header logo
Asia asset finance
Mogo Academy
Science & Tech
Reddit user data compromised in sophisticated hack
Aug 03, 201812:47 PM
Reddit user data compromised in sophisticated hack

Reddit has suffered a data breach compromising usernames, passwords and email addresses of groups of users, the site has confirmed.

 

While the size of the breach has yet to be clarified, Reddit said two data sets had been accessed by hackers, including one from 2007 containing account details and all public and private posts between 2005 and May 2007.

 

The second data store included logs and databases linked to Reddit’s daily digest emails, which was accessed between 3 and 17 June this year. The data includes usernames and email addresses linked to those accounts.

 

Jake Moore, security specialist at ESET, said: “Reddit is one of the world’s biggest websites so a hack of any data at this level is quite a feat.”

 

Reddit said the breach was discovered on 19 June following the attack happening four days prior. The hackers broke in using compromised employee accounts that were protected using SMS two-factor authentication.

 

The site said it was messaging affected users. Reddit chief technology officer Christopher Slowe said: “If your account credentials were affected and there’s a chance the credentials relate to the password you’re currently using on Reddit, we’ll make you reset your Reddit account password.”

 

“Whether or not Reddit prompts you to change your password, think about whether you still use the password you used on Reddit 11 years ago on any other sites today.

 

“If your email address was affected, think about whether there’s anything on your Reddit account that you wouldn’t want associated back to that address.”
SMS-based two-factor authentication broken

 

Reddit uses the common SMS-based two-factor authentication to protect its employee accounts, requiring a one-time passcode to be entered alongside a username and password.

 

However, Reddit said hackers had intercepted those text messages.

 

Keith Graham, chief technology officer for SecureAuth + Core Security, said: “While SMS-based authentication is popular and much more secure than password alone, it’s widely known to be vulnerable to cybercriminals who have hacked many celebrities using this method.

 

Graham explained that cybercriminals are capable of gaining access to a phone number to which an SMS two-factor code is sent. He said: “For example, a cybercriminal would simply need to give a wireless provider an address, last 4 digits of a social security number and perhaps a credit card to transfer a phone number.

 

“This is exactly the type of data that is widely available on the dark web thanks to large database breaches like Equifax.”

 

Source: The Guardian

 

 

 

MostRead
Mobitel 5g
VideoStories
Sarath Weerasekara writes to ARFRO on Suresh Sallay's behalf

Sarath Weerasekara writes to ARFRO on Suresh Sallay's behalf

Government puts up theatrics to avoid farmers' concerns – MP Dilith Jayaweera

Government puts up theatrics to avoid farmers' concerns – MP Dilith Jayaweera

‘We have no intention of following previous regimes’ – PM Harini Amarasuriya

‘We have no intention of following previous regimes’ – PM Harini Amarasuriya

Suresh Sallay treated at National Hospital for 12 days; Maligakanda Magistrate visits for inspection

Suresh Sallay treated at National Hospital for 12 days; Maligakanda Magistrate visits for inspection

Govt. launches island wide dengue control programmes; public urged to stay vigilant

Govt. launches island wide dengue control programmes; public urged to stay vigilant

Farmers stage protests urging govt. to purchase paddy at a fair price

Farmers stage protests urging govt. to purchase paddy at a fair price

Sugeeshwara Bandara arrested over allegations of misappropriating state funds

Sugeeshwara Bandara arrested over allegations of misappropriating state funds

'No one can influence public appointments'  Govt denies officials appointed at Cardinal’s request

'No one can influence public appointments' Govt denies officials appointed at Cardinal’s request

Crucial data on Suresh Sallay’s devices may prove innocence, claims Udaya Gammanpila

Crucial data on Suresh Sallay’s devices may prove innocence, claims Udaya Gammanpila

Yoshitha Rajapaksa released on bail following arrest by the Bribery Commission

Yoshitha Rajapaksa released on bail following arrest by the Bribery Commission

Political debate intensifies over Suresh Sallay detention and CID conduct

Political debate intensifies over Suresh Sallay detention and CID conduct

Court of Appeal to consider Former President Gotabaya Rajapaksa’s petition tomorrow

Court of Appeal to consider Former President Gotabaya Rajapaksa’s petition tomorrow

 Cabinet gives nod to secure US$ 200 million in ABD funding for infrastructure and housing projects

Cabinet gives nod to secure US$ 200 million in ABD funding for infrastructure and housing projects

 “Gotabaya’s arrest will be determined by evidence” CID responsible for Easter attacks probe: Govt.

“Gotabaya’s arrest will be determined by evidence” CID responsible for Easter attacks probe: Govt.

 Dengue infections surpass 42,000; Special dengue control program to be held in schools this week

Dengue infections surpass 42,000; Special dengue control program to be held in schools this week

Lassana Flora