6 ms·
>Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss". After what lastpass did I cannot trust any self reporting.
by pgrote 4y ago
>Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss".
After what lastpass did I cannot trust any self reporting.
- remus 4y agoI think this is overly pessimistic. While there's definitely shady companies out there who will say this while having very poor security practices, it's tricky demonstrating that something didn't happen. Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?
- Dalewyn 4y agoSpecifically with regards to Reddit, spez is now known to have edited the database holding comments without making that fact known in any way. So absolutely nothing coming out of Reddit should be trusted or quoted.
- piva00 4y agoYup, I don't trust spez, I don't trust reddit's management (even less after the Chinese investments). This is a case to be cynical, reddit is not transparent and their leadership has been riddled with stupid politics, including the whole weird saga they did with Ellen Pao.
- sillysaurusx 4y agoEhh. Spez being human makes me inclined to trust him a little more. I’m neutral in politics, but editing those comments was objectively funny. Stupid, yes — astonishingly so. But it finally broke the illusion that users own their comments. That’s all it ever was: an illusion. I don’t trust authority in general. But given the choice between spez and musk, I’d take spez any day. He’s at least not hopped up on drugs running around making crazy decisions. And in terms of Reddit’s trustworthiness, it makes even less sense that editing comments would be of any consequence. If they detect a hacker and have the logs to prove it, they’d gain nothing by modifying the logs. And if they don’t, they gain nothing by fabricating the logs. So it seems reasonable to conclude that they just don’t have the logs. Which is also reasonable. When I was hacking into systems at Matasano, it always made me uncomfortable just how undetectable I was. I wasn’t trying particularly hard to conceal myself, but a few well-chosen bash incantations and opening things in vi means all anyone sees is that a vi process is running.
- raspberry1337 4y agoI'd take the devil over musk! At least he is not hopped up on drugs and running around making crazy bad decisions
- nkozyra 4y agoGetting some Poe's Law vibes here.
- malfist 4y ago> Spez being human makes me inclined to trust him a little more You realize what you're saying right? You're saying someone's actions that breach trust makes you trust them more? Actions speak louder than words, if someone is showing you that you can't trust them, you don't decide that you're going to trust them more!
- 7speter 4y ago> But it finally broke the illusion that users own their comments. That’s all it ever was: an illusion. Makes me wonder about all what else about reddit is an “illusion”
- LarryMullins 4y agoSo basically "he lied to me, lying is a human behavior, so I trust him." Wew.
- qingdao99 4y agoHow hard is it to resist directly editing user data on your site? It's a pretty clear-cut case of abuse of power.
- doubled112 4y agoI've always strongly believed in "ignorance is bliss", and "if somebody wants me to know something they will tell me". The idea of snooping barely crosses my mind, let alone editing. Maybe it is different because Reddit comments are intended to be public.
- pokepim 4y ago[dead]
- gruez 4y ago>Yup, I don't trust spez, I don't trust reddit's management (even less after the Chinese investments) I think you (and many other people) are overestimating how much chinese influence there is on reddit, considering that they have < 10% stake (according to wikipedia they "led" a funding round that raised 10% of valuation, and since then there was another funding round that presumably diluted their stake).
- corbulo 4y agoAbove 0 is too much. Could 10% buy you mod spot over a large major subreddit? Maybe get reddit to look the other way for your astroturf campaigns? Reddit is just as shady with its Overton Window manipulation tactics & strategies as Twitter has been exposed to be. Remember when Ghislaine Maxwell was revealed as a mod of r/Worldnews? I'm convinced any relevant PR company worth its salt has infiltrated moderator teams of every major subreddit. Whats stopping them? Or anyone else for that matter
- gruez 4y ago> Above 0 is too much. Could 10% buy you mod spot over a large major subreddit? Maybe get reddit to look the other way for your astroturf campaigns? That's... not how fundraising rounds usually work.
- corbulo 4y agoThats how ownership and influence works. You think China is buying 10% because of how profitable reddit is?
- gruez 4y agoI can ask the same for the other investors. >in 2005. Condé Nast Publications acquired the site in October 2006. In 2011, Reddit became an independent subsidiary of Condé Nast's parent company, Advance Publications.[11] In October 2014, Reddit raised $50 million in a funding round led by Sam Altman and including investors Marc Andreessen, Peter Thiel, Ron Conway, Snoop Dogg, and Jared Leto.[12] Their investment valued the company at $500 million then.[13][14] In July 2017, Reddit raised $200 million for a $1.8 billion valuation, with Advance Publications remaining the majority stakeholder.[15] In February 2019, a $300 million funding round led by Tencent brought the company's valuation to $3 billion.[16] In August 2021, a $700 million funding round led by Fidelity Investments raised that valuation to over $10 billion.[4] What type of shadowy agenda are entities like Jared Leto or Fidelity Investments trying to advance? Or should we assume that they're acting altruistically because they're not Chinese?
