SMS 2FA gave us sweet FA security, says Reddit: Hackers stole database backup of user account info, posts, messages

Email addresses, hashed passwords, and other details from mid-2000s era swiped

In a Wednesday mea culpa, Reddit – the online chat board that got a little out of hand and became the sixth most-visited website on the internet – has admitted it was raided by hackers unknown.

For four days, specifically June 14 to June 18, miscreants managed to break into the website's cloud hosting and source-code repository accounts of several Reddit employees, despite their accounts being locked down with two-factor authentication via SMS. It looks at this stage as though a man-in-the-middle attack was used to snatch the SMS tokens, allowing the accounts to be taken over. The staffers' phones themselves weren't hacked, it is claimed.

"We learned that SMS-based authentication is not nearly as secure as we would hope, and the main attack was via SMS intercept," the Reddit team said in a statement on Wednesday. "We point this out to encourage everyone here to move to token-based 2FA."

El Reg also highly recommends hardware tokens for multi-factor authentication rather than SMSes. Text messages can, for example, be intercepted by scumbags hijacking phone accounts in so-called port-out scams, or through SS7 tricks, or through browser-based attacks, or potentially eavesdropped over the air.


US standards lab says SMS is no good for authentication


In this instance, it is not known exactly how the login SMSes were grabbed – they could have been phished, after all.

The attackers managed to snaffle a backup database of information that was submitted to the site from its launch in 2005 until May 2007, including usernames, passwords (although these were salted and hashed), email addresses, and all content including public and private messages.

That sounds bad, however, there are mitigating factors. Reddit wasn't that big for the first year or so of operation, and the founders have admitted that many of the accounts were sock puppets intended to drive initial traffic. The loss of private messages may be more serious, although they are all over a decade old.

Reddit also said that some email digests sent out between June 3 and June 17 have been stolen, showing which safe-for-work subreddits some email addresses were following. Affected users will be contacted by the biz if they were caught up in the theft.

The statement also mentions that the Reddit source code, internal logs, configuration files, and other employee workspace files were accessed.

"In other news, we hired our very first Head of Security, and he started 2.5 months ago," said Reddit CTO Christopher Slowe. "I’m not going to out him in this thread for obvious reasons, and he has been put through his paces in his first few months. So far he hasn’t quit." ®

Other stories you might like

  • 5G C-band rollout at US airports slowed over radio altimeter safety fears
    Well, they did say from July, now they really mean from July 2023

    America's aviation watchdog has said the rollout of 5G C-band coverage near US airports won't fully start until next year, delaying some travelers' access to better cellular broadband at crowded terminals.

    Acting FAA Administrator Billy Nolen said in a statement this month that its discussions with wireless carriers "have identified a path that will continue to enable aviation and 5G C-band wireless to safely co-exist."

    5G C-band operates between 3.7-3.98GHz, near the 4.2-4.4GHz band used by radio altimeters that are jolly useful for landing planes in limited visibility. There is or was a fear that these cellular signals, such as from cell towers close to airports, could bleed into the frequencies used by aircraft and cause radio altimeters to display an incorrect reading. C-band technology, which promises faster mobile broadband, was supposed to roll out nationwide on Verizon, AT&T and T-Mobile US's networks, but some deployments have been paused near airports due to these concerns. 

    Continue reading
  • IBM settles age discrimination case that sought top execs' emails
    Just days after being ordered to provide messages, Big Blue opts out of public trial

    Less than a week after IBM was ordered in an age discrimination lawsuit to produce internal emails in which its former CEO and former SVP of human resources discuss reducing the number of older workers, the IT giant chose to settle the case for an undisclosed sum rather than proceed to trial next month.

    The order, issued on June 9, in Schenfeld v. IBM, describes Exhibit 10, which "contains emails that discuss the effort taken by IBM to increase the number of 'millennial' employees."

    Plaintiff Eugene Schenfeld, who worked as an IBM research scientist when current CEO Arvind Krishna ran IBM's research group, sued IBM for age discrimination in November, 2018. His claim is one of many that followed a March 2018 report by ProPublica and Mother Jones about a concerted effort to de-age IBM and a 2020 finding by the US Equal Employment Opportunity Commission (EEOC) that IBM executives had directed managers to get rid of older workers to make room for younger ones.

    Continue reading
  • FTC urged to probe Apple, Google for enabling ‘intense system of surveillance’
    Ad tracking poses a privacy and security risk in post-Roe America, lawmakers warn

    Democrat lawmakers want the FTC to investigate Apple and Google's online ad trackers, which they say amount to unfair and deceptive business practices and pose a privacy and security risk to people using the tech giants' mobile devices.

    US Senators Ron Wyden (D-OR), Elizabeth Warren (D-MA), and Cory Booker (D-NJ) and House Representative Sara Jacobs (D-CA) requested on Friday that the watchdog launch a probe into Apple and Google, hours before the US Supreme Court overturned Roe v. Wade, clearing the way for individual states to ban access to abortions. 

    In the days leading up to the court's action, some of these same lawmakers had also introduced data privacy bills, including a proposal that would make it illegal for data brokers to sell sensitive location and health information of individuals' medical treatment.

    Continue reading

Biting the hand that feeds IT © 1998–2022