Reddit Confirms It Was Hacked–Recommends Users Set Up 2FA
forbes.com
forbes.com
Ah the classic PR blur. Could mean anything from "all good" to "we don't log - ignorance is bliss".
After what lastpass did I cannot trust any self reporting.
Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?
So absolutely nothing coming out of Reddit should be trusted or quoted.
I don’t trust authority in general. But given the choice between spez and musk, I’d take spez any day. He’s at least not hopped up on drugs running around making crazy decisions.
And in terms of Reddit’s trustworthiness, it makes even less sense that editing comments would be of any consequence. If they detect a hacker and have the logs to prove it, they’d gain nothing by modifying the logs. And if they don’t, they gain nothing by fabricating the logs. So it seems reasonable to conclude that they just don’t have the logs.
Which is also reasonable. When I was hacking into systems at Matasano, it always made me uncomfortable just how undetectable I was. I wasn’t trying particularly hard to conceal myself, but a few well-chosen bash incantations and opening things in vi means all anyone sees is that a vi process is running.
You realize what you're saying right? You're saying someone's actions that breach trust makes you trust them more?
Actions speak louder than words, if someone is showing you that you can't trust them, you don't decide that you're going to trust them more!
Makes me wonder about all what else about reddit is an “illusion”
Wew.
The idea of snooping barely crosses my mind, let alone editing.
Maybe it is different because Reddit comments are intended to be public.
Then again, so did my last boss till i got to know him better
I think you (and many other people) are overestimating how much chinese influence there is on reddit, considering that they have < 10% stake (according to wikipedia they "led" a funding round that raised 10% of valuation, and since then there was another funding round that presumably diluted their stake).
Reddit is just as shady with its Overton Window manipulation tactics & strategies as Twitter has been exposed to be. Remember when Ghislaine Maxwell was revealed as a mod of r/Worldnews? I'm convinced any relevant PR company worth its salt has infiltrated moderator teams of every major subreddit. Whats stopping them? Or anyone else for that matter
That's... not how fundraising rounds usually work.
>in 2005. Condé Nast Publications acquired the site in October 2006. In 2011, Reddit became an independent subsidiary of Condé Nast's parent company, Advance Publications.[11] In October 2014, Reddit raised $50 million in a funding round led by Sam Altman and including investors Marc Andreessen, Peter Thiel, Ron Conway, Snoop Dogg, and Jared Leto.[12] Their investment valued the company at $500 million then.[13][14] In July 2017, Reddit raised $200 million for a $1.8 billion valuation, with Advance Publications remaining the majority stakeholder.[15] In February 2019, a $300 million funding round led by Tencent brought the company's valuation to $3 billion.[16] In August 2021, a $700 million funding round led by Fidelity Investments raised that valuation to over $10 billion.[4]
What type of shadowy agenda are entities like Jared Leto or Fidelity Investments trying to advance? Or should we assume that they're acting altruistically because they're not Chinese?
None, they might just really believe that Reddit might be profitable one day and they want a share of the pie. Snoop Dogg also invested in Klarna, for example.
On the other hand I have lots of reservations about the motivation of the likes of Sam Altman and Peter Thiel in this, Marc Andreesen is not such a wildcard, might be just stupid with money as the latest plays of a16z seems to making them be.
I'd stop visiting altogether if I didn't have a general problem with compulsive browsing.
However, having been at (what I deemed) non-shady companies, there’s still the very human desire to downplay as much as is reasonable. Shady companies overstep reasonability on purpose.
Really, don't trust corporations at all. Even if the circumstances of life force you to do business with them and hope nothing goes wrong, that's no reason to ever trust them. The bigger the corporation the more true this is, since the structure of corporations makes people feel less personally responsible for the bad things they might do to you, like lying to you about the scope of a data breach. The "just following orders" mentality allows workers to do things they'd never otherwise do to you, and that's just one example.
If any sort of business is safe to trust, it's the one-man-shop owner-operator kind of business and you can only trust those guys insofar as you can trust any other person at all. In that case you have to consider it on a case-by-case basis.
So you're saying we should trust Twitter? :)
As it happens, there is something that would help, though if and only if they can do it: Explain what evidence they would have if the breach had occurred.
I can't tell you how many large, well known companies I have worked with that either intentionally mislead, downplay, obscure or straight up lie in these types of notifications.
