Last night via the official r/reddit community, Reddit disclosed that they were pwned:
On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees. As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens.
After successfully obtaining a single employee’s credentials, the attacker gained access to some internal docs, code, as well as some internal dashboards and business systems. We show no indications of breach of our primary production systems (the parts of our stack that run Reddit and store the majority of our data).
Exposure included limited contact information for (currently hundreds of) company contacts and employees (current and former), as well as limited advertiser information. Based on several days of initial investigation by security, engineering, and data science (and friends!), we have no evidence to suggest that any of your non-public data has been accessed, or that Reddit’s information has been published or distributed online.
Reddit claims that user data is secure, but:
Since we’re talking about security and safety, this is a good time to remind you how to protect your Reddit account. The most important (and simple) measure you can take is to set up 2FA (two-factor authentication) which adds an extra layer of security when you access your Reddit account. Learn how to enable 2FA in Reddit Help. And if you want to take it a step further, it’s always a good idea to update your password every couple of months – just make sure it’s strong and unique for greater protection.
Also: use a password manager! Besides providing great complicated passwords, they provide an extra layer of security by warning you before you use your password on a phishing site… because the domains won’t match!
Now I can’t tell if Reddit is saying this because there is a legitimate threat out there that they haven’t disclosed, or this is generally good advice. Which it is good advice from my view. But if you’re a Reddit user, you should likely take their advice just in case this turns into a LastPass type of situation.
UPDATE: Monti Knode, Director of Customer Success at Horizon3.ai has this comment:
“Another successful phishing campaign isn’t a surprise and shouldn’t be. This attack vector is successful because it can look so legit, from plausible prompts to cloning their intranet gateway. This attack further reinforces the fact that the old perceptions of a perimeter are dead and gaining access is almost trivial, while understanding the blast radius of a successful attack matters more than ever.
“What can an attacker do if they landed on a specific asset? What could they do with a specific credential? In what scenario is our sensitive data at risk? These are the questions we should all be asking, because it’s not a matter of if, but when.”
Jesh Sax, Technical Account Manager at Tanium adds this:
“The techniques used at Reddit are all too familiar. Attackers are adapting to security techniques like multi-factor authentication and organizations need to take measures to mitigate potential vulnerabilities. Whether it’s physical security tokens or finding ways to authenticate both the user and the device that they’re logging in from, security teams need to continue to evolve.
“However, the fact that the user self-reported and the security team was able to catch things early on prevented this from becoming a much larger story. This speaks volumes to the culture that the security team has promoted at Reddit, where users feel comfortable speaking up when they’ve clicked on a phishing link. This type of security-aware culture is what every organization should strive for.”
Reddit’s CEO Has Completely Lost The Plot
Posted in Commentary with tags Reddit on June 16, 2023 by itnerdSteve Huffman who is the CEO of Reddit had an interview with The Verge. And it went as well as you’d expect. Which is badly. In the interview, he said this:
We offer the API so the vast majority of our use of the uses of the API — so not these, the other 98 percent of them that make tools, bots, enhancements for Reddit — that’s what the API is for.
It was never designed to support third-party apps. We let it exist. And I should take the blame for that, because I was the guy arguing for that for a long time. But I didn’t know — and this is my fault — the extent that they were profiting off of our API. That these were not charities.
The ones that actually are doing good for our users — RedReader, Dystopia, Luna — like actually adding real value at their own cost? We’ve exempted. We’ll carry that cost.
Huffman “didn’t know” what was going on? Um, he’s the CEO, he’s supposed to know. That’s either a dodge or he’s asleep at the switch. That’s eye opening either way.
But there’s also this:
I want to stop you for a second there. So you’re saying that Apollo, RIF, Sync, they don’t add value to Reddit?
Not as much as they take. No way.
Um, let me point out something here. The native Reddit app sucks. And I don’t mean it kind of sucks, or it sort of sucks. I mean that it is really, REALLY BAD. Third party apps for Reddit are, or were orders of magnitude better than the native Reddit app. Maybe he should go do something about that because those apps were likely a factor when it came to people being on Reddit. Without them, the willingness for people to be on Reddit drops.
But it also seems that Reddit is going to force subreddits that have been dark back online.
This guy is one of the moderators of the r/Apple subreddit, and according to him, Reddit is threatening to remove moderators of subreddits that are blacking out indefinitely. Excuse my French here, but that’s a dick move by Reddit and illustrates that this protest is likely hurting them more than they are letting on.
At the end of the day, this will be a case study of how to anger the users who generate the content on which your platform is built on, with the net result of the platform imploding. That’s what Huffman is doing here. The question is, will he get a clue and change course in time to save Reddit before the users that he needs to generate content that encourages people to visit the platform leave for other places and put a bullet in his plans to have the platform generate income?
UPDATE: According to AppleInsider, the r/Apple subreddit has reopened under duress because of the threats made by Reddit. Like I said earlier, this is a dick move by Reddit.
Leave a comment »