36 ms·
Reddit Security Incident
- vxxzy 8y agoSMS Interception is what got them. Moving to offline 2FA needs to happen. SMS Interception is on the rise.
- Silhouette 8y agoAnd yet bizarrely, the number of organisations with serious security requirements that are adopting SMS messages or other methods dependent on phone numbers as 2FA just recently is quite noticeable. Stripe use it for logging into your business's account. HMRC (the UK government tax office) also uses it for logging in. Various banks and financial services I use in a personal capacity rely on secondary phone authentication to set up things like new recipients for paying bills online.
- deleted 8y ago[deleted]
- packetized 8y agoInteresting that the data accessed was very specifically only limited to: * A complete copy of an old database backup containing very early Reddit user data -- from the site’s launch in 2005 through May 2007 * Logs containing the email digests we sent between June 3 and June 17, 2018 Also of note: "Already having our primary access points for code and infrastructure behind strong authentication requiring two factor authentication (2FA), we learned that SMS-based authentication is not nearly as secure as we would hope, and the main attack was via SMS intercept." If this doesn't put the nail in the coffin of SMS-based 2FA, I'm not sure what will.
- SteveNuts 8y agoI thought I had heard that Reddit was using a non-salted or non-hashed password in the early days?
- tylerhou 8y agoThey probably deleted those backups when they realized how that was bad.
- samstave 8y ago>"Can you txt me the old mysql root pw to the reddit DB? Need to check something, thanks - Alexis."
- Deimorz 8y agoThat was about 6 months before the stolen backup (December 2006): https://www.reddit.com/r/reddit.com/comments/usqe/reddits_streak_of_bad_luck_continues/cuugl/?context=3 https://www.reddit.com/r/reddit.com/comments/usqe/reddits_st...
- mtgx 8y agoIf that's what Reddit's security team was thinking by mid-2018, then Reddit security is in bad shape. NIST recommended the deprecation of SMS 2FA two years ago. When NIST recommends the deprecation of a protocol you know you should've already gotten rid of it five years earlier, not keep it around for another five years. The sooner more companies start supporting U2F and WebAuthn, the sooner more people will start buying and using hardware security keys.
- aroch 8y agoI don't think it was up to Reddit. Some providers offer no way to do MFA without mandatory SMS involvement in some way -- either primary delivery is by SMS or you can "reset" / get back up codes via SMS.
- dbg31415 8y agoLooking at you, LinkedIn. Microsoft has been lax on this.
- robohoe 8y agoMany major banks do that too.
- hackinthebochs 8y agoI've been interested in enabling MFA on my google account, but with no obvious way to bypass/disable SMS, I don't even bother.
- wolf550e 8y agoLook at step 18 in this guide: https://techsolidarity.org/resources/security_key_gmail.htm https://techsolidarity.org/resources/security_key_gmail.htm
- Alex3917 8y agoBecause of cases like this, it's also the admin's responsibility to have their wireless provider put a security pin and a Do Not Port order on their account. Sometimes reps will ignore this and port people's accounts anyway, but it's still negligent not take this precaution.
- JoblessWonder 8y agoThat is not what data it was limited to at all. That is the data they are highlighting because it affects their users the most. Here is the list of what of what they are saying they got access to: https://news.ycombinator.com/item?id=17665254 https://news.ycombinator.com/item?id=17665254
- mikestew 8y agowe learned that SMS-based authentication is not nearly as secure as we would hope Yeesh, what is going on with their security team over there? Years ago it was "oh, now we realize why everyone was saying that storing passwords in plaintext is a bad idea." Now it's "oh, now we realize what a bad idea SMS auth is." So what is Reddit doing today that you and I would think, "of course, no one does that anymore 'cuz 'duh'." but they think, "nah, it's still okay."?
- tptacek 8y agoIt sounds like Reddit just recently hired security. It's not at all unusual for companies of Reddit's size not to have a security team; the only thing that makes them noteworthy in that regard is how old the company is. If your expectation is that most of the companies you've worked with or availed yourself of have dedicated security teams, revise your expectations sharply downwards.
