Every thing you'll want to know in regards to the Reddit knowledge breach
von Satoshi Nakamoto


Some safety researchers are involved about how Reddit is dealing with a current knowledge theft incident.
Web stalwart Reddit yesterday (1 August) disclosed particulars of an information breach, which occurred between 14 and 18 June of this 12 months. The corporate mentioned {that a} hacker infiltrated a number of of its programs and efficiently accessed some consumer knowledge.
In line with the corporate, it has been conducting an intensive investigation for the reason that incident got here to gentle. The hacker accessed consumer knowledge together with some present e mail addresses from Reddit digests despatched to customers, in addition to usernames and a database backup from 2007, which contained outdated salted and hashed passwords.
How did the breach occur?
Three phrases: worker account compromise. Though the worker accounts accessed had been protected by two-factor authentication (2FA), the kind of 2FA utilized by employees relied on one-time passwords (OTPs) despatched to or generated by a cell phone. These OTPs may be simply intercepted or phished.
Token-based safety reminiscent of bodily safety keys are regarded by the safety business because the most secure type of 2FA, which is predicated on Common Second Issue (U2F). Google was lately within the highlight for its adoption of bodily safety keys.
Reddit mentioned: “We discovered that SMS-based authentication will not be almost as safe as we might hope and the primary assault was by way of SMS intercept. We level this out to encourage everybody right here to maneuver to token-based 2FA.”
The corporate burdened that the attacker didn't acquire write entry to Reddit programs and was unable to change Reddit info. It added that it has additional locked down and rotated all API keys and manufacturing secrets and techniques. Monitoring and logging programs are additionally being upgraded.
What's Reddit doing about it?
Reddit is cooperating with regulation enforcement and is messaging consumer accounts if there's a likelihood that the credentials stolen mirror the account’s present password (altering your password is a good suggestion). Safety measures are additionally being beefed up.
Some criticism is being levelled on the platform for placing the onus on customers affected by the e-mail digest theft to think about if they've any knowledge they wouldn’t need to be related to their e mail addresses.
These addresses, which can have been accessed by way of the theft of the emails, may determine people. The customers affected right here had been informed to go looking by way of their very own inboxes to see in the event that they acquired a digest by way of e mail from Reddit between three and 17 June of this 12 months.
The agency solely employed its first ever head of safety two months in the past, mentioned chief know-how officer Christopher Slowe. He added: “I’m not going to out him on this thread for apparent causes, and he has been put by way of his paces in his first few months. To this point, he hasn’t stop.”
Reddit has declined to reveal the amount of affected customers.
Not all 2FA strategies are created equal
Joseph Carson, chief safety scientist at Thycotic, informed Siliconrepublic.com: “The hack at Reddit is a reminder that when defending delicate knowledge by selecting 2FA along with a password, it is very important know that not all 2FA affords the identical safety; for instance, the distinction between utilizing SMS-based authentication and token-based authentication.
“I'm involved that Reddit appears to be enjoying down the info breach because it was ‘solely learn entry to delicate knowledge and never write’. That is constructive information; nonetheless, it doesn't cut back the severity of the breach when it pertains to delicate knowledge.”
Reddit brand on a cell phone. Picture: Tero Vesalainen/Shutterstock
Source link
Read the full article
Satoshi Nakamoto
Keine Verbindung
Verbindung wird wiederhergestellt
Etwas ist schiefgelaufen
Wir sind gleich wieder da