I have had legal teams tell me that they don't have to notify customers of a breach because an event happened on their test/dev systems, or a developer was compromised and not their actual service.
I have had companies intentionally not give information (like what an attacker was able to exfiltrate from a particular set of customers) that would been extremely helpful to inform or assess their risk. Instead they put out a generic "sophisticated attacker compromised our system, but no credentials or PII from our application were stolen".
Reddit also said they haven't seen the data advertised at data-selling sites.
What inelegant phrasing.
Another option is to treat online accounts as throwaway wherever possible. As much as Reddit would like to sell you gizmos for your profile, there's no benefit to the user to have an old account with lots of karma. Just keep re-rolling with strong random passwords and you have nothing to lose.
It's a bit funny since alias was meant to hide who you were or at least make ire less formal than a person's full name. Then I go and use my name for an alias!
Decades later and it's still my main account and I often need to either switch accounts to the one with my real name or embarassingly ask people to invite my nickname account to various shared documents, calendars, etc. No way to migrate my YouTube channel either…
Having a disconnected online entity means less-than-pleasant jackasses can't pull something from years or even decades ago, put it out of context, and proceed to troll your life.
Not putting your real life identity on public display for the world to see means you maintain tighter control over how, when, and where your information gets out. Do you really need your real name, face, place of employment, telephone number, email address (with your name in it), and maybe even your home address publicized? More than likely you don't.
Having online identities disconnected from real life means you can use them to safeguard your actually really-fucking-important real life things. Your bank account? Use an email that uses a nickname instead of your real name so any would be hackers have to second guess your email too.
Worst comes to shove and shit hits the fan, you can throw away an online identity and make another one. You can't throw away your real name and face.
There are nothing but benefits by keeping your online and real life identities separate, and if you ask me it's one of the first steps to being truly internet literate.
Presumably, a Reddit leak means even more opportunity to unmask (dox) users who have responded truthfully to threads that say things like "what's the worst thing you ever did". Lots of blackmail opportunities.
All outbound clicks from the site are redirected via out.reddit.com which ties click activity to an individual (username / IP / device fingerprint based). This can only be blocked with aggressive old.reddit script blocking which breaks portions of the site.
The outbound click data is used for profiling and interest based advertising, but the data can be much worse than simply linking comments to identity.
They also tie IP/identity to individuals to serve relevant ads and this is the push to get people installing reddit on phones, where deviceIDs is an easy UUID for ads.
https://github.com/moby/moby/blob/master/pkg/namesgenerator/...
Some subs have a minimum amount age or karma requirement to post. This is ostensibly to combat bots.
These days I don't even log into reddit. After wide spread banning from subreddits for random reasons it's not worthwhile. I'll keep browsing old.red as long as it exists but if it goes away I'll DNS block all reddit at the router.
I don't need to know who you actually are, but over time interacting with other people here I've started to get a feel for several hundred accounts. This makes HN more pleasant because I have some sense of what sort of person they are to talk with, and what is likely to go well or poorly. When there have been subreddits I was really into, I would start to get a sense for the more prolific commenters there too.
If I regularly attended some sort of social club and it was common for people to replace their faces I would find it frustrating as well.
Personally I value the web as a knowledge store that persists.
Use a non-logged chat service if you want a transient medium.
Instead of acting like a bullshit filter, upvote/downvote tends to act like a dog getting petted for echoing back a popular opinion to the group or the dog being scolded for echoing an unpopular opinion. Dogs like to get pats on the head and don't like being yelled at.
It is really one of the dumbest ideas of the last 30 years. Total disregard for human behavior and total disregard for the truth considering how often the truth is an unpopular opinion at a specific moment in time.
Throwaway accounts to me are a small protest to this ridiculous system.
I wonder how many people have that reflex. I usually only notice usernames when mentioned by others.
My kingdom for an ignore-list.
Nowhere else can you have in-depth technical discussions about the implications of Humean Projectivism on p2p network architecture, with a cybernetic dragonfly, a flying squirrel, and with distracting interjections by a literal fantasy troll. A bit of personal QA/QC, and individual filtering options, are all you need. Anything else is just censorious control of the narrative.