- mikestew 8y agoIt's not at all unusual for companies of Reddit's size not to have a security team; Well, by "security team" I meant "people that should know better". I mean, raise your hand if you knew even ten years ago what a bad idea it was to store passwords in plaintext. Okay, now keep your hand up if you're job role includes the words "security team". Hmm, not a lot of hands left. You don't need a dedicated security team to figure out that some folks, including the CEO, shouldn't be let anywhere near the database nor making design decisions.
- koube 8y agoReddit had a security team, they just haven't had the position "Head of Security" until now[0]. They did have a policy of using TOTP but couldn't enforce it on certain providers (applications?) [1]. [0]: https://old.reddit.com/r/announcements/comments/93qnm5/we_had_a_security_incident_heres_what_you_need_to/e3f8fza/?context=1 https://old.reddit.com/r/announcements/comments/93qnm5/we_ha... [1]: https://old.reddit.com/r/announcements/comments/93qnm5/we_had_a_security_incident_heres_what_you_need_to/e3f79r9/?context=1 https://old.reddit.com/r/announcements/comments/93qnm5/we_ha...
- robk 8y agoHas anyone leaked this? I'm more interested in unlocking my eponymous account I created 13 years ago then promptly lost access to without an email attached :(
- ziftface 8y agoHow would that help you? Brute force a bunch of your old passwords?
- anowlcalledjosh 8y agoThere are a couple of comments on the linked thread suggesting that someone may be using it (scam emails containing people's old reddit passwords).
- BOBOTWINSTON 8y agoCan you or someone else explain/link to me the basics of why SMS-based 2FA is so terrible? I've never really heard the sentiment before, but it appears to be common knowledge.
- nodesocket 8y agoThis seems to indicate a level of sophistication behind traditional hacking skills. How did they get the phone number to know which carrier to contact to socially engineer? Also, I am not sure I understand: > we suspect weaknesses inherent to SMS-based 2FA to be the root cause of this incident It seems that optaining employee login credentials was the root cause, and bypassing 2FA was the second hurdle but not the root cause.
- freeone3000 8y agoYou don't need to know the carrier, just the number. Talk to a carrier in the country and ask to port "your" number to a new plan. Most salespeople would have no problem ignoring security for a sale.
- c2h5oh 8y ago1. It's too easy to get a duplicate sim card 2. MITM for SMS is not hard if you can get close and requires <$500 in hardware
- DennisAleynikov 8y agoTOTP clients cannot be intercepted where as sms tokens can be compromised in a variety of ways.
- whitepoplar 8y agoTOTP tokens can absolutely be intercepted. A MITM attack can work like this: 1) User inputs username and pw into spurious site. 2) Spurious site prompts for the user's TOTP token. 3) Spurious site proceeds to immediately log in to the real site w/ username, pw, and valid TOTP token. 4) Bad guys get an HTTP session cookie which for many sites lasts practically indefinitely.
- deleted 8y ago[deleted]
- jandrese 8y agoSMS is not about securing an account. It's only use is as a proof of work (money) to make it harder/more expensive to make a bot account. Using it as a security measure is a mistake.
- pandasun 8y agoEdit: nevermind
- always_good 8y agoThey didn't say write-only access. They said they only got R access instead of RW access.
- slg 8y agoThe hacker(s) took a database backup from 2007. I have never worked anywhere that has kept a backup that long. It is possible it is some sort of final archive before a large migration, redesign, or something like that. However if the intent is to keep it forever it should at least be encrypted. As far as I'm aware, the only strong reason to not enable encryption on backups is to allow a secondary backup or mirroring system to compare the changes between backup files rather than reprocessing the entire thing as a single new file. That reason disappears for an archived backup.
- draw_down 8y agoA lot of things now considered security best practices were not in wide use back in 2007, to put it mildly.
- btgeekboy 8y agoGiven the weird collection of stuff they got (including the ancient database backup) I wouldn’t be surprised if this was the contents of an admin’s home directory.
- Symbiote 8y ago+1 insightful. While looking at GDPR compliance, I came across a guide that said "backups are kept for as long as it will take you to notice the missing data and restore it. Exported data kept for longer than this is an archive". That helped me realise I really shouldn't be keeping 5-year-old database backups for some systems; a few months is plenty sufficient time for us to notice any corruption. As part of that clear-out, I searched for and deleted many old mysql-backup-2012-just-in-case.tar.gz from /root and similar places.
