Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

241–250 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#241

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

If you use the old/classic Reddit experience and you can't find the option to enable 2FA in your profile, use this URL directly instead: https://www.reddit.com/2fa/enable/

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#242

Earlier quoted context omitted.

The last time I tried to change the password of a reddit account I lost access to it. I attempted to change the password, got an error saying something went wrong. I figured I'd try again later. so I also didn't save the newly generated password. Got logged out, and couldn't log back in with the old password. And there's no way that I know of to contact anyone at reddit to try and get help.

Try the Forgot Password link?

The email provider that account was tied to doesn't exist anymore, and the domain is taken. I didn't notice until after it happened, so I am not putting all the blame on reddit. It's more of a string of unlucky circumstances. Who knows if I could have even changed it without access to the email account, anyway.

Fun fact: Reddit for the longest time didn't require an email address to create accounts.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#243
post #223
post #190

Earlier quoted context omitted.

Why should it matter who wrote it?

One big reason I care about who wrote things is expertise. Ex: I've consistently seen informed and sensible security-related commentary from tptacek, so I would pay more attention to security-related advice with his name on it than if it was a name I didn't recognize.

[flagged]

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#244
post #90
post #49

Earlier quoted context omitted.

> treat online accounts as throwaway wherever possible I don't need to know who you actually are, but over time interacting with other people here I've started to get a feel for several hundred accounts. This makes HN more pleasant because I have some sense of what sort of person they are to talk with, and what is likely to go well or poorly. When there have been subreddits I was really into, I would start to get a s…

Interesting. Here I am thinking one of the best things about HN is how the usernames being a lighter shade makes them easy to ignore entirely and focus only on what's being said instead of the speaker.

On the contrary, it makes it harder to immediate spot and ignore shitposters or people who consistently make really stupid posts on certain kinds of thread, of which sort there are several very active posters. It's a big part of why a certain kind of trolly posting thrives on HN in a way that it doesn't some other places with sigs or user images or otherwise more-prominent user ID.

My kingdom for an ignore-list.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#245

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

That's how most treat it. Just go to any thread even 3 months old and 1/4th of the users are deleted.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#246
post #197

Earlier quoted context omitted.

Reads like an 8th grader's report trying to meet the teacher's word count.

I've actually noticed how _bad_ the writing of some articles can be. I'm not a good writer by any means... but the best I can say is it sounds like an essay cranked out by someone in high school. Just reminded me of my first "wtf." A journalist for our local university wrote a review for the movie "Hustlers" where they justified sexually assaulting and robbing men in New York because "men in New York were responsible…

When you find out how little these writers are paid you can understand the amount of effort they can put into these articles and still make enough money to eat.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#247
post #173

Earlier quoted context omitted.

Reddit is a shady company. Doing everything they can on the browser experience including interrupting me while I'm typing to try to shunt me over to the app is shady. I don't want the app. I have clicked 'continue in browser' at least 200 times. My preference ought to be clear and recorded by now. I'd stop visiting altogether if I didn't have a general problem with compulsive browsing.

Why use reddit's official app? There are several decent opensource apps. (BTW, you can use libredd.it to just read-only reddit)

Thanks I may look into libredd.it. I intentionally removed the 3rd party apps because they were too good and enabled me to doom scroll too efficiently. I used the website in part because it's a painful experience which will keep me from staying on there too long. A read-only version may help that even more because then I'd have to switch to the full website if I wanted to rage post about how someone is wrong on the internet.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#248
post #20
post #13

And this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.

10 years ago "use a strong password with all these symbols" Average person reluctantly moves from 123456 to P@55word! 8 years ago "no passwords such, use a pass phrase" Average person reluctantly moves from P@55word! to correct-horse-battery-staple 6 years ago "ok but you need to use different passwords on each site" Average person reluctantly moves to different passwords per site 4 years ago "but you can be phished,…

> Normal people don't like new shiny ways of working every year or so. My house's front door lock is broadly the same interface as my great-grandparent's front door lock, but technologists think changing the way things work every couple of years is acceptable.

Your front door doesn't have thousands of anonymous bots a day trying to brute force it.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#249
post #139

Earlier quoted context omitted.

The sophisticated aspect of these types of attacks typically isn't in the technical aspects, but the social engineering involved. It usually involves meticulous research on the target, what and who they work with, and have crafted an email that plausibly looks and sounds like an internal email, that talks about company stuff in company language, mentions coworkers and so on. Add a note of urgency, make it someone who…

Cloning an intranet site is also a nice wrinkle that probably trips up a lot of less-tech-savvy employees who are trained to recognize phishing attempts that use replicas of Amazon, Google, Facebook, and other big well-known public web sites, which they mentally categorize as a different thing from their company's internal tools.

This is what interested me. How do you clone an intranet site without gaining access to it?

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#250

>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for yo…

We're in a crisis of trust. "You have nothing to lose" is wrong. You and the community both have something to lose if identity is not valued. A throwaway is indistinct from a bot paid for by some rich mustache-twirling billionaire or state actor trying to control narrative.

We are in a crisis of trust, but I'm not sure the solution involves stronger identities. I've used Reddit for well over a decade at this point. I hate that my high school opinions are just out there permanently on the internet. It's much more damaging to communities for people to feel like they can't participate for fear of leaving a permanent record. If you were at a party, would you feel comfortable knowing you were being recorded the entire time? I think the same thing applies to digital communities.

We need some way of verifying that a real human is on the other end, but we don't necessarily need to know who that person is.

Post reply on HN