sexually assaulting and robbing men in New York because "men in New York were responsible…
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#247Earlier quoted context omitted.
Reddit is a shady company. Doing everything they can on the browser experience including interrupting me while I'm typing to try to shunt me over to the app is shady. I don't want the app. I have clicked 'continue in browser' at least 200 times. My preference ought to be clear and recorded by now. I'd stop visiting altogether if I didn't have a general problem with compulsive browsing.
Why use reddit's official app? There are several decent opensource apps. (BTW, you can use libredd.it to just read-only reddit)
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#248And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.
10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…
Your front door doesn't have thousands of anonymous bots a day trying to brute force it.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#249Earlier quoted context omitted.
The sophisticated aspect of these types of attacks typically isn't in the technical aspects, but the social engineering involved. It usually involves meticulous research on the target, what and who they work with, and have crafted an email that plausibly looks and sounds like an internal email, that talks about company stuff in company language, mentions coworkers and so on. Add a note of urgency, make it someone who…
Cloning an intranet site is also a nice wrinkle that probably trips up a lot of less-tech-savvy employees who are trained to recognize phishing attempts that use replicas of Amazon, Google, Facebook, and other big well-known public web sites, which they mentally categorize as a different thing from their company's internal tools.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#250>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…
We're in a crisis of trust. "You have nothing to lose" is wrong. You and the community both have something to lose if identity is not valued. A throwaway is indistinct from a bot paid for by some rich mustache-twirling billionaire or state actor trying to control narrative.
We need some way of verifying that a real human is on the other end, but we don't necessarily need to know who that person is.