After what lastpass did I cannot trust any self reporting.
After what lastpass did I cannot trust any self reporting.
Say you had detailed audit logs for example. What happens if there's a subtle bug in those systems that allowed the hacker to proceed without logs being recorded?
So absolutely nothing coming out of Reddit should be trusted or quoted.
I don’t trust authority in general. But given the choice between spez and musk, I’d take spez any day. He’s at least not hopped up on drugs running around making crazy decisions.
And in terms of Reddit’s trustworthiness, it makes even less sense that editing comments would be of any consequence. If they detect a hacker and have the logs to prove it, they’d gain nothing by modifying the logs. And if they don’t, they gain nothing by fabricating the logs. So it seems reasonable to conclude that they just don’t have the logs.
Which is also reasonable. When I was hacking into systems at Matasano, it always made me uncomfortable just how undetectable I was. I wasn’t trying particularly hard to conceal myself, but a few well-chosen bash incantations and opening things in vi means all anyone sees is that a vi process is running.
You realize what you're saying right? You're saying someone's actions that breach trust makes you trust them more?
Actions speak louder than words, if someone is showing you that you can't trust them, you don't decide that you're going to trust them more!
Makes me wonder about all what else about reddit is an “illusion”
Wew.
The idea of snooping barely crosses my mind, let alone editing.
Maybe it is different because Reddit comments are intended to be public.
Then again, so did my last boss till i got to know him better
I think you (and many other people) are overestimating how much chinese influence there is on reddit, considering that they have < 10% stake (according to wikipedia they "led" a funding round that raised 10% of valuation, and since then there was another funding round that presumably diluted their stake).
Reddit is just as shady with its Overton Window manipulation tactics & strategies as Twitter has been exposed to be. Remember when Ghislaine Maxwell was revealed as a mod of r/Worldnews? I'm convinced any relevant PR company worth its salt has infiltrated moderator teams of every major subreddit. Whats stopping them? Or anyone else for that matter
That's... not how fundraising rounds usually work.
>in 2005. Condé Nast Publications acquired the site in October 2006. In 2011, Reddit became an independent subsidiary of Condé Nast's parent company, Advance Publications.[11] In October 2014, Reddit raised $50 million in a funding round led by Sam Altman and including investors Marc Andreessen, Peter Thiel, Ron Conway, Snoop Dogg, and Jared Leto.[12] Their investment valued the company at $500 million then.[13][14] In July 2017, Reddit raised $200 million for a $1.8 billion valuation, with Advance Publications remaining the majority stakeholder.[15] In February 2019, a $300 million funding round led by Tencent brought the company's valuation to $3 billion.[16] In August 2021, a $700 million funding round led by Fidelity Investments raised that valuation to over $10 billion.[4]
What type of shadowy agenda are entities like Jared Leto or Fidelity Investments trying to advance? Or should we assume that they're acting altruistically because they're not Chinese?
None, they might just really believe that Reddit might be profitable one day and they want a share of the pie. Snoop Dogg also invested in Klarna, for example.
On the other hand I have lots of reservations about the motivation of the likes of Sam Altman and Peter Thiel in this, Marc Andreesen is not such a wildcard, might be just stupid with money as the latest plays of a16z seems to making them be.
I'd stop visiting altogether if I didn't have a general problem with compulsive browsing.
However, having been at (what I deemed) non-shady companies, there’s still the very human desire to downplay as much as is reasonable. Shady companies overstep reasonability on purpose.
Really, don't trust corporations at all. Even if the circumstances of life force you to do business with them and hope nothing goes wrong, that's no reason to ever trust them. The bigger the corporation the more true this is, since the structure of corporations makes people feel less personally responsible for the bad things they might do to you, like lying to you about the scope of a data breach. The "just following orders" mentality allows workers to do things they'd never otherwise do to you, and that's just one example.
If any sort of business is safe to trust, it's the one-man-shop owner-operator kind of business and you can only trust those guys insofar as you can trust any other person at all. In that case you have to consider it on a case-by-case basis.
So you're saying we should trust Twitter? :)
As it happens, there is something that would help, though if and only if they can do it: Explain what evidence they would have if the breach had occurred.
I can't tell you how many large, well known companies I have worked with that either intentionally mislead, downplay, obscure or straight up lie in these types of notifications.
I have had legal teams tell me that they don't have to notify customers of a breach because an event happened on their test/dev systems, or a developer was compromised and not their actual service.
I have had companies intentionally not give information (like what an attacker was able to exfiltrate from a particular set of customers) that would been extremely helpful to inform or assess their risk. Instead they put out a generic "sophisticated attacker compromised our system, but no credentials or PII from our application were stolen".