Sunday, March 26, 2023
No Result
View All Result
  • Login
NEWSLETTER
Google Publishers
  • World
    • Africa
    • China
    • Asia
    • Australia
    • India
      • राजनीति
      • राशिफल
    • Europe
    • Middle East
    • United Kingdom
  • Politics
  • Lifestyle
    • All
    • Diet and Weight Loss
    • Fashion
    • Health
    • Relationships
    Helping children early is the key: Early childhood enrichment is the missing piece to close the education gap

    Helping children early is the key: Early childhood enrichment is the missing piece to close the education gap

    Ask Amy: ‘Hot Christian woman’ seeks ‘Hot Christian Man’

    Ask Amy: ‘Hot Christian woman’ seeks ‘Hot Christian Man’

    New York doesn’t need a Trump law: Albany bill on statute of limitations changes for presidents is unnecessary and aimed at only one person

    New York doesn’t need a Trump law: Albany bill on statute of limitations changes for presidents is unnecessary and aimed at only one person

    ‘Children put at risk’ as NHS autism assessments are cut back

    ‘Children put at risk’ as NHS autism assessments are cut back

    Readers sound off on dog rescuers, windmills and library funding

    Readers sound off on dog rescuers, windmills and library funding

    Gut bacteria in babies may predict type 1 diabetes in later life, study finds

    Gut bacteria in babies may predict type 1 diabetes in later life, study finds

    I am worried that my introvert teenage son is missing out | Ask Philippa

    I am worried that my introvert teenage son is missing out | Ask Philippa

    Daily horoscope for March 26, 2023

    Daily horoscope for March 26, 2023

    Tanner Cook serves up sock-trick in Roughnecks domination over Rush

    Tanner Cook serves up sock-trick in Roughnecks domination over Rush

    Hong Kong records rise in outbreaks linked to food outlets

    Hong Kong records rise in outbreaks linked to food outlets

    Trending Tags

    • Golden Globes
    • Mr. Robot
    • MotoGP 2017
    • Climate Change
    • Flat Earth
    • food
    • Fashion
    • Diet and Weight Loss
    • Mindfulness
    • Relationships
  • Entertainment
    • All
    • Celebrities
    • Gaming
    • Music
    • Sports
    I switched from my iPhone 14 Pro but iMessage wouldn’t let me go

    I switched from my iPhone 14 Pro but iMessage wouldn’t let me go

    Warriors hope recent wins swing momentum away from ‘dangerous’ play-in

    Warriors hope recent wins swing momentum away from ‘dangerous’ play-in

    Amanda Bynes’ Psychiatric Hold Extended Another Week, Not Talking With Anyone

    Amanda Bynes’ Psychiatric Hold Extended Another Week, Not Talking With Anyone

    Actor Djimon Hounsou slams Hollywood for feeling ‘tremendously cheated’ by industry

    Actor Djimon Hounsou slams Hollywood for feeling ‘tremendously cheated’ by industry

    NBA East playoff picture: Nets jump Heat, take tiebreaker; Cavs can clinch top-six seed with win vs. Rockets

    NBA East playoff picture: Nets jump Heat, take tiebreaker; Cavs can clinch top-six seed with win vs. Rockets

    Ant Anstead Sells Laguna Beach Home

    Ant Anstead Sells Laguna Beach Home

    I was wrong: the Corsair Xeneon Flex bendable display isn’t just a gimmick

    I was wrong: the Corsair Xeneon Flex bendable display isn’t just a gimmick

    Carlos Alcaraz must dethrone Rafael Nadal and Novak Djokovic to become new king

    Carlos Alcaraz must dethrone Rafael Nadal and Novak Djokovic to become new king

    How Sony Santa Monica knocked God of War Ragnarok’s big narrative climax into shape

    How Sony Santa Monica knocked God of War Ragnarok’s big narrative climax into shape

    • Celebrities
    • Gaming
    • Movie
    • Music
    • Television
  • Sports
  • Business
    • Market
    • Media
    • Perspectives
    • Success
    • Tech
    • Videos
  • Travel
    • Destinations
    • Food & Drinks
    • Stay
  • Style
    • Architecture
    • Arts
    • Beauty
    • Design
    • Luxury
  • Tech
    Save $200 on this 86-inch LG QNED 4K TV with this flash deal | Digital Trends

    Save $200 on this 86-inch LG QNED 4K TV with this flash deal | Digital Trends

    Where to watch England vs. Ukraine live stream for free online from anywhere

    Where to watch England vs. Ukraine live stream for free online from anywhere

    Get lifetime access to unlimited web hosting for just $86 with code

    Get lifetime access to unlimited web hosting for just $86 with code

    Quordle today – hints and answers for Sunday, March 26 (game #426)

    Quordle today – hints and answers for Sunday, March 26 (game #426)

    This 77-inch LG OLED TV Just Got a Massive $1,000 Price Cut | Digital Trends

    This 77-inch LG OLED TV Just Got a Massive $1,000 Price Cut | Digital Trends

    Putin plans to store tactical nuclear weapons in Belarus

    Putin plans to store tactical nuclear weapons in Belarus

    Trending Tags

    • Sillicon Valley
    • Climate Change
    • Election Results
    • Flat Earth
    • Golden Globes
    • MotoGP 2017
    • Mr. Robot
    • AI World
    • Future
    • Gadget
    • Innovate
    • Innovative Cities
  • World
    • Africa
    • China
    • Asia
    • Australia
    • India
      • राजनीति
      • राशिफल
    • Europe
    • Middle East
    • United Kingdom
  • Politics
  • Lifestyle
    • All
    • Diet and Weight Loss
    • Fashion
    • Health
    • Relationships
    Helping children early is the key: Early childhood enrichment is the missing piece to close the education gap