- deleted 4y ago[deleted]
- boppo1 4y agoReddit is a shady company. Doing everything they can on the browser experience including interrupting me while I'm typing to try to shunt me over to the app is shady. I don't want the app. I have clicked 'continue in browser' at least 200 times. My preference ought to be clear and recorded by now. I'd stop visiting altogether if I didn't have a general problem with compulsive browsing.
- stefantalpalaru 4y ago[dead]
- seanw444 4y agoSounds like a job for uBlock Origin. Just block the element.
- jungledeuce 4y agoSure, shady companies exist. And you shouldn’t trust shady companies to self report. But… you already know that, it’s in the name! “Shady”. So I think the idea that you should never trust self reporting is indeed an over reaction. However, having been at (what I deemed) non-shady companies, there’s still the very human desire to downplay as much as is reasonable. Shady companies overstep reasonability on purpose.
- throwaway2056 4y agoWhy use reddit's official app? There are several decent opensource apps. (BTW, you can use libredd.it to just read-only reddit)
- tstrimple 4y agoThanks I may look into libredd.it. I intentionally removed the 3rd party apps because they were too good and enabled me to doom scroll too efficiently. I used the website in part because it's a painful experience which will keep me from staying on there too long. A read-only version may help that even more because then I'd have to switch to the full website if I wanted to rage post about how someone is wrong on the internet.
- PuppyTailWags 4y agoThere's no regulation with teeth to hold companies accountable for breaches, by and large, and therefore this is exactly the appropriate amount of pessimism.
- LarryMullins 4y agoNever trust any company with a PR department at all, they're all opportunistic liars who's priority is limited damage to the company, not telling the truth. They only do the latter when they think it will have the effect of the former. Really, don't trust corporations at all. Even if the circumstances of life force you to do business with them and hope nothing goes wrong, that's no reason to ever trust them. The bigger the corporation the more true this is, since the structure of corporations makes people feel less personally responsible for the bad things they might do to you, like lying to you about the scope of a data breach. The "just following orders" mentality allows workers to do things they'd never otherwise do to you, and that's just one example. If any sort of business is safe to trust, it's the one-man-shop owner-operator kind of business and you can only trust those guys insofar as you can trust any other person at all. In that case you have to consider it on a case-by-case basis.
- bithead 4y agoNot trusting corporations is possibly the best advice available. I used to work for the largest insurer on Earth, a "health insurance" company. They quit paying for my insulin, which I need to live. They have enough lawyers they could just pile them physically on my house and suffocate me. They then laid me off due to age. My group of layoffs was 155, and of those 17 were under 40. They did give me a pile of cash not to sue - which I took like the opportunistic bastard I am in the end.
- hn_go_brrrrr 4y ago> Never trust any company with a PR department at all So you're saying we should trust Twitter? :)
- LarryMullins 4y agoHeh, but what is Elon, if not a one-man PR department?
- dcow 4y agoOne man department. Such praise.
- mannykannot 4y agoThe difficulty of verifying the claim is not somehow a justification for making it - quite the opposite, in fact. As it happens, there is something that would help, though if and only if they can do it: Explain what evidence they would have if the breach had occurred.
- genmud 4y agoHaving worked professionally in security and incident response for 15+ years now, this take is not just spot on, but might be overly optimistic. I can't tell you how many large, well known companies I have worked with that either intentionally mislead, downplay, obscure or straight up lie in these types of notifications. I have had legal teams tell me that they don't have to notify customers of a breach because an event happened on their test/dev systems, or a developer was compromised and not their actual service. I have had companies intentionally not give information (like what an attacker was able to exfiltrate from a particular set of customers) that would been extremely helpful to inform or assess their risk. Instead they put out a generic "sophisticated attacker compromised our system, but no credentials or PII from our application were stolen".
- fsociety 4y agoHaving talked with some folks who have been around the block in their career.. it is a pessimistic statement but sadly it is often true.
- suslik 4y agoMaybe I missed that - did they misreport anything? I know they royally fucked up, put they didn't really hide the fact that the (encrypted) vault data was stolen.
- TallGuyShort 4y agoAfter their initial announcement, they updated the same post after months as they had since discovered it was worse. And in some cases it turns out the vault data was not as encrypted as they had ever said. Here's one of the better write-ups I've seen: https://palant.info/2022/12/26/whats-in-a-pr-statement-lastpass-breach-explained/ https://palant.info/2022/12/26/whats-in-a-pr-statement-lastp...