21 ms·
Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
- bamboozled 4y agoSo many hacks lately, it's hard to believe that it's a coincidence ?
- corobo 4y agoIt's feasible it's related to layoffs. I dunno if it is actually related but no time like the present if everyone's on edge. Want to phish someone in 2023? Send an email saying they've been laid off. Link to an article (which requires auth to read, of course) for full details of their redundancy payout.
- Am4TIfIsER0ppos 4y agoDefinitely a coincidence and not a conspiracy of spooks working for the NSA (and similar) breaching servers in order to con you into getting a government spying device (cell phone).
- gonzo41 4y agoSecurity done well is a bit expensive and boring. Thus lots of hacks because everyone is cheap and every one has a short attention span
- kristiandupont 4y agoI don't know if you are implying that it's related to the war or something. Sadly, I am more of the belief that it's a trend. I think we will see much more of it.
- lynx23 4y ago"to the war", I smeel a singularity. Can you be more specific, to which war exactly are you refering to? https://en.wikipedia.org/wiki/List_of_ongoing_armed_conflicts https://en.wikipedia.org/wiki/List_of_ongoing_armed_conflict...
- Miraste 4y agoI suppose you're trying to make a point about the relative attention devoted to Ukraine vs other conflicts, but in this case there really is only one war with large state actors who have the motive and cyberwarfare ability for mass hacking campaigns.
- kataklasm 4y agoParent is pretty obviously referring to the 2022 Russian invasion of Ukraine, the single biggest (regarding media coverage) armed conflict right now.
- bamboozled 4y agoIt might be related to layoffs too? Maybe you're implying something :)
- bdhcuidbebe 4y agoIts just more news worthy, is all.
- bigDinosaur 4y agoYou've been downvoted, but of course it's reasonable to think 'not a coincidence'. But I'd actually say that it's not a particularly interesting observation given how many nation state backed intelligence (or even crime, assuming a difference) groups there are that do frequently hack large companies and government agencies. The pertinent thing here is that we simply don't know, and there are also plenty of boring criminal groups that also hack.
- duckmysick 4y agoSo many compared to when?
- wongarsu 4y agoThis hack was very sophisticated and targeted ("plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway") but wasn't after the easily monetizable stuff (user emails, which in combination with their most used subreddits would be very valuable for targeted spam), but instead went for data on employees and business partners. This sure seems like a setup for attacking a more valuable target.
- mikewarot 4y agoI'm not giving reddit my phone number, I get enough junk calls as it is. Edit: Reads comment by Maxburn, googles TOTP and Authy Why the heck do I need a 3rd party involved? Ugh
- Maxburn 4y agoIt's actually TOTP so I stuck that in Authy.
- deleted 4y ago[deleted]
- corobo 4y agoYou're welcome to calculate the code yourself by hand! Those apps keep track of it for you, you can use any 2FA app that supports TOTP. You could even make your own if you want. https://en.wikipedia.org/wiki/Time-based_one-time_password https://en.wikipedia.org/wiki/Time-based_one-time_password
- Maxburn 4y agoThis was my first thought after OP edit, lol, good luck doing this all yourself under the time limit. OP needs to educate themselves on 2FA methods. Google authenticator exists, but I'm trying to get google out of my life. I think Bitwarden has one. I'm only using Authy because it was among the first to offer a backup/restore solution that I stumbled on.
- dicknuckle 4y agoNo 3rd party is involved. You're localizing the 2nd factor of authentication. Google could burn down tomorrow andb cease to exist, you could still use authenticator. It's a cryptographic verification scheme, not a service. RSA was a big one that was similar. Not sure if it's still used today but there was a little hardware fob that wasn't connected to the internet or anything, the whole thing works on Time. The only thing that fob needed was a constant battery power, if it died you'd have to replace the battery and call the helpdesk to get it resynced with your account. The only thing your phone needs is a good time source like GPS or network time. I believe authenticator app works even if your phone doesn't have service. You could be on a landline in a remote region with no Internet, talking to your significant other on the other side of the world, have them log in to your account and give them the code displayed by the authenticator app and they could send that important email you forgot.
- spokeonawheel 4y agoNo.
- spokeonawheel 4y agoidk what the big deal is, my password is plenty secure, see? its hunter2
- rascul 4y agoAll I can see is *******
- TEP_Kim_Il_Sung 4y agoJust what I need: Another big social media platform connecting one of my many anonymous pseudonyms to my phone number!
- leereeves 4y agoIt's a ridiculous request. In short: "We've been hacked, so you should give us your phone number." Hilarious!
- timmywil 4y agoCould use an app for 2fa tho right?
- cristoperb 4y agoI just set up 2FA on my reddit account and at least it uses totp rather than sms.