- dane-pgp 8y agoSpeaking of GDPR compliance, and as some in the Reddit thread have pointed out, the GDPR requires disclosure of serious data breaches to the affected users without "undue delay", and to the relevant supervisory authority within 72 hours: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/personal-data-breaches/ https://ico.org.uk/for-organisations/guide-to-the-general-da... It will be interesting to see what consequences, if any, Reddit end up facing over this.
- hyder_m29 8y agoHow would an attacker go about intercepting an SMS?
- httpz 8y agoI once walked into a T-mobile store, showed them my phone and claimed that the simcard is stuck and asked them to transfer it to a new simcard I brought with me. They asked for my phone number, scanned the barcode on the new simcard, done. I didn't have to provide any identity. I could have been anybody and the only trace would be the security camera in the store.
- firloop 8y agoEssentially, convincing a mobile operator to transfer someone’s phone account to a SIM card an attacker controls.
- roganartu 8y agoThe SMS interception via social engineering of telecom support staff, as others have pointed out, seems most likely, but consider another approach: an app on the users phone with message read permissions. Most people are not diligent enough to perform an audit of the permissions requested by every app they install and I could also believe a determined attacker might install an app on an unattended and unlocked phone given the opportunity.
- saagarjha 8y agoOf course, this only works on Android, and the user has to have given explicit permission for this.
- ksec 8y agoMost of these so called Social Engineering of your Sim happens in US. In most other places, your are required some form of proof before you can get or alter any of your personal information as well as Sim card.
- EwanToo 8y agoTake a look at this post for an example attack https://theantisocialengineer.com/2018/07/23/sim-swap-fraud-a-victims-perspective/ https://theantisocialengineer.com/2018/07/23/sim-swap-fraud-...
- Alex3917 8y agoSMS hijacking? Really? How is it that Reddit’s security team is continually learning security lessons that have been common knowledge among non-technical people for 5+ years? They seem to treat their production systems more carelessly than the average person treats their Nintendo switch account.
- vesinisa 8y agoFor example GitHub Enterprise account does not differentiate between security levels of token and SMS based 2FA so the issue seems more widespread.
- StriverGuy 8y agoThis is not common knowledge among non-technical people. In fact, many non-technical people don't even know what 2FA is. Additionally, it can take some time to change security standards in a large company. Most companies that are not in high compliance environments focus their engineering efforts on features.
- gmjosack 8y ago> been common knowledge among non-technical people for 5+ years Who are these non-technical people that you know that are not only using MFA but also know that SMS is insecure for MFA? Rather than putting them down I'm happy they're willing to share and bring knowledge, that some communities already know, to even more people.
- Alex3917 8y ago> Who are these non-technical people that you know that are not only using MFA but also know that SMS is insecure for MFA? Anyone who reads pretty much any mainstream newspaper? At this point it would be easier to name mainstream media publications that haven’t covered this issue extensively. E.g. just google: site:nytimes.com sms hijacking site:wsj.com sms hijacking site:latimes.com sms hijacking Not to mention the fact that it’s been discussed on Reddit itself hundreds of times. And on the front page of HN dozens of times as well. E.g.: https://news.ycombinator.com/item?id=14480191 https://news.ycombinator.com/item?id=14480191
- danbtl 8y agoHow does SMS interception actually work in practice? Wouldn't this require physical access to the phone/SIM, or are there any known remote exploits?
- tptacek 8y agoHow about "teenager calls phone company, gets number reassigned"? That's the level of assurance we're dealing with in SMS.
- srj 8y agoI was able to go into a mobile phone store and ask for a new sim for phone number x and get it without any identification. All I was asked was to sign my name and pay some small amount of money.
- ojosilva 8y agoWould someone kindly explain how a SMS can be intercepted during 2FA and how/why tokens otoh are safer? A friend and I were brainstorming the design of a fraud prevention app/startup just this week and we naively thought SMS would be the way to go. Yikes!
