Earlier quoted context omitted.
In practice in many services 2FA is about hoarding PI to target ads, not improve security. I don't buy into that.
TOTP doesn’t expose PII.
Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
261–270 of 301 posts
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#262Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#263Earlier quoted context omitted.
I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?
Never trust any company with a PR department at all, they're all opportunistic liars who's priority is limited damage to the company, not telling the truth. They only do the latter when they think it will have the effect of the former. Really, don't trust corporations at all. Even if the circumstances of life force you to do business with them and hope nothing goes wrong, that's no reason to ever trust them. The bigg…
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#264Earlier quoted context omitted.
>Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss". After what lastpass did I cannot trust any self reporting.
I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?
I can't tell you how many large, well known companies I have worked with that either intentionally mislead, downplay, obscure or straight up lie in these types of notifications.
I have had legal teams tell me that they don't have to notify customers of a breach because an event happened on their test/dev systems, or a developer was compromised and not their actual service.
I have had companies intentionally not give information (like what an attacker was able to exfiltrate from a particular set of customers) that would been extremely helpful to inform or assess their risk. Instead they put out a generic "sophisticated attacker compromised our system, but no credentials or PII from our application were stolen".
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#265Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#266Earlier quoted context omitted.
I would hope most people. I can't imagine being so incurious that I'd read an awesome comment and not wonder who wrote it.
Why should it matter who wrote it?
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#267Earlier quoted context omitted.
> treat online accounts as throwaway wherever possible I don't need to know who you actually are, but over time interacting with other people here I've started to get a feel for several hundred accounts. This makes HN more pleasant because I have some sense of what sort of person they are to talk with, and what is likely to go well or poorly. When there have been subreddits I was really into, I would start to get a s…
Interesting. Here I am thinking one of the best things about HN is how the usernames being a lighter shade makes them easy to ignore entirely and focus only on what's being said instead of the speaker.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#268Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#269Kind of weird posting this here. Hacker News provides little ability to manage an account, much less setup 2FA.
No 2FA, no muting/blocking or following, non-transparent moderation using long-discredited techniques, security through obscurity. For a site devoted to discussing the latest tech, the site itself is curiously stuck in the 90s and the grognards like it that way.
Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
#270Earlier quoted context omitted.
Try the Forgot Password link?
The email provider that account was tied to doesn't exist anymore, and the domain is taken. I didn't notice until after it happened, so I am not putting all the blame on reddit. It's more of a string of unlucky circumstances. Who knows if I could have even changed it without access to the email account, anyway. Fun fact: Reddit for the longest time didn't require an email address to create accounts.