- iLoveOncall 4y ago> Reddit recommends users set up 2FA to protect accounts How about Reddit follows their own recommendation and forces 2FA for their employees? Those kinds of attacks are 100% avoidable. Nobody with my company username and password can do ANYTHING, unless they have physical access to my computer...
- deleted 4y ago[deleted]
- dfxm12 4y agoYou used to be able to create a reddit account without an email address. If all they can get is a username and password, by and large, who cares? Just create another account and you're on your way. It's way less likely hackers will figure out your creds on other sites if they don't have an email address to act as a key. Why require email for dumb social media sites? You can talk about password recovery, but emails aren't necessarily required for that, and it could be something to opt in to. It seems like email is required to make data collection, tracking and advertising easier. It sucks that all this creepy data collection is not only an annoyance, but also makes us less secure.
- _aavaa_ 4y agoThere are legitimate reasons for requiring an email, e.g. increasing the difficult of making bots and for banned people to make a new account.
- from 4y agoPhone verification raises account creation costs to at least 20-30 cents an account (assuming you ban VOIP and only take first world countries, can be lower otherwise), email verification if you still allow yandex rambler outlook hotmail addresses raises it to a cent at max.
- lghh 4y agoReddit doesn't require an email. They use dark patterns to make it look like you do, but anywhere it asks for an email in signup can be left blank.
- greesil 4y agoSo did they store their passwords in plain text? No? Did they salt their hashes?
- indymike 4y agoIt would be nice if Reddit had an easy to find way to turn on 2FA.
- paganel 4y agoWhy would I give reddit my email or, God forbid, my phone number?
- app4soft 4y ago> TL:DR Based on our investigation so far, Reddit user passwords and accounts are safe[0] [0] https://old.reddit.com/r/reddit/comments/10y427y/we_had_a_security_incident_heres_what_we_know/ https://old.reddit.com/r/reddit/comments/10y427y/we_had_a_se...
- paulschreiber 4y agoNot requiring security keys for staff in 2023 is inexcusable.
- butz 4y ago<tinfoil-hat>Now that is an easy way to collect phone numbers from all users</tinfoil-hat>
- anigbrowl 4y ago(off topic) Davey Winder is a blast from the past, I used to hang out with him 30 years ago. Nice to see he's still surfing the tech wave.
- lakomen 4y agoGoogle should drop Reddit indexing, since it full is disinformation and agenda
- timbit42 4y agoIf they did that, their search engine would go from 10% useful to 0% useful.
- berniedurfee 4y agoThis trend is going to get much worse before it gets better. Buckle up!
- 0___0 4y agohttps://old.reddit.com/r/reddit/comments/10y427y/we_had_a_security_incident_heres_what_we_know/ https://old.reddit.com/r/reddit/comments/10y427y/we_had_a_se...
- welder 4y agoThis is the original source, and way more informative than the Forbes article. Please change the post to link here.
- jaclaz 4y ago>On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens. It doesn't seem to me that much sophisticated, rather "normal", unless they are omitting some relevant details, it sounds a lot like "Action needed urgently, click here to login to ...".
- marginalia_nu 4y agoThe sophisticated aspect of these types of attacks typically isn't in the technical aspects, but the social engineering involved. It usually involves meticulous research on the target, what and who they work with, and have crafted an email that plausibly looks and sounds like an internal email, that talks about company stuff in company language, mentions coworkers and so on. Add a note of urgency, make it someone who has discovered something isn't right, there's an urgent technical issue or the company or money is missing from the accounts or something, or perhaps it was dressed up as a memo announcing layoffs at reddit. If it's an urgent "threat" you tend to tunnel vision quite hard. The result is very far removed from how your typical spam emails tend to look.
- sillysaurusx 4y agoYep. We had a charming English fellow at NCC Group in charge of doing this for a living. He had it down to a science. Everything from the phrasing to the phishing.
- say_it_as_it_is 4y agoThe hacker stole the source code and shortly thereafter died of radiation poisoning
- webdoodle 4y agoI'd love to see the source code and compare it to the open source code, before they went closed source. I bet there are some real fun things in there, from an attack surface standpoint.
- deleted 4y ago[deleted]
- jhgg 4y agoAnd this is why we should all adopt webuathn, and get rid of totp based 2fa. This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.
- daneel_w 4y agoAre you really suggesting that a billion netizens should stop using TOTP on their smartphones and go buy another hardware device?
- 0xCMP 4y agoBoth latest versions of Android and iOS support passkeys plus support on Chrome/Brave/Edge/Safari. While not as secure or convenient as a security key for initially logging in there is no need for a new device in many cases. besides the fact that the webauthn yubikey is $20 vs $50-70 for it's more popular and well known versions.
- xaduha 4y ago> And this is why we should all adopt webuathn, and get rid of totp based 2fa. I'd be glad to personally, but if a site supports 2fa at all, then it's mostly likely TOTP. And some require TOTP first and allow webauth only in addition to it.