- css 8y agoEither some sort of ss7 exploit [0] or the attackers socially engineered the cell service provider [1]. This happened to some big YouTubers in the past [2]. [0] https://www.washingtonpost.com/news/the-switch/wp/2014/12/18/german-researchers-discover-a-flaw-that-could-let-anyone-listen-to-your-cell-calls-and-read-your-texts/?utm_term=.bb0aa36f9144 https://www.washingtonpost.com/news/the-switch/wp/2014/12/18... [1] https://www.theregister.co.uk/2017/07/10/att_falls_for_hacker_tricks/ https://www.theregister.co.uk/2017/07/10/att_falls_for_hacke... [2] https://www.youtube.com/watch?v=caVEiitI2vg https://www.youtube.com/watch?v=caVEiitI2vg
- AnoniMoose 8y agoYou don't need ss7 0days. One one hand it's hilariously insecure to begin with, especially now lots of it gets trucked over the internet. On the other hand, there's a number of companies selling access and associated services for trivial amounts of money.
- tptacek 8y agoSMS ties security to phone numbers. Phone companies can trivially move numbers to different people, accounts, and SIMs. When you rely on SMS for security, you are relying on the customer support staff of giant mobile phone companies for your security. There are other more technical weaknesses with SMS, because the phone networks themselves are also insecure. But the big issue is phone companies themselves. Don't use SMS 2FA.
- chris_wot 8y agoGoogle pretty much foists it on all our employees.
- Dowwie 8y agoIf you are using SMS based 2FA, understand the risk:. "Already having our primary access points for code and infrastructure behind strong authentication requiring two factor authentication (2FA), we learned that SMS-based authentication is not nearly as secure as we would hope, and the main attack was via SMS intercept. We point this out to encourage everyone here to move to token-based 2FA."
- lsllc 8y agoAlright, 2FA tokens came up the other day on HN and now we have this. Time to make the switch. Yubikey 4 / Feitian looks interesting, but it seems it only works in Chrome with Gmail etc. etc. Anyone have any thoughts on solutions that include Safari on Mac and/or iOS? The NEO claims NFC support but I doubt that works on iOS.
- teilo 8y ago2FA does not usually mean U2F hardware such as Yubikey. Reddit does not support hardware keys. Most of the time, 2FA means using a token generator, such as Google Authenticator, Authy, or similar. They are just apps. This is much safer than SMS because one would need physical access to your unlocked phone to generate a token.
- jjnoakes 8y agoTOTP has a downside when compared to SMS as well. In cases where server security was breached and databases (or database backups or dumps) were accessed, if the TOTP seeds were part of the database (not sure how likely that is, but I'm guessing it's likely), then TOTP is doing nothing for security. TOTP protects against things like credential stuffing and weak passwords, and is safer than SMS (no hijacking/intercepting), but for database security breaches things aren't so cut and dry. I wonder if there should be a TOTP-like app which you still register with a site when you first log in or create your account, and which codes are sent to when new logins are needed, but which uses a more secure communication channel than SMS. This gives you the best of both worlds, no? One-time codes not generated from a single plain text seed, communicated to a known client over a secure channel, to prove the initial user is still in possession of the known client?
- tptacek 8y agoThe distinction you're drawing here isn't meaningful. Outside of securing an application's database, a TOTP key has no value anyways. If you have a persistent attacker who quietly owns your database, no 2FA is doing anything for you; the attacker can log in whenever they want anyways. Once the database is compromised, you invalidate all the TOTP secrets, and they become worthless.
- samstave 8y agoI got the alert to change my PW. I had had the same PW for 12 years! Edit: 12 years, not 13. ------------------------------- Account credentials from 2007 compromised from reddit [A] sent 35 minutes ago Hi, TL;DR: As part of the security incident described here, we've determined that your account credentials may have been compromised. You'll need to reset your password to continue using Reddit. Details below. On June 19, Reddit was alerted about a security incident during which an attacker gained access to account credentials from 2007 (usernames + salted password hashes). We're messaging you because your Reddit account credentials were among the data that was accessed. If there's a chance the credentials relate to your current password, we'll prompt you to reset the password on your Reddit account. Also, think about whether you still use the password you used on Reddit 11 years ago on any other sites today. If there's a chance the credentials relate to the password you're currently using on Reddit, we'll make you reset your Reddit account password. You can find more information about the incident in the announcement post linked above. If you have other questions not answered there, feel free to contact us at contact@reddit.com.
- shawn 8y agoHas reddit been live for 13 years? Jeez. I thought my 11 year account was old.