You wanna talk about how humans work - strangers in real life also don't just walk up to you and start talking about Reddit account security out of the blue! We also don't trust a talking head on TV or on the radio just because they're human. Relationships are built over time & higher trust has to be earned. Even if you're referring to the fact that most of us probably live in a relatively high trust society, that doesn't mean we trust our neighbors' opinions on strong passwords (or whatever) just because we trust them as our neighbor!
Ideas do not exist without context. Arguably the context is more essential than individual ideas. Judging ideas without context is not a useful exercise. It's easy to fall into a local minimum that's actually quite bad. Eugenics is a common example. Eliminating genetic disease sounds great as long as you don't have the context of genocide or humanism.
When it comes to political discussions or any kind of politically biased graphic, particularly if it is something I disagree with, I assume it is astroturf/agitprop. When misinformation and propaganda are mainstream, why can I trust some random account on the internet for facts?
Tech is certainly different.
I know that there's a difference between spinning up a new account every few months, and for every reply. But long-term relationships in communities matter.
When millionaires, state actors, politicians, corporations, etc, switch from using bot farms to manipulate public opinion to paying influencers to do the same thing, people whose identity is inherently valued and trusted, you end up in the same position as we're currently in.
Secondly, it's easy to farm up these internet points and sell the account to somebody else who's keen on exploiting the tendency of people like you to think that the internet points confer trustworthiness.
We need some way of verifying that a real human is on the other end, but we don't necessarily need to know who that person is.
I attempted to change the password, got an error saying something went wrong. I figured I'd try again later. so I also didn't save the newly generated password.
Got logged out, and couldn't log back in with the old password.
And there's no way that I know of to contact anyone at reddit to try and get help.
Fun fact: Reddit for the longest time didn't require an email address to create accounts.
<Reddit hacked>
"Huh, I guess I better change my password."
<Recommends TFA>
"Hmm, give reddit my phone number .... no."
I used to think so until I decided to reroll my old account into a new one, and it was such a pain re-subscribing to all my subreddits again.
I reroll every time I am banned from a sub I like because that sub notices I play in other subs - that whole “thing” is horseshit to me. So I just reroll to get around that autoban bot.
It gives you a chance to re-evaluate what is actually giving you value. It’s like spring cleaning.
It’s the same reason I enjoy setting up a new or freshly reformatted phone or laptop. Feels good to clean out the cobwebs.
works for me everywhere except HN, because of the silly requirement of 500 karma to be able to downvote.
SMS is no longer recommended as a means of 2FA, as it's very vulnerable. Some sites still rely on it, unfortunately. However, it appears Reddit does support TOTP.
I (used to, i guess) do the same. I must have 40 accounts in total over the years. Funny enough i didn't even make a strong password - a stupidly bad one, unique for each account, actually. I had almost hoped it was hacked because it would be interesting to be hacked and not care.
Just reminded me of my first "wtf." A journalist for our local university wrote a review for the movie "Hustlers" where they justified sexually assaulting and robbing men in New York because "men in New York were responsible for the 2008 financial crisis." All without missing a beat. Can't believe what passes these days.
Reddit's own phrasing is much better:
Since we’re talking about security and safety, this is a good time to remind you how to protect your Reddit account. The most important (and simple) measure you can take is to set up 2FA (two-factor authentication) which adds an extra layer of security when you access your Reddit account. Learn how to enable 2FA in Reddit Help. And if you want to take it a step further, it’s always a good idea to update your password every couple of months – just make sure it’s strong and unique for greater protection.
Also: use a password manager! Besides providing great complicated passwords, they provide an extra layer of security by warning you before you use your password on a phishing site… because the domains won’t match!
-- https://www.reddit.com/r/reddit/comments/10y427y/we_had_a_se...
Why require email for dumb social media sites? You can talk about password recovery, but emails aren't necessarily required for that, and it could be something to opt in to. It seems like email is required to make data collection, tracking and advertising easier. It sucks that all this creepy data collection is not only an annoyance, but also makes us less secure.
I don't know what they think they are accomplishing since burner e-mails are trivial, but perhaps it gives a semblance of doing something.
Edit: It works when using the right URL, see https://news.ycombinator.com/item?id=34742134 below.
That experimental part is interesting.
