Live data from Hacker News

Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

forbes.com

261–270 of 301 posts

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#261
post #177

Earlier quoted context omitted.

In practice in many services 2FA is about hoarding PI to target ads, not improve security. I don't buy into that.

TOTP doesn’t expose PII.

Don't you need to send the generator hardware dongle thingy (whatever it is called in English) to the user?

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#263
post #111

Earlier quoted context omitted.

I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?

Never trust any company with a PR department at all, they're all opportunistic liars who's priority is limited damage to the company, not telling the truth. They only do the latter when they think it will have the effect of the former. Really, don't trust corporations at all. Even if the circumstances of life force you to do business with them and hope nothing goes wrong, that's no reason to ever trust them. The bigg…

[deleted]

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#264
post #111
post #93

Earlier quoted context omitted.

>Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss". After what lastpass did I cannot trust any self reporting.

I think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?

Having worked professionally in security and incident response for 15+ years now, this take is not just spot on, but might be overly optimistic.

I can't tell you how many large, well known companies I have worked with that either intentionally mislead, downplay, obscure or straight up lie in these types of notifications.

I have had legal teams tell me that they don't have to notify customers of a breach because an event happened on their test/dev systems, or a developer was compromised and not their actual service.

I have had companies intentionally not give information (like what an attacker was able to exfiltrate from a particular set of customers) that would been extremely helpful to inform or assess their risk. Instead they put out a generic "sophisticated attacker compromised our system, but no credentials or PII from our application were stolen".

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#266
post #190
post #185

Earlier quoted context omitted.

I would hope most people. I can't imagine being so incurious that I'd read an awesome comment and not wonder who wrote it.

Why should it matter who wrote it?

I guess it wouldn't if one didn't value people. YMMV, but I think people are kind of cool — so if I hear a great song I want to know who the artist was. It helps me build a mental model of what I might be able to expect from them. I'm kind of shocked that this might not be obvious to everyone, TBH.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#267
post #90
post #49

Earlier quoted context omitted.

> treat online accounts as throwaway wherever possible I don't need to know who you actually are, but over time interacting with other people here I've started to get a feel for several hundred accounts. This makes HN more pleasant because I have some sense of what sort of person they are to talk with, and what is likely to go well or poorly. When there have been subreddits I was really into, I would start to get a s…

Interesting. Here I am thinking one of the best things about HN is how the usernames being a lighter shade makes them easy to ignore entirely and focus only on what's being said instead of the speaker.

HN is an accessibility nightmare thanks to the low contrast of so many critical UI elements

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#269
post #37

Kind of weird posting this here. Hacker News provides little ability to manage an account, much less setup 2FA.

No 2FA, no muting/blocking or following, non-transparent moderation using long-discredited techniques, security through obscurity. For a site devoted to discussing the latest tech, the site itself is curiously stuck in the 90s and the grognards like it that way.

At least it has kept the nice 90s atmosphere too. Generally HN users are high value targets - how little spam or trolling there is to be found here by outsiders is incredible considering the lack of safeguards you mentioned.

Re: Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA

#270

Earlier quoted context omitted.

Try the Forgot Password link?

The email provider that account was tied to doesn't exist anymore, and the domain is taken. I didn't notice until after it happened, so I am not putting all the blame on reddit. It's more of a string of unlucky circumstances. Who knows if I could have even changed it without access to the email account, anyway. Fun fact: Reddit for the longest time didn't require an email address to create accounts.

Reddit still doesn't require an email to create accounts, even if it now heavily implies it does. Just click next without entering one.
Post reply on HN