BlackCat claims they hacked Reddit and will leak the data
databreaches.net
databreaches.net
There is very little in the way of genuinely sensitive data I can imagine them having. So little commerce is done on Reddit that the risk of there being hundreds of thousands of CC numbers and home addresses is almost nil. User passwords? Half of Reddit is creating burner accounts every 3 months to dodge suspensions and bans.
The truth is that you can use the same computer across many different networks, or even on the same network with a refreshed dynamic IP address, and such a table wouldn't allow the cross referencing you're suggesting.
For a username -> ip address table to provide this functionality, the users would need to access the site from the same IP address, not the same computer.
It's worth noting that the table would become polluted by things like public wifi, shared home internet, VPNs, etc. as well
Methods like stylometry make ip correlation largely unnecessary for finding alts.
I love you too, HN.
If that is the case: fuck it. Lets make it miserable for everyone until the pain is felt to an extent that necessitates changes.
Reddit failed to keep that information safe, and if it's an user's information they need to do what they can to keep it safe. They don't get to make the choice if it's someone else's information. If it's theirs, go hard, let it leak if they want.
If Reddit leaks my data, Reddit should pay me, not thieves and extortionists.
But "we don't negotiate with terrorists" isn't very brave if you're giving up someone else's data.
Their first attempt failed, so they just try and piggy back on this media hype wrt to api changes eve tho they dont give a damn, just to blow up this supposed breach and add fuel to the existing fire.
But I would very much want to see the IP addresses each account used last time, to identify people with many alt accounts
If it was me, and I wanted "independent" researchers to highlight clusters or duplicates I would do the following as a first-pass solution:
Store an internal mapping of IP->unique sequential number, likewise do the same for usernames. The goal is that it's random and not based on any hash or ordering. So people with either the IP, username or username + IP, can't identify the unique internal numbers.
Then release those. Though tbf, if I was part of any sort of "bot prevention" or "sock puppet identification" team at Reddit, I'd be doing this already. But we all know the dirty secret is to not actually track down such abuse, but to appear like you are doing so, so that you can inflate your user count with plausible deniability.
Just make sure to remove the NSFW accounts to avoid future "incidents".
Seems like he’s on a media blitz to try and change the narrative. You know when you’re doing interviews with The Verge you’re in bother.
The facts are that no threat nor blackmail attempt was made and Spez had entirely invented and spread the false claims as an attempt to discredit Selig.
In response to the false claims, Christian Selig released a recording of the phone call that disproved the claim and cleared his name. As Selig is in Canada, he was legally entitled to record and release the phone call. Huffman took umbrage at this action because it revealed Huffman's deceptive conduct.
Later in a Reddit "AMA", Huffman continued stating falsehoods about interactions with Selig, in spite of the evidence.
https://techcrunch.com/2023/06/09/reddit-ceo-doubles-down-on...
There were 4-5 other things that are escaping me at the moment.
Hadn't heard that one, so thanks for mentioning it. Link for others[0].
Interestingly enough something else is mentioned in the article which is even more damning for Spez.
> RIF was paying a “sizable revenue share” to Reddit beginning in 2012, which was during Yishan Wong’s tenure as CEO. (...) Reddit terminated the agreement in 2016 — which was the year after Huffman took over as CEO.
[0]: https://www.theverge.com/2023/6/16/23763661/reddit-rif-is-fu...
That is not exactly true. It sounds like there was a genuine misunderstanding during their call, and that Huffman might have believed - for a portion of the call - that a blackmail attempt was happening. If you listen to the audio, it really does sound like a blackmail attempt. At least that's how I heard it.
It also seemed clear that Huffman no longer believed that he had been blackmailed by the end of the call. But it wasn't "entirely invented," and I actually think that Huffman might not have fully believed Selig's explanation of his 'pay me $10 million to make this go away' statement (or whatever Selig's exact language was).
Separately, from what I recall, Huffman did not accuse Selig of illegally recording their phone call. Huffman took umbrage over the release of what, IIRC, he referred to as a private conversation, stating that he did not see how he could possibly do business with Selig after that. In fairness, Huffman's statement makes sense in isolation - regardless of whether the call was legally recorded. Which it seems to have been.