I was able to get the old account disabled, but couldn't get it back because I couldn't prove I'd ever owned it. So I created a new account, and it wasn't a big deal, but I was annoyed that I lost my preferred username. Fortunately I'm not a moderator for any subreddits.
Don't get the privacy concerns. I'm totally fine if people know what I post on Reddit. It's public. I wouldn't want any friends to get confused by private messages sent as me, though.
People who don't care about losing their account probably aren't doing anything they care about with it, and that's okay, but it's not everyone.
Good for you. But for others, pseudonimity is a way of protecting themselves in real life. There are people who cannot express their views on certain subjects without inviting scrutiny, or even danger, in their real lives.
> It's public.
There are private subreddits.
I've never used a private subreddit, but I imagine it might be hard to get back in after your account got hacked?
I don't do that anymore.
Who cares? Those of us who treat subreddits as communities, and as such have built relationships there.
It doesn't seem to me that much sophisticated, rather "normal", unless they are omitting some relevant details, it sounds a lot like "Action needed urgently, click here to login to ...".
Could be anything from average phishing or some 0-day that happened to be found by gov employee or phishing email, to "a bunch of men kidnapped target and beat them till they gave them access
Basically applies to every team there is.
Means almost every other time you're sent a link, you have to log in yet again. And man are you sent jira tickets often in tech.
The employee's password was probably passw0rd, and that's being generous for reddit.
It usually involves meticulous research on the target, what and who they work with, and have crafted an email that plausibly looks and sounds like an internal email, that talks about company stuff in company language, mentions coworkers and so on.
Add a note of urgency, make it someone who has discovered something isn't right, there's an urgent technical issue or the company or money is missing from the accounts or something, or perhaps it was dressed up as a memo announcing layoffs at reddit. If it's an urgent "threat" you tend to tunnel vision quite hard.
The result is very far removed from how your typical spam emails tend to look.
Reddit is far from the worst offender in this area. I should have specified my opinion as a more general one.
This attack vector is significantly harder to pull off if a hardware authenticator will assert that the user is logging into the correct domain.
Average person reluctantly moves from 123456 to P@55word!
8 years ago "no passwords such, use a pass phrase"
Average person reluctantly moves from P@55word! to correct-horse-battery-staple
6 years ago "ok but you need to use different passwords on each site"
Average person reluctantly moves to different passwords per site
4 years ago "but you can be phished, you have to use 2FA"
Average person reluctantly moves to SMS
2 years ago "no in some countries it's easy to take over SMS, use TOTP"
Average person reluctantly moves to TOTP
Today "no TOTP is rubbish, you can be phished, use this hardware authenticator"
Normal people don't like new shiny ways of working every year or so. My house's front door lock is broadly the same interface as my great-grandparent's front door lock, but technologists think changing the way things work every couple of years is acceptable.
Nobody should ever suggest you use TOTP or SMS 2fa to prevent phishing.
> 6 years ago "ok but you need to use different passwords on each site"
Really the only one that matters in practise. TOTP is basically just a work around to get users to actually do this.
Edit: i would also add this is a corporate environment where its reasonable to be more picky. And webauth really is the best (only?) Solution to phishing.
It also depends on how sophisticated the attacker is. Do they fake log you out so they could capture a second 2fa token in order to change the totp token to a new device and change your email?
And of course, for the most part damage can usually be done in minutes - copying confidential files does not need long term access.
True, but your house's front door lock is very likely to offer quite poor security. Most house locks are vulnerable to bumping attacks that are almost trivial to pull off. The only reason this is acceptable is the threat model you're dealing with when securing a physical house is very different from securing an internet-connected computer.
Moreover, while the threats against your front door have remained marginally the same as those against your great-grandparent's door, computers and the network they are operating in change extremely frequently. All the security recommendations you're naming were quite reasonable for their time but rapidly became outdated.
They very explicitly said they're paying enormous amounts of money to avoid being robbed (I'm not missing the irony here).
Something I found out recently is that my lockable desk drawer can be thwarted by giving it a sharp shove to the right while pulling the drawer. It juuust about pops the metal locking rod out of the mechanism for a moment, if you're pulling on the drawer it'll just open.. Found it out when I misplaced the key, haha.
The safety glass in cars is especially difficult where I expect much less from that in a home.
With the obsession over insulation I suspect they're stronger than I remember, but brute force always works - if not, just use more. Maybe introduce leverage
While surely nothing offers complete security, it massively increases the effort required to break in (from essentially zero).
