Story image

User passwords and email addresses compromised in Reddit breach

02 Aug 18

Reddit has announced that a hacker broke into a few of its systems and managed to access some user data, including some current email addresses and a 2007 database backup containing old salted and hashed passwords.

Reddit has since been conducting a painstaking investigation to figure out just what was accessed and to improve its systems and processes to prevent the incident from happening again.

Timeline

On June 19, Reddit learned that between June 14 and June 18, an attacker compromised a few employee accounts with its cloud and source code hosting providers.

Its primary access points for code and infrastructure had required two-factor authentication (2FA) via SMS-based authentication, and the main attack was via SMS intercept.

Reddit acknowledged that although it was a serious attack, the attacker did not gain write access to Reddit systems; they gained read-only access to systems that contained backup data, source code and other logs.

They were not able to alter Reddit information, and it has since taken steps to further lock down and rotate all production secrets and API keys, and to enhance logging and monitoring systems.

What was accessed

Two key areas of user data were accessed:

·       All Reddit data from 2007 and before including account credentials and email addresses

o   What was accessed: A complete copy of an old database backup containing very early Reddit user data from the site’s launch in 2005 through May 2007. In Reddit’s first years it had fewer features, so the most significant data contained in this backup are account credentials (username + salted hashed passwords), email addresses, and all content (mostly public, but also private messages) from the abovementioned timeframe.

o   How to tell if your information was included: Reddit has messaged affected users and is resetting passwords on accounts where the credentials might still be valid. Users that signed up for Reddit after 2007 are safe. Reddit is advising users to check their private messages and/or email inbox.

·       Email digests sent by Reddit in June 2018

o   What was accessed: Logs containing the email digests sent between June 3 and June 17, 2018. The logs contain the digest emails themselves. The digests connect a username to the associated email address and contain suggested posts from select popular and safe-for-work subreddits users subscribed to.

o   How to tell if your information was included: Users who don’t have an email address associated with their account or if their “email digests” user preference was unchecked during that period are not affected. Otherwise, users can search their email inbox for emails from noreply@redditmail.com between June 3-17, 2018.

As the attacker had read access to storage systems, other data was accessed such as Reddit source code, internal logs, configuration files and other employee workspace files, but these two areas are the most significant categories of user data.

What is Reddit doing about it?

Reddit has reported the issue to law enforcement and is cooperating with their investigation.

It is messaging user accounts if there’s a chance the credentials taken reflect the account’s current password, and it has taken measures to guarantee that additional points of privileged access to Reddit’s systems are more secure (e.g., enhanced logging, more encryption and requiring token-based 2FA to gain entry since it suspects weaknesses inherent to SMS-based 2FA to be the root cause of this incident.)

Webroot senior threat research analyst Tyler Moffitt says that SMS-based authentication has often been used by cybercriminals to hack celebrities.

“In this type of attack, the phone number is the weakest link.

“Cybercriminals can steal a victim’s phone number by transferring it to a different SIM card with relative ease, thereby getting access to text messages and SMS-based authentication,” Moffit says.

“For example, a cybercriminal would simply need to give a wireless provider an address, last 4 digits of a social security number, and perhaps a credit card to transfer a phone number.”

He adds, “This is exactly the type of data that is widely available on the dark web thanks to large database breaches like Equifax.”

IDC: Smartphone shipments ready to stabilise in 2019
IDC expects year-over-year shipment growth of 2.6% in 2019, while the world's largest market is still forecast to be down 8.8% in 2018.
52mil users affected by Google+’s second data breach
Google+ APIs will be shut down within the next 90 days, and the consumer platform will be disabled in April 2019 instead of August 2019 as originally planned.
New app conducts background checks on potential tenants
Landlords and house owners need to obtain a tenant’s full name, date of birth, email address, and mobile number in order to conduct the search. And most importantly, they have to get the tenant’s permission first.
GirlBoss wins 2018 YES Emerging Alumni of the Year Award
The people have spoken – GirlBoss CEO and founder Alexia Hilbertidou has been crowned this year’s Young Enterprise Scheme (YES) Emerging Alumni of the Year.
IDC: Standalone VR headset shipments grow 428.6% in 3Q18
The VR headset market returned to growth in 3Q18 after four consecutive quarters of decline and now makes up 97% of the combined market.
Meet Rentbot, the chatbot that can help with tenancy law
If you find yourself in a tricky situation  - or if you just want to understand your rights as a landlord or tenant, you can now turn to a chatbot for help.
PlayerUnknown’s Battlegrounds (PUBG) finally releases on PS4
PUBG on PS4 feels like it’s still in Early Access as the graphics look horribly outdated and the game runs poorly too. 
How AI can fundamentally change the business landscape
“This is an extremely interesting if not pivotal time to discuss how AI is being deployed and leveraged, both in business and at home.”