I think that Huffman looks really bad in all this. But that's a reason to be particularly careful about accuracy in our statements about what happened.
(And, interestingly, being downvoted for it. Despite no one presenting evidence that my account of what happened is wrong.)
He “took umbrage” after he publicly called out Selig for threatening Reddit, a thing that did not happen, and is immediately made obvious by the Reddit rep apologizing for the misunderstanding repeatedly.
Framing this as “Huffman was mad about Selig releasing a private discussion” is extremely misleading, and ignores the fact that Selig was basically forced to do so by Huffman’s public misrepresentation of that private conversation.
If Huffman doesn’t want a private conversation released, a good start would be avoiding misleading public statements about that private conversation.
> In fairness, Huffman's statement makes sense in isolation
You can make just about anything make sense in isolation, but this doesn’t mean that it makes sense in the real world.
Removing context is as good as lying in many situations, and this is one of those situations.
People can make up their own mind if they think the Dev was trying to blackmail Reddit or not.
This is false.(1) What I've written there is accurate. Why? Because while there was a misunderstanding, it was immediately corrected including Huffman apologising for his misunderstanding. Despite this Huffman later made the extortion/blackmail claim.
No part of the conversation supports extortion or blackmail, hypothetically even if Selig was serious about being bought out, that still wouldn't be extortion or blackmail.
(1) https://www.reddit.com/r/apolloapp/comments/144f6xm/apollo_w...
Transcript of the call here: https://gist.github.com/christianselig/fda7e8bc5a25aec9824f9...
Blackmail is a threat of revealing damaging information. That didn't happen.
Extortion is a threat of consequences. However it's clear that Selig can't enact consequences on Reddit. It's Reddit who can disable Apollo's API key. Selig can't render any kind of damage onto Reddit. This is further supported by the fact that Selig has no choice but to discontinue the app and will take a loss on the refunding of subscriptions.
Additionally the provided context of the conversation matches the discussions that Reddit has been having with other developers: i.e. API access and the future costs of that.
If one wishes to set a low bar for extortion: Then it would be Reddit attempting to extort 3rd party app developers by levying unrealistic API access costs, effectively ending their businesses. A concept that could actually hold water as Reddit develops a competitor app.
Now, I dont subscribe to the ideas of the morons in the_donald (I'm even ot from the USA) but I really took offense at what he did... like, what freaking integrity can a person have, when he does that kind of sleazy things.
Not even CmdrTaco or his team did it with all the trolls in Slashdoy.
He also unpersoned Aaron Swartz, removing him from the Reddit Co-founder page, and saying that he wasn't really a founder... After Swartz died. Which is just incredibly scummy.
And then there were the comments about owning slaves after an apocalypse.
And then there's the Ghislaine Maxwell / maxwellhill theories [0], which bring the Swartz stuff to a very dark place...
0 - https://www.reddit.com/r/conspiracy/comments/r45a5n/here_is_...
“Long story short, my takeaway from Twitter and Elon at Twitter is reaffirming that we can build a really good business in this space at our scale,” Huffman said.
“Now, they’ve taken the dramatic road,” he added, “and I guess I can’t sit here and say that we’re not either, but I think there’s a lot of opportunity here.”
The puzzle pieces sort of fell into place when I read that, because he's acting like an Elon knock-off. This is why they should replace him, because just like Elon is driving Twitter into the ground, the frantic Elon-like decisions of Huffman are driving reddit into the ground.
This isn't about Reddit not being allowed to make money or turn a profit or have a good IPO. The decisions made so far seem to run counter to Reddit's ability to do just that. Who will buy into an IPO of a burning platform that is at war with its own users? How do you make money from an API that's too expensive for people to pay for?
As much as I disagree with the gross consumer-unfriendliness of the direction and choices of management, they're sitting on an incredibly valuable data store that will attract search results - I've read a number of comments recently that "site:reddit" is a required filter on Google these days. That's hard to kill.
