6 ms·
Interesting that the data accessed was very specifically only limited to: * A complete copy of an old database backup containing very early Reddit user data --
by packetized 8y ago
Interesting that the data accessed was very specifically only limited to:
* A complete copy of an old database backup containing very early Reddit user data -- from the site’s launch in 2005 through May 2007
* Logs containing the email digests we sent between June 3 and June 17, 2018
Also of note:
"Already having our primary access points for code and infrastructure behind strong authentication requiring two factor authentication (2FA), we learned that SMS-based authentication is not nearly as secure as we would hope, and the main attack was via SMS intercept."
If this doesn't put the nail in the coffin of SMS-based 2FA, I'm not sure what will.
- SteveNuts 8y agoI thought I had heard that Reddit was using a non-salted or non-hashed password in the early days?
- tylerhou 8y agoThey probably deleted those backups when they realized how that was bad.
- samstave 8y ago>"Can you txt me the old mysql root pw to the reddit DB? Need to check something, thanks - Alexis."
- Deimorz 8y agoThat was about 6 months before the stolen backup (December 2006): https://www.reddit.com/r/reddit.com/comments/usqe/reddits_streak_of_bad_luck_continues/cuugl/?context=3 https://www.reddit.com/r/reddit.com/comments/usqe/reddits_st...
- mtgx 8y agoIf that's what Reddit's security team was thinking by mid-2018, then Reddit security is in bad shape. NIST recommended the deprecation of SMS 2FA two years ago. When NIST recommends the deprecation of a protocol you know you should've already gotten rid of it five years earlier, not keep it around for another five years. The sooner more companies start supporting U2F and WebAuthn, the sooner more people will start buying and using hardware security keys.
- aroch 8y agoI don't think it was up to Reddit. Some providers offer no way to do MFA without mandatory SMS involvement in some way -- either primary delivery is by SMS or you can "reset" / get back up codes via SMS.
- dbg31415 8y agoLooking at you, LinkedIn. Microsoft has been lax on this.
- robohoe 8y agoMany major banks do that too.
- hackinthebochs 8y agoI've been interested in enabling MFA on my google account, but with no obvious way to bypass/disable SMS, I don't even bother.
- wolf550e 8y agoLook at step 18 in this guide: https://techsolidarity.org/resources/security_key_gmail.htm https://techsolidarity.org/resources/security_key_gmail.htm
- Alex3917 8y agoBecause of cases like this, it's also the admin's responsibility to have their wireless provider put a security pin and a Do Not Port order on their account. Sometimes reps will ignore this and port people's accounts anyway, but it's still negligent not take this precaution.
- aroch 8y agoPhone company reps are notorious for ignoring any and all such notes on accounts, we can't know for sure if Reddit had this in place but it probably wouldn't be much of a hurdle
- JoblessWonder 8y agoThat is not what data it was limited to at all. That is the data they are highlighting because it affects their users the most. Here is the list of what of what they are saying they got access to: https://news.ycombinator.com/item?id=17665254 https://news.ycombinator.com/item?id=17665254
- mikestew 8y agowe learned that SMS-based authentication is not nearly as secure as we would hope Yeesh, what is going on with their security team over there? Years ago it was "oh, now we realize why everyone was saying that storing passwords in plaintext is a bad idea." Now it's "oh, now we realize what a bad idea SMS auth is." So what is Reddit doing today that you and I would think, "of course, no one does that anymore 'cuz 'duh'." but they think, "nah, it's still okay."?
- tptacek 8y agoIt sounds like Reddit just recently hired security. It's not at all unusual for companies of Reddit's size not to have a security team; the only thing that makes them noteworthy in that regard is how old the company is. If your expectation is that most of the companies you've worked with or availed yourself of have dedicated security teams, revise your expectations sharply downwards.
- mikestew 8y agoIt's not at all unusual for companies of Reddit's size not to have a security team; Well, by "security team" I meant "people that should know better". I mean, raise your hand if you knew even ten years ago what a bad idea it was to store passwords in plaintext. Okay, now keep your hand up if you're job role includes the words "security team". Hmm, not a lot of hands left. You don't need a dedicated security team to figure out that some folks, including the CEO, shouldn't be let anywhere near the database nor making design decisions.
- koube 8y agoReddit had a security team, they just haven't had the position "Head of Security" until now[0]. They did have a policy of using TOTP but couldn't enforce it on certain providers (applications?) [1]. [0]: https://old.reddit.com/r/announcements/comments/93qnm5/we_had_a_security_incident_heres_what_you_need_to/e3f8fza/?context=1 https://old.reddit.com/r/announcements/comments/93qnm5/we_ha... [1]: https://old.reddit.com/r/announcements/comments/93qnm5/we_had_a_security_incident_heres_what_you_need_to/e3f79r9/?context=1 https://old.reddit.com/r/announcements/comments/93qnm5/we_ha...
- robk 8y agoHas anyone leaked this? I'm more interested in unlocking my eponymous account I created 13 years ago then promptly lost access to without an email attached :(
- ziftface 8y agoHow would that help you? Brute force a bunch of your old passwords?
- anowlcalledjosh 8y agoThere are a couple of comments on the linked thread suggesting that someone may be using it (scam emails containing people's old reddit passwords).
- BOBOTWINSTON 8y agoCan you or someone else explain/link to me the basics of why SMS-based 2FA is so terrible? I've never really heard the sentiment before, but it appears to be common knowledge.
- nodesocket 8y agoThis seems to indicate a level of sophistication behind traditional hacking skills. How did they get the phone number to know which carrier to contact to socially engineer? Also, I am not sure I understand: > we suspect weaknesses inherent to SMS-based 2FA to be the root cause of this incident It seems that optaining employee login credentials was the root cause, and bypassing 2FA was the second hurdle but not the root cause.
- freeone3000 8y agoYou don't need to know the carrier, just the number. Talk to a carrier in the country and ask to port "your" number to a new plan. Most salespeople would have no problem ignoring security for a sale.
- c2h5oh 8y ago1. It's too easy to get a duplicate sim card 2. MITM for SMS is not hard if you can get close and requires <$500 in hardware
- DennisAleynikov 8y agoTOTP clients cannot be intercepted where as sms tokens can be compromised in a variety of ways.
- whitepoplar 8y agoTOTP tokens can absolutely be intercepted. A MITM attack can work like this: 1) User inputs username and pw into spurious site. 2) Spurious site prompts for the user's TOTP token. 3) Spurious site proceeds to immediately log in to the real site w/ username, pw, and valid TOTP token. 4) Bad guys get an HTTP session cookie which for many sites lasts practically indefinitely.