- oldManRiver 8y agoI got on reddit in 2005, before you could comment. Got on thefacebook as well in 2005 because the college kids in my classes (taking for fun as an adult) told me I needed to be on there to get invited to parties and so they could write on my wall. Good times.
- samstave 8y agoWith those comments and your username, you can tell people to CD .. off your lawn.
- empath75 8y ago>In other news, we hired our very first Head of Security wow...
- sdinsn 8y ago> we hired our very first Head of Security, and he started 2.5 months ago He started before the hack happened
- jandrese 8y agoI'm pretty sure he didn't fix every security problem on his first day of work. Once a company gets big enough every change ends up being an ordeal of organizing all stakeholders and getting them to agree and giving them time to update their own systems so they won't be broken when the change happens, etc...
- Deimorz 8y agoThe scary part of this is probably for people that had accounts on reddit in 2007 but later deleted them, or just completely forgot they existed. Reddit's not going to be able to contact the owners of those accounts. Did you have an account 11 years ago? Did you vote on anything embarrassing, or send any compromising messages? How sure are you? I don't even know the answer to those questions for myself.
- techscruggs 8y agoReddit can't contact them because Reddit didn't require an email address to create an account back then. If they did require an email address, they could restore their database backups to retrieve that information.
- Deimorz 8y agoEven then, that would require those people to still have access to the same email address they used to sign up over 11 years ago. Even Gmail probably wasn't in very wide use yet at that point, it was invite-only until February 2007.
- Markoff 8y agoi use email addresses set up 20 years ago, they are just redirected to my current mailbox or pulled by current mailbox
- PSZD 8y agoReddit still doesn't require an email, the signup form is just a well executed dark pattern - you can hit next and skip providing an email.
- deaddodo 8y agoI wouldn't call a form requesting your email (the only entry field on a dedicated page) a "dark pattern". They out right imply an email is necessary and knowing it's not requires knowledge otherwise or accidentally clicking "next".
- JoblessWonder 8y agoThis incident report glosses over the depth of what access was given to focus on the user data that was compromised... but it sure seems like they got pretty deep: * A complete copy of an old database backup containing user data from launch in 2005 through May 2007 including: -usernames, -salted/hashed passwords, -e-mails, -all content including private messages * Reddit source code * Internal logs * configuration files * other employee workspace files [?]
- bredren 8y agoThis is a serious breach and I'd suggest "gloss over" does not characterize Reddit's statement appropriately. Given how the report is structured, it seems like the amount of leaked data is purposefully being hidden behind red herring info about SMS 2FA that is not important to users who want to know where they stand. When this DB is leaked, there should be more than enough weak passwords to both pwn and dox many, many reddit users. Do we know the encryption scheme reddit used to encrypt their password database involved in the leak? Also, how is it that Reddit gained a head of security 2.5 months ago? Who was in charge of this prior to that date?
- Deimorz 8y ago> Do we know the encryption scheme reddit used to encrypt their password database involved in the leak? At the time of this backup, it would have been SHA1. Here's the relevant hashing code: https://github.com/reddit-archive/reddit/blob/4778b17e939e119417cc5ec25b82c4e9a65621b2/r2/r2/models/account.py#L244-L248 https://github.com/reddit-archive/reddit/blob/4778b17e939e11... Edit: reddit's confirmed this here: https://www.reddit.com/r/announcements/comments/93qnm5/we_had_a_security_incident_heres_what_you_need_to/e3f8og0/ https://www.reddit.com/r/announcements/comments/93qnm5/we_ha...
- bredren 8y agoWhile not unexpected, it is very bad for these users. This salt will do nothing to stop a cracking effort. A system with pairs of GTX 960 and GTX 1060 cards can easily check 12 billion hashes a second. This database is hosed.
- Canada 8y agoFor what reason was a decade old backup kept online for? That is insane. If they have hygine that poor I'm really worried about what other problems they have.
- ajross 8y agoGood grief. You're talking about a decade old data set. Try this: Go to your own site backup for whatever you've got, be it a personal disk backup or something you made for a customer or friend or whatnot. Now, tell me which files might contain sensitive information to third parties. I'll wait. This isn't "hygine". This is "we have a 11 year old backup mounted somewhere that we all forgot about and we honestly don't know what's in it". Yeah, it sounds dumb, but it's not reasonably avoidable by internet pontification regarding "best practices" unless your "best practices" involve eidetic memories or time machines.