I feel the bigger threat to reddit is that many of the ways that people are introduced to it will be better served by AI-driven services. If people can find what they're looking for without ever visiting reddit, then they won't get involved in the communities, and the communities there slowly thin out.
Amusingly I see part of the reason for reddit's success is how poorly Google has become at finding information on the web. These days it seems that reddit is the go to place to find answers to a myriad of problems.
this might come as a shock, but a few hundred powertripping übermods aren't really an indicator for the state of reddit as a businesss.
They threatened to break their mop, and the custodians immediately surrendered
And I think mod tools (the automated ones) are also third-party only?
---
EDIT:
I forgot that Reddit has private messaging and chat, so maybe that does have some value.
Not sure how much the internal messaging system is used on Reddit (personally never used the chat, DMS are very rare)
I would bet that it has even lower value than that. They were only able to get 80gigs of data -- basically nothing compared to reddit's actual dataset. This means they probably didnt get anywhere close to any high value databases (or even low value).
Also, the fact that they dont even describe what type of data they managed to get a hold of tells me its probably not that meaningful. Reddit should definitely not be paying these extortionists regardless of what was swiped.
Aside from that, email addresses to usernames might be valuable - you could identify high-value targets from finance, crypto, or luxury item subs.
Or you could just make lists of people who post on specific subs for targeted harrassment.
It's interesting that they think it's "their" money.
Also, we have an interesting situation here: 1. Either the data is practically worthless - because reddit didn't bother with them; or 2. The data is critical and Reddit is truly mismanaged.
Guess only time will clear this one out. Wait and see.
For all you Businesspeople reading this: this is how much that tech debt the Engineering team has been talking about has costed.
Quite frankly, this is a good PR move, although I would assume that it's still better to maintain a low profile. Still, I'm sure a lot of people are hoping for more events like this to occur in order to punish Reddit.
Also known as complying with local laws.
It's always amusing when Americans realise that most of the world doesn't ascribe to their views on free speech.
And in fact governments with broad support from their citizens want social media companies to be regulated.
That's one form of "censorship and governmental collusion". There are others. Parts of government collude with companies outside of actual law too.
I never knew in the first place. Is this a solid fact? I find it hard to imagine people sharing cp via twitter.
And personally, yes, I came across accounts that were doing this. Seemed like they were mostly based outside of the USA, and the exploitation is usually something along the lines of someone using existing porn, advertising a series of link shorteners to access said porn, then profiting from the ad clicks. This is probably not profitable for anyone in a developed country, and is also probably only profitable due to child porn being outright banned from most of the internet, with no free access to material, people will jump through hoops to access said material. I'd been reporting those accounts for years to no avail until recently. Instagram has the same issue. I gave up on reporting on Instagram as I couldn't stomach seeing this stuff and my reports never had any results. The people sharing this stuff on Instagram fall into a few categories, occasionally parents, and other adults selling access to pictures/videos of their young children and toddlers in bikinis, something that would otherwise not be sexual, except that they are selling to an audience that is sexualizing it. Instagram will not take any of this down as it's not technically nudity. Maybe it's changed though. The other class of abusers are usually non USA based, and they'll exploit Instagram live to share, multiple broadcasters will be streaming, but one will be broadcasting hardcore child porn. You can only report one host of the stream, and by the time anyone looks at it, presumably, they've switched to another account to stream. It will usually be another broadcaster that was on the previous stream. I couldn't continue spending time reporting this stuff due to the hardcore nature of it. Instagram really needs to fix their reporting and allow reporting of every single broadcaster that is part of a live stream.
The FBI does not enforce supreme laws to which they are subject to, they have throughout their pathetic existence continue to routinely break laws largely with impunity.
No. The US executive branch via government agency can't tell a website to silence speech, that's a violation of the first amendement. That's exactly what happened with Twitter. Twitter didn't comply with any law, Twitter just did the binding of the US executive branch when it came to censorship. Completely unlawful.
They prefer a more managed version of it where hate speech, doxxing, abuse, defamation etc aren't rampant.