    Helping children early is the key: Early childhood enrichment is the missing piece to close the education gap

    Ask Amy: ‘Hot Christian woman’ seeks ‘Hot Christian Man’

    Ask Amy: ‘Hot Christian woman’ seeks ‘Hot Christian Man’

    New York doesn’t need a Trump law: Albany bill on statute of limitations changes for presidents is unnecessary and aimed at only one person

    New York doesn’t need a Trump law: Albany bill on statute of limitations changes for presidents is unnecessary and aimed at only one person

    ‘Children put at risk’ as NHS autism assessments are cut back

    ‘Children put at risk’ as NHS autism assessments are cut back

    Readers sound off on dog rescuers, windmills and library funding

    Readers sound off on dog rescuers, windmills and library funding

    Gut bacteria in babies may predict type 1 diabetes in later life, study finds

    Gut bacteria in babies may predict type 1 diabetes in later life, study finds

    I am worried that my introvert teenage son is missing out | Ask Philippa

    I am worried that my introvert teenage son is missing out | Ask Philippa

    Daily horoscope for March 26, 2023

    Daily horoscope for March 26, 2023

    Tanner Cook serves up sock-trick in Roughnecks domination over Rush

    Tanner Cook serves up sock-trick in Roughnecks domination over Rush

    Hong Kong records rise in outbreaks linked to food outlets

    Hong Kong records rise in outbreaks linked to food outlets

    Trending Tags

    • Golden Globes
    • Mr. Robot
    • MotoGP 2017
    • Climate Change
    • Flat Earth
    • food
    • Fashion
    • Diet and Weight Loss
    • Mindfulness
    • Relationships
  • Entertainment
    • All
    • Celebrities
    • Gaming
    • Music
    • Sports
    I switched from my iPhone 14 Pro but iMessage wouldn’t let me go

    I switched from my iPhone 14 Pro but iMessage wouldn’t let me go

    Warriors hope recent wins swing momentum away from ‘dangerous’ play-in

    Warriors hope recent wins swing momentum away from ‘dangerous’ play-in

    Amanda Bynes’ Psychiatric Hold Extended Another Week, Not Talking With Anyone

    Amanda Bynes’ Psychiatric Hold Extended Another Week, Not Talking With Anyone

    Actor Djimon Hounsou slams Hollywood for feeling ‘tremendously cheated’ by industry

    Actor Djimon Hounsou slams Hollywood for feeling ‘tremendously cheated’ by industry

    NBA East playoff picture: Nets jump Heat, take tiebreaker; Cavs can clinch top-six seed with win vs. Rockets

    NBA East playoff picture: Nets jump Heat, take tiebreaker; Cavs can clinch top-six seed with win vs. Rockets

    Ant Anstead Sells Laguna Beach Home

    Ant Anstead Sells Laguna Beach Home

    I was wrong: the Corsair Xeneon Flex bendable display isn’t just a gimmick

    I was wrong: the Corsair Xeneon Flex bendable display isn’t just a gimmick

    Carlos Alcaraz must dethrone Rafael Nadal and Novak Djokovic to become new king

    Carlos Alcaraz must dethrone Rafael Nadal and Novak Djokovic to become new king

    How Sony Santa Monica knocked God of War Ragnarok’s big narrative climax into shape

    How Sony Santa Monica knocked God of War Ragnarok’s big narrative climax into shape

    • Celebrities
    • Gaming
    • Movie
    • Music
    • Television
  • Sports
  • Business
    • Market
    • Media
    • Perspectives
    • Success
    • Tech
    • Videos
  • Travel
    • Destinations
    • Food & Drinks
    • Stay
  • Style
    • Architecture
    • Arts
    • Beauty
    • Design
    • Luxury
  • Tech
    Save $200 on this 86-inch LG QNED 4K TV with this flash deal | Digital Trends

    Save $200 on this 86-inch LG QNED 4K TV with this flash deal | Digital Trends

    Where to watch England vs. Ukraine live stream for free online from anywhere

    Where to watch England vs. Ukraine live stream for free online from anywhere

    Get lifetime access to unlimited web hosting for just $86 with code

    Get lifetime access to unlimited web hosting for just $86 with code

    Quordle today – hints and answers for Sunday, March 26 (game #426)

    Quordle today – hints and answers for Sunday, March 26 (game #426)

    This 77-inch LG OLED TV Just Got a Massive $1,000 Price Cut | Digital Trends

    This 77-inch LG OLED TV Just Got a Massive $1,000 Price Cut | Digital Trends

    Putin plans to store tactical nuclear weapons in Belarus

    Putin plans to store tactical nuclear weapons in Belarus

    Trending Tags

    • Sillicon Valley
    • Climate Change
    • Election Results
    • Flat Earth
    • Golden Globes
    • MotoGP 2017
    • Mr. Robot
    • AI World
    • Future
    • Gadget
    • Innovate
    • Innovative Cities
No Result
View All Result
Google Publishers
No Result
View All Result
Home Tech

This week’s Reddit breach shows company’s security is (still) woefully inadequate

by Google Publishers
February 11, 2023
in Tech
0
This week’s Reddit breach shows company’s security is (still) woefully inadequate
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Tumblr

Getty Images

Popular discussion website Reddit proved this week that its security still isn’t up to snuff when it disclosed yet another security breach that was the result of an attack that successfully phished an employee’s login credentials.

In a post published Thursday, Reddit Chief Technical Officer Chris “KeyserSosa” Slowe said that after the breach of the employee account, the attacker accessed source code, internal documents, internal dashboards, business systems, and