- rvz 4y agoHilarious to see that even companies like Reddit still do not take security seriously despite being around longer than most internet companies. If this was Meta, or Twitter that got breached via there would be outrage everywhere as to why employees did not use hardware keys.
- 7ewis 4y agoIs this similar to how hardware wallets show the true addresses on their displays?
- Avamander 4y ago
- huhtenberg 4y agoEarlier thread on this - https://news.ycombinator.com/item?id=34731407 https://news.ycombinator.com/item?id=34731407
- devnullbrain 4y ago>While Reddit also suggests that updating passwords every couple of months is a good idea, as well as using a password manager, that's not advice most security professionals would currently condone. Changing passwords regularly, that is, not password manager usage. What inelegant phrasing. Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for your profile, there's no benefit to the user to have an old account with lots of karma. Just keep re-rolling with strong random passwords and you have nothing to lose.
- MildlySerious 4y agoThe last time I tried to change the password of a reddit account I lost access to it. I attempted to change the password, got an error saying something went wrong. I figured I'd try again later. so I also didn't save the newly generated password. Got logged out, and couldn't log back in with the old password. And there's no way that I know of to contact anyone at reddit to try and get help.
- djbusby 4y agoTry the Forgot Password link?
- MildlySerious 4y agoThe email provider that account was tied to doesn't exist anymore, and the domain is taken. I didn't notice until after it happened, so I am not putting all the blame on reddit. It's more of a string of unlucky circumstances. Who knows if I could have even changed it without access to the email account, anyway. Fun fact: Reddit for the longest time didn't require an email address to create accounts.
- ridgered4 4y agoReddit still doesn't require an email to create accounts, even if it now heavily implies it does. Just click next without entering one.
- bmitc 4y agoKind of weird posting this here. Hacker News provides little ability to manage an account, much less setup 2FA.
- mkr-hn 4y agoWhat's weird about posting news of a breach of a major site on a news aggregator?
- bmitc 4y agoJust that Hacker News doesn't provide the protections being discussed given the also discussed assumption that sites will be breached at some point.
- notacoward 4y agoNo 2FA, no muting/blocking or following, non-transparent moderation using long-discredited techniques, security through obscurity. For a site devoted to discussing the latest tech, the site itself is curiously stuck in the 90s and the grognards like it that way.
- Arnavion 4y ago>no muting/blocking https://news.ycombinator.com/item?id=33365189 https://news.ycombinator.com/item?id=33365189
- Shaggy2000 4y agoAt least it has kept the nice 90s atmosphere too. Generally HN users are high value targets - how little spam or trolling there is to be found here by outsiders is incredible considering the lack of safeguards you mentioned.
- bawolff 4y agoThe setup 2FA advice is kind of weird. I mean its fine in general, but it was an employee who was breached not a user, and there is no indication that the attackers got account data.
- deleted 4y ago[deleted]
- wongarsu 4y agoAnd apparently the phishing attack phished both password and 2FA for getting into the intranet. So whatever 2FA they used internally didn't help.
- ridgered4 4y agoYeah, but every crisis is an opportunity and this is an opportunity to scare people into coughing up PII that advertisers love so much.
- Havoc 4y ago>Reddit also stated that there was no evidence the systems used to run Reddit itself and store the majority of data, the primary production systems in other words, was breached. Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss".
- pgrote 4y ago>Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss". After what lastpass did I cannot trust any self reporting.
- remus 4y agoI think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?
- Dalewyn 4y agoSpecifically with regards to Reddit, spez is now known to have edited the database holding comments without making that fact known in any way. So absolutely nothing coming out of Reddit should be trusted or quoted.
- piva00 4y agoYup, I don't trust spez, I don't trust reddit's management (even less after the Chinese investments). This is a case to be cynical, reddit is not transparent and their leadership has been riddled with stupid politics, including the whole weird saga they did with Ellen Pao.
- sillysaurusx 4y agoEhh. Spez being human makes me inclined to trust him a little more. I’m neutral in politics, but editing those comments was objectively funny. Stupid, yes — astonishingly so. But it finally broke the illusion that users own their comments. That’s all it ever was: an illusion. I don’t trust authority in general. But given the choice between spez and musk, I’d take spez any day. He’s at least not hopped up on drugs running around making crazy decisions. And in terms of Reddit’s trustworthiness, it makes even less sense that editing comments would be of any consequence. If they detect a hacker and have the logs to prove it, they’d gain nothing by modifying the logs. And if they don’t, they gain nothing by fabricating the logs. So it seems reasonable to conclude that they just don’t have the logs. Which is also reasonable. When I was hacking into systems at Matasano, it always made me uncomfortable just how undetectable I was. I wasn’t trying particularly hard to conceal myself, but a few well-chosen bash incantations and opening things in vi means all anyone sees is that a vi process is running.