Specifically, (unless I missed some document) they received reports and acted on them independently. There were cases of "report received and acted on", but no proof of "action forced even though employee disagreed".
1. https://time.com/6286814/india-twitter-jack-dorsey-clash/
2. Elon Musk: https://english.elpais.com/international/2023-05-24/under-el...
This whole Twitter Files thing was embarrassing mundane and the amount of censoring twitter does right now is 100x worse. Just look at the Turkish elections...
2. It is also bad when Elon Musk does it.
I am not interested in any back and forth of "well ackshually now its this percentage worse", I only have a desire for it to stop entirely.
Only recently did Twitter stop fighting back and Musk just announced it - it wasn't something hidden.
Capitulation is the cessation of resistance. It does not stipulate perpetuity. A person/entity can capitulate and then at a later point change their mind. This does not mean they never capitulated.
>Only recently did Twitter stop fighting back
Complying with censorship is not what I consider fighting back. Once you have aided the government in censorship at the moment when dissidents have the opportunity to create change, the damage is done.
>and Musk just announced it - it wasn't something hidden.
I did not state or imply that "it" was hidden.
What you're missing is it's ILLEGAL and UNCONSTITUTIONAL to do such a thing in the US by the US government, which is at the heart of the Twitter Files controversy. Censoring public discourse among the voting electorate especially concerning matters of national importance and electoral candidates is without question a form of election manipulation, which has, and will continue to, affect the outcome. So it is not wrong to say that our elections, or any elections amidst broad, systemic censorship/collusion by the government with contractors, academia and corporations, was a government-manipulated one.
With free speech one can accept that there will be inaccurate takes from all sides that have to be distilled and debated, but that stops when these ideas can't even be spoken about.
Ok. Could you quote specifically when that was documented to happen? As in actually forced by a government agency, not just links provided to Twitter as "you should check out these tweets".
In case my previous comment was misunderstood, I meant that: I have not seen any cases where Twitter was forced to do anything. Every case I'm aware of, someone provided a tweet/account and twitter employees made the decision themselves (sometimes agreeing, sometimes pushing back).
> What you're missing is it's ILLEGAL and UNCONSTITUTIONAL to do such a thing in the US by the US government, which is at the heart of the Twitter Files controversy.
You're still missing the point. Read the quoted text. You said once again you haven't seen that Twitter was forced to do anything.
The unconstitutional and illegal bit is the US government merely _asking_ Twitter to censor content.
Here's a bite-sized video of the EIP and Atlantic Council under CISA openly bragging about how they accomplish it - pressure them to draft policy, then pressure them to uphold those policies.
Coercion to self-regulate: https://twitter.com/MikeBenzCyber/status/1608688753052377088
The Election Integrity Project was also recently highlighted in this recent WaPO Article: https://archive.ph/PjiVe
With this retort citing direct conversations that highlight that succinctly lays out everything: https://rumble.com/v2t4bha-censorship-industry-decoded-ep.-1...
It bears repeating how these allegations would make it unconstitutional via Supreme Court precedent and the law of agency (citations within link): https://www.newsweek.com/fbi-colluded-twitter-suppress-free-...
It's not like any of this was a secret, either: CISA openly admitted such on their website and even tried to quietly scrub it. Thanks to the Internet Archive preventing a rewrite of history (archive.org links within): https://theohiostar.com/commentary/commentary-government-cen...
At the very least it's a civil action called 'tortious interference'; using Federal money (employee time) wrongly might rise to the level of 'fraudulent conversion'...
TI is when a 3rd party interferes with a the interactions between 2 parties. In this case the feds interfered with the user's use of Twitter.
The second is obvious, you spend Federal money on a wrong purpose , just like if you had employees help you remodel your house while they were supposed to be working.
Redditors are being used as pawns by the third party devs in their fight to maintain their free loading existence. Which was easy, social media is good at riling up people for made up reasons.
Reddit has several hundred million users, and even more anonymous visitors. The two biggest third party apps have 1.5M users combined.