Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

251–260 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#251
post #63

Earlier quoted context omitted.

A similar argument I have with my wife: She insists on only living in gated communities. I'm like, "it's just a PVC pipe that goes up and down, it's not fort knox." But for some reason that gives her peace of mind, and worth the HOA fee of $350/mo.

My God. My condo complex is responsible for all external maintenance. It has steel gates that would stop an f150. They handle water, gas and trash pickup and it only costs $230/mo. It's in a fairly pricey area. I feel like you're getting robbed.

My HOA is 250 a year. haha

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#252
post #62

Earlier quoted context omitted.

> My house's front door lock is broadly the same interface as my great-grandparent's front door lock True, but your house's front door lock is very likely to offer quite poor security. Most house locks are vulnerable to bumping attacks that are almost trivial to pull off. The only reason this is acceptable is the threat model you're dealing with when securing a physical house is very different from securing an intern…

Also, people should definitely upgrade their front door locks! A three star euro cylinder will snap, instead of letting the intruder in. While surely nothing offers complete security, it massively increases the effort required to break in (from essentially zero).

Very few break-ins are accomplished via defeating a lock with something in the vein of a pick (bumping, pick gun, etc). Most break in are accomplished via a broken window/glass door.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#253
post #228
post #116

Earlier quoted context omitted.

Yup, I don't trust spez, I don't trust reddit's management (even less after the Chinese investments). This is a case to be cynical, reddit is not transparent and their leadership has been riddled with stupid politics, including the whole weird saga they did with Ellen Pao.

>Yup, I don't trust spez, I don't trust reddit's management (even less after the Chinese investments) I think you (and many other people) are overestimating how much chinese influence there is on reddit, considering that they have < 10% stake (according to wikipedia they "led" a funding round that raised 10% of valuation, and since then there was another funding round that presumably diluted their stake).

Above 0 is too much. Could 10% buy you mod spot over a large major subreddit? Maybe get reddit to look the other way for your astroturf campaigns?

Reddit is just as shady with its Overton Window manipulation tactics & strategies as Twitter has been exposed to be. Remember when Ghislaine Maxwell was revealed as a mod of r/Worldnews? I'm convinced any relevant PR company worth its salt has infiltrated moderator teams of every major subreddit. Whats stopping them? Or anyone else for that matter

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#254
post #213

Earlier quoted context omitted.

You judge each comment by its own merits. Online forums like HN are a source of ideas, not necessarily correct ideas.

Eh in many ways that is not how humans work. We tend to build close in groups with higher trust level, because not trusting everything any anyone is physically and mentally exhausting. If you met a person that behaved in this manner in real life most people would conclude they had a mental illness or were an abuse victim.

Interacting with accounts in a huge, pseudo-anonymous social media sites based on discussion with voting systems is quite different from interacting with people in real life. For big sites like HN and most subreddits, the users may as well be anonymous. HN goes a step further and deemphasizes usernames a bit by making them lighter in color and smaller compared to the black body text. How do you build a "close in group" on a site this big with not a lot of emphasis on who you are? I've been on smaller message boards where you can actually get to know people and have an avatar and some public info about yourself attached to every post. It's a different experience in that case, for sure.

You wanna talk about how humans work - strangers in real life also don't just walk up to you and start talking about Reddit account security out of the blue! We also don't trust a talking head on TV or on the radio just because they're human. Relationships are built over time & higher trust has to be earned. Even if you're referring to the fact that most of us probably live in a relatively high trust society, that doesn't mean we trust our neighbors' opinions on strong passwords (or whatever) just because we trust them as our neighbor!

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#255

Earlier quoted context omitted.

> Never trust any company with a PR department at all So you're saying we should trust Twitter? :)

Heh, but what is Elon, if not a one-man PR department?

One man department. Such praise.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#256
post #173
post #111

Earlier quoted context omitted.

I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?

Reddit is a shady company. Doing everything they can on the browser experience including interrupting me while I'm typing to try to shunt me over to the app is shady. I don't want the app. I have clicked 'continue in browser' at least 200 times. My preference ought to be clear and recorded by now. I'd stop visiting altogether if I didn't have a general problem with compulsive browsing.

Reddit pushing their app so hard annoys the hell out of me too, but what are they doing that qualifies as "shady"?

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#257
post #181

Earlier quoted context omitted.

Yes I agree. This just emphasizes OP's point about how we can't make these accounts throwaway as there would be no content to judge.

You judge each comment by its own merits. Online forums like HN are a source of ideas, not necessarily correct ideas.

It would be nice for everyone to achieve the platonic ideal of having a gapless empirical understanding of the world from root to stem. It is not possible for a single person to do that, let alone everyone. At some point it becomes necessary to trust if we are going to provide and consume information remotely.

Ideas do not exist without context. Arguably the context is more essential than individual ideas. Judging ideas without context is not a useful exercise. It's easy to fall into a local minimum that's actually quite bad. Eugenics is a common example. Eliminating genetic disease sounds great as long as you don't have the context of genocide or humanism.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#258

Earlier quoted context omitted.

We're in a crisis of trust. "You have nothing to lose" is wrong. You and the community both have something to lose if identity is not valued. A throwaway is indistinct from a bot paid for by some rich mustache-twirling billionaire or state actor trying to control narrative.

Trusting an anonymous redditor because they have lots of "karma" is extremely foolish. For one, they probably got those internet points by reposting other people's cat pictures and now you're in a conversation with them about something that has nothing to do with the subject of stealing cat photos, so why should the internet points they earned doing that count for anything ? Secondly, it's easy to farm up these inter…

Strawman. I never said anything about karma. A user's entire post and comment history is one click away during a discussion. That can be skimmed to build a decent picture quickly. That too can be faked, but the bar is much higher.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#259

Earlier quoted context omitted.

Windows has a service called "Windows Hello" which can work with WebAuthn (otherwise it's hardware keys). It requires your computer to have various biometric or camera technology built in, such as a finger print scanner. I'm sure windows laptops are more equipped for this, but desktops obviously are not, and I'm certainly not advising folks to leave some insecure cheap imported webcam hooked up 24/7 "for security pur…

I would be weary of using this, I have been using Windows since Windows 95 and seen enough things go wrong that I wouldn't want to be locked out of my online accounts. For example one thing I noticed is that by simply updating my BIOS in Windows 11 causes havoc and everything gets signed out. A cross-platform hardware token sounds more appealing to me. I could see Hello being something to secure corporate laptops/acc…

>For example one thing I noticed is that by simply updating my BIOS in Windows 11 causes havoc and everything gets signed out.

That's surprising. As in, the fact that that happens is to be expected from the firmware's point of view - updating the firmware changes the measurements made to the TPM so any secrets can no longer be unlocked. But I would've expected Windows to update the expected measurements before applying the update to prevent that from happening.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#260
post #37

Kind of weird posting this here. Hacker News provides little ability to manage an account, much less setup 2FA.

No 2FA, no muting/blocking or following, non-transparent moderation using long-discredited techniques, security through obscurity. For a site devoted to discussing the latest tech, the site itself is curiously stuck in the 90s and the grognards like it that way.

>no muting/blocking

https://news.ycombinator.com/item?id=33365189

Post reply on HN