this post was submitted on 19 Jun 2023
5 points (100.0% liked)

Asklemmy

43852 readers
1236 users here now

A loosely moderated place to ask open-ended questions

Search asklemmy 🔍

If your post meets the following criteria, it's welcome here!

  1. Open-ended question
  2. Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
  3. Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
  4. Not ad nauseam inducing: please make sure it is a question that would be new to most members
  5. An actual topic of discussion

Looking for support?

Looking for a community?

~Icon~ ~by~ ~@Double_A@discuss.tchncs.de~

founded 5 years ago
MODERATORS
top 26 comments
sorted by: hot top controversial new old
[–] const_void@lemmy.ml 3 points 1 year ago (1 children)

Probably should've invested in better security instead of trying to chase tech trends like NFTs.

[–] gkd@lemmy.ml 1 points 1 year ago (1 children)

You mean the 100th award I could buy was starting to be overkill? /s

[–] const_void@lemmy.ml 5 points 1 year ago* (last edited 1 year ago) (1 children)

Thanks for the gold kind stranger! 🤮

[–] Luccajan@sh.itjust.works 0 points 1 year ago (1 children)

Thanks for the puke kind strager

[–] Royalish@lemmy.ml 0 points 1 year ago

Thanks for the thanks thanks thanks.

[–] farizer@kbin.social 3 points 1 year ago (1 children)

Hopefully they publish the data so we can add to the fediverse

[–] Phoeniqz@lemmy.dbzer0.com 1 points 1 year ago

The article says, the data supposedly contains information about Reddit's tracking system. I don't think we want that in the FediVerse

[–] atypicaloddity@kbin.social 1 points 1 year ago

It happened a while back and is just popping up again now because they're capitalizing on the Reddit drama. So I don't really have an opinion on them -- hacking bad, etc but I don't really care.

[–] tojikomori@kbin.social 1 points 1 year ago* (last edited 1 year ago) (1 children)

I've seen a few sites welcome the news with glee, as though Reddit's leadership is going to be strongly affected. That's childish and myopic. This is bad news for everyone.

Whether or not Reddit pays, we should assume the data will make its way into the hands of people who (further) weaponize it against Reddit's users, e.g. people who've posted risque photos of themselves or shared compromising details through throwaway accounts can be doxxed or matched to their normal accounts via their IP or other common details. PMs and other private account details might contain mailing addresses and other private or compromising information, too. (Edit: as Phoeniqz points out in replies, the article author assumes this is not the case based on Reddit's and BlackCat's statements about the leak.)

If Reddit knew about the breach earlier and didn't do their due diligence to alert users, then that's further condemnation of their leadership and priorities, but it doesn't undo the damage this might cause users.

If Reddit were to pay BlackCat, then it would further enrich, reward, and encourage them. If, as is more likely, it doesn't, then the blowback it receives (especially from any high profile consequences of the leak) might encourage other companies to pay up in future.

[–] Phoeniqz@lemmy.dbzer0.com 0 points 1 year ago* (last edited 1 year ago) (2 children)

From the article:

We can be pretty sure of what to doesn’t include, and that’s user data such as account details, passwords or payment information. That’s because, from the very start, Reddit made it quite clear that the ‘live’ production systems holding such data were not breached.

[–] SickIcarus@kbin.social 1 points 1 year ago

That’s because, from the very start, Reddit made it quite clear that the ‘live’ production systems holding such data were not breached.

Because Reddit is known for being forthright and honest…

[–] tojikomori@kbin.social 0 points 1 year ago (1 children)

Yes but note the specific details of that assumption and their reasoning: it's based on reddit's announcement of the security incident a few months ago which starts:

Based on our investigation so far, Reddit user passwords and accounts are safe…

Now, look again at what BlackCat has promised in this leak:

Instead, BlackCat is teasing such revelations as "all the statistics they track about their users," and data concerning how Reddit "silently censors users."

80 GB of "statistics and data" about Reddit's users is a lot. It may not contain raw IP addresses, but we know that IP matching is one of the ways Reddit catches sock puppets, so there may at least be a hash that could be used to identify accounts held by the same users.

Am I going too far worrying about PMs and other details? Maybe. It really depends on the honesty and competence of BlackCat and Reddit, and the article author's assumptions based on their statements.

[–] PascalSausage@beehaw.org 1 points 1 year ago

This is assuming that the group is telling the truth about what they found.

[–] CookieJarObserver@feddit.de 1 points 1 year ago (1 children)

Great. Fuck em and if they leak it EU citizens can sue the shit out of them :)

[–] PascalSausage@beehaw.org 1 points 1 year ago (2 children)

No user data was accessed according to Reddit.

[–] CookieJarObserver@feddit.de 1 points 1 year ago (1 children)

See, there is the problem, "according to reddit" they probably don't even know themselves currently. I don't believe them anyway.

[–] PascalSausage@beehaw.org 0 points 1 year ago (1 children)

They can 100% know what was accessed and what wasn’t. This didn’t just happen, it happened in February and their SOC team or an external company would have conducted a full sweep as they’re legally required to disclose what was breached in many of the territories they operate in, which they did four days after the incident took place. I know it’s on trend to hate Reddit right now, but it’s not some one man operation running on a dusty old server in a garage, it’s something like the 20th most visited website on the entire internet, and that comes with certain legal obligations. They know what they’re doing and clearly take this kind of thing seriously.

You don’t have to believe them, but there’s no proof that any user data was breached and they seem to have followed the proper protocols so far. Unless anything else comes out, I’m inclined to believe that they’re telling the truth, or at least not lying.

[–] CookieJarObserver@feddit.de 1 points 1 year ago

When it comes to legal obligations... Reddit is currently very hard violating EU laws, they don't do shirt.

[–] DoucheAsaurus@kbin.social 1 points 1 year ago

according to Reddit

A super trustworthy source as we all know.

[–] FarceMultiplier@lemmy.ca 1 points 1 year ago (1 children)

No website is invulnerable. Since we know from Reddit's godawful official app they don't do development very well, no doubt the website also has vulnerable holes.

[–] PascalSausage@beehaw.org 2 points 1 year ago (1 children)

They didn't access the data through a vulnerability in the code, they phished some employee credentials and access it that way.

[–] FarceMultiplier@lemmy.ca 1 points 1 year ago (1 children)

That in itself is a vulnerability. In my company we check for impossible travel, browser variance, etc. Credentials are only one aspect of this.

[–] PascalSausage@beehaw.org 1 points 1 year ago* (last edited 1 year ago)

True, I just interpreted your comment differently to that.

[–] gentleman@kbin.social 1 points 1 year ago (1 children)

@Phoeniqz If Reddit is only announcing the hack now then that is very likely going to be a legal problem in a number of US jurisdictions, not to mention EU and others.

[–] Phoeniqz@lemmy.dbzer0.com 1 points 1 year ago (1 children)

I'm not so sure tho, as no user data was affected.

[–] dismalnow@kbin.social 1 points 1 year ago

@Phoeniqz

@gentleman

My read was that BlackCat only got non-prod data. So perhaps it's sourcecode.

In which case.. they've likely got nothing of value other than the code used to track users.

load more comments
view more: next ›