6 ms·
We [Reddit] had a security incident. Here’s what we know
- mancerayder 4y agoI got a message this morning that I was accepted into a sub that I never heard about, as if I had applied (but I didn't). It seemed to be a notification, not a message. I don't see it now. I'm guessing it's related to the hack, but it's not obvious what the scam or purpose was.
- seydor 4y ago> They gained access to some internal documents, code, and some internal business systems. nothing important
- TechBro8615 4y agoFortunately the hacker was fruitless in their effort to delete the mobile site and add a permanent redirect and HPKP pinning to old.reddit.com
- yellowapple 4y agoFortunately?
- toomuchtodo 4y ago/s
- wolongong942 4y agoThis is how most initial disclosures go, then a few weeks on the third-party security firm investigating notifies them they got completely pwned.
- PoignardAzur 4y ago> Exposure included limited contact information for (currently hundreds of) company contacts and employees (current and former), as well as limited advertiser information. Based on several days of initial investigation by security, engineering, and data science (and friends!), we have no evidence to suggest that any of your non-public data has been accessed, or that Reddit’s information has been published or distributed online. Reassuring if true.
- mzs 4y ago>After successfully obtaining a single employee’s credentials, the attacker gained access to some internal docs, code, as well as some internal dashboards and business systems. Together with the contact info that could be basis for the next attack.
- millzlane 4y agoAdded to the list of things that they have bungled.
- favaq 4y agoReddit stopped publishing their source code a long time ago, so I hope the hackers publish whatever they took.
- webdoodle 4y agoAlong with murdering there warrant canary, and repeated attempts to force people to there new crap web design or privacy invasive app.
- uPiDmTXL 4y agoNo, Reddit. Phising is not a sophisticated attack. Working in the cyber industry, it's so frustrating to see companies claim that they were done over by "sophisticated attacks" like phising! I understand it from the PR points angle, but I always cringe. I hope others see through it too. I guess we'll wait to see what they actually stole when they post the ransom.
- blitzar 4y agoIt is almost as annoying as when hack / breach turns out to be someone scrapped every profile on the site.
- sneak 4y agoRight? This is completely eliminated by using U2F tokens. If you aren't using hardware auth to authenticate to corporate internal resources, your IT department is negligent or incompetent or both. I literally have advanced protection turned on for a small four person single location retail operation I am involved with, simply for the PII of a few hundred people that they have to handle. The little USB/NFC fobs are $15. There is no excuse other than incompetence.
- NoPicklez 4y agoUsing MFA is absolutely a must. But not using hardware based 2FA doesn't make the IT department, completely negligent or incompetent. Most companies I know if they are using MFA are using Microsoft Authenticator soft tokens through their enterprise 365 environments.
- TacticalCoder 4y agoFrom TFA: > in an attempt to steal credentials and second-factor tokens. > > After successfully obtaining a single employee’s credentials So was the attempt to steal second-factor successful or was it the account of an employee without 2FA that was compromised? Because then... On the page as to how to set up 2FA linked from TFA: https://reddithelp.com/hc/en-us/articles/360043470031-What-is-two-factor-authentication-and-how-do-I-set-it-up- https://reddithelp.com/hc/en-us/articles/360043470031-What-i... > "After setup, you may be asked to log out and log back in to your account. Moving forward, you’ll need to enter a 6-digit code from your authenticator app every time you log in to Reddit." There's 2FA and 2FA. TOTP like Google Authenticator giving these six digits are easy to phish. I much prefer FIDO(2) devices and the webauthn protocol (Chrome doesn't even allow U2F anymore but webauthn is backward compatible with old security keys), especially when the device uses a different method for registering a service the first time and for then authenticating to that service (for example by using a different PIN for registering and for authenticating or by displaying on the device itself if you're registering or authenticating).
- lawgimenez 4y agoCrazy with all the security implemented, all it takes is just a phishing email.
- ehPReth 4y agoMore places really really need to use [essentially] unphishable 2fa (security keys) and make that the sole method of 2fa except maybe in a break-glass case. but even them, you can have multiple security keys including backup ones
- deafpolygon 4y agoI find it funny that while I'm a regular visitor to Reddit, I only find out about the attack on HN.
- mkr-hn 4y agoSame, except I found out on Mastodon and posted it to HN.
- Zeyka 4y agoWow, old reddit is so ugly and outdated
- MathMonkeyMan 4y agoIt's compact and nag-free.
- prox 4y agoAlso doesn’t crash my browser (mobile) -and no don’t want to use any apps.