- Symbiote 8y agoIt contains personal data, so it's subject to the GDPR, so the law in the EU requires those "best practices".
- ajross 8y agoNo doubt true. But the GDPR didn't provide time machines. I was arguing with the "hur hur dumb noobz" tone of the grandparent post, not with the need to store data responsibly. Doing things right is hard. Especially so when you need correct mistakes made in your startup youth.
- Canada 8y agoIt's simple. If it's a couple of years old and I haven't accessed it then it gets archived offline. Metadata about it is kept hot so I can track what I have. I might be a bit sloppy personally and have a limited amount of 4 year old stuff still internet connected but certainly not anything approaching 10 years and it's sure as hell not large archives of other people's data I have a duty to protect. There is just no excuse for that, it serves no business purpose, ancient backups that have no recovery value should not be online if they are kept at all. This incident shows an appalling lack of care by reddit technical leadership. Obviously they are not systematically tracking and reviewing the data they keep. Given this incident I would not be the least bit surprised if they have copies of this and that all over the place with no awareness or oversight.
- NVRM 8y agoIn comment from the admin: « In other news, we hired our very first Head of Security, and he started 2.5 months ago. » No comment. «Old salted and hashed passwords» This sentence mean: All hashed were readable. It also mean, if they are still needed on their servers, that they are probably still in use. It would had been easy to salt this hashes. First fix holes, then redesign...
- tluyben2 8y agoI keep telling my bank SMS 2fa is bad but they say it is not. Many banks replaced tokens with SMS unfortunately.
- 21 8y agoYour average mom & pop can't handle TOTP 2FA, they will inevitably need to reset it when changing phones.
- adrr 8y agoFOB based token generator that you can attach to your keys is pretty braindead. Some banks used to issue them but have switched to SMS/EMail.
- reitanqild 8y agoAround here it is still mandatory, that or something on the SIM card of the phone that 1) displays a popup that you can match with the bank login screen and then 2) type a separate pin code on your phone to unlock.
- adrr 8y agoI don't know any bank that supports token-based 2FA and most support both SMS and email based 2FA. Email is a terrible 2FA method since most users re-use passwords. One way to help protect you is to visit your carrier's retail store and have them turn off online access to your account and require all changes to your account to be done in person with a valid government ID. This should make it more difficult for number porting attacks but they can still sniff the SMS message when goes over the cell network. As far as I know, mobile network control messages aren't protected.
- Symbiote 8y agoSeveral British banks use Chip+PIN cards to provide a token — not necessarily for login, but for authorizing a transaction. Like this: https://c7.alamy.com/comp/CYGATP/online-banking-security-chip-and-pin-card-reader-for-authorising-transactions-CYGATP.jpg https://c7.alamy.com/comp/CYGATP/online-banking-security-chi...
- erikb 8y agoYou mean they tell us 1.5 months after the event that our emails and passwords might be compromised?
- newman8r 8y agoIf the logs contained IP addresses, they could be used to correlate multiple accounts, leading to throwaway accounts being doxxed. It doesn't sound like IP address data was compromised, but I wouldn't be surprised.
- barking 8y agoSo what's to stop a hijacker persuading the website to take off 2FA or switch you from TOTP to SMS. Seems just as possible as hijacking your phone.
- zokier 8y agoWhile everyone is piling on how SMS 2FA is oh so bad, it is worth noting that it is supposed to be the second factor here. So what happened to the first factor is the obvious question. Someone was using weak/compromised password or got social engineered would be my guesses, neither which are very good options.
- SpaethCo 8y agoThis was also my first thought when reading this. It almost makes me wonder if it was really a SMS exploit at all — when someone has the user, pass, and 2FA code, that sounds to me like the target clicked on a convincing URL and readily supplied all the things their attacker would need.
- MattSayar 8y agoGood point. I'm willing to bet it was spear phishing. Really, really effective, and I don't believe there is a solution besides education and vigilance.
- vram22 8y agoWas the notification to Reddit users about the incident, sent from noreply@redditnewsletters.com ?
- hindsightbias 8y ago>In other news, we hired our very first Head of Security, and he started 2.5 months ago. Uh huh.