The list you are describing could as well be seen as every service trying to implement the simplest and least disruptive technology, only to find out two years later that it was insufficient and switching to the next best thing, only for the cycle to repeat each time.
Which of course from the users perspective doesn't make a difference, but it gives a different perspective on how to solve it for the future.
I'm sure authentication technology will settle down in a decade or two.
Most regular users never moved beyond using 'P@55word!' everywhere.
I don't even think it's realistic to get him to use a smartphone for this, he hates the things.
WebAuthn works great for your Web 3.0 startup but as soon as you're talking about the average user, who is likely decades older than the commenters here, and far less interested in keeping up with these things, and far less patient with the hassles... asking them to carry hardware is a nonstarter for so many.
I don't know anyone using "Hello" but I suppose it's an option. Most Windows users would likely have to use a hardware key though.
That's surprising. As in, the fact that that happens is to be expected from the firmware's point of view - updating the firmware changes the measurements made to the TPM so any secrets can no longer be unlocked. But I would've expected Windows to update the expected measurements before applying the update to prevent that from happening.
It can also be defeated by any idiot with a bump key in about 10 seconds.
A reluctant move is still a move, and thus beneficial. But we definitely have different ideas of the “average person”. I sincerely doubt the average has moved on from P@55word, and even then only because the website they’re trying to register an account with imposes the rule. I’d be happy to be proven wrong; do we have data on it?
8 years ago "no passwords, use a pass phrase"
Average person reluctantly moves from "P@55word!" to "P@55word! P@55word! P@55word!"
6 years ago "different passwords on each set"
Average person shrugs and changes nothing
2 years ago "use TOTP 2FA"
Average person already using SMS changes nothing, and the sites allow this as a grandfathered exception effectively indefinitely
Your front door doesn't have thousands of anonymous bots a day trying to brute force it.
While not as secure or convenient as a security key for initially logging in there is no need for a new device in many cases.
besides the fact that the webauthn yubikey is $20 vs $50-70 for it's more popular and well known versions.
I'd be glad to personally, but if a site supports 2fa at all, then it's mostly likely TOTP. And some require TOTP first and allow webauth only in addition to it.
If this was Meta, or Twitter that got breached via there would be outrage everywhere as to why employees did not use hardware keys.
Edit: Reads comment by Maxburn, googles TOTP and Authy
Why the heck do I need a 3rd party involved? Ugh
Those apps keep track of it for you, you can use any 2FA app that supports TOTP. You could even make your own if you want.
Google authenticator exists, but I'm trying to get google out of my life. I think Bitwarden has one. I'm only using Authy because it was among the first to offer a backup/restore solution that I stumbled on.
RSA was a big one that was similar. Not sure if it's still used today but there was a little hardware fob that wasn't connected to the internet or anything, the whole thing works on Time. The only thing that fob needed was a constant battery power, if it died you'd have to replace the battery and call the helpdesk to get it resynced with your account. The only thing your phone needs is a good time source like GPS or network time. I believe authenticator app works even if your phone doesn't have service. You could be on a landline in a remote region with no Internet, talking to your significant other on the other side of the world, have them log in to your account and give them the code displayed by the authenticator app and they could send that important email you forgot.
Have a look at Yubikey's - there, the seed is stored on the key itself, the calculation done on the key itself, and all the app does is read it all via NFC.
Yes, you use the Yubico Authenticator app, but it's entirely local only (runs fine with all networking switched off).
It's available for Mac, Linux and Windows, as well as Android and iOS. On computers your key needs to be inserted into a USB port. For Android and iOS I use the NFC key and I just scan it against the phone after launching the app.
"We've been hacked, so you should give us your phone number."
Hilarious!
https://en.wikipedia.org/wiki/List_of_ongoing_armed_conflict...
Want to phish someone in 2023? Send an email saying they've been laid off. Link to an article (which requires auth to read, of course) for full details of their redundancy payout.
How about Reddit follows their own recommendation and forces 2FA for their employees?
Those kinds of attacks are 100% avoidable. Nobody with my company username and password can do ANYTHING, unless they have physical access to my computer...
[0] https://old.reddit.com/r/reddit/comments/10y427y/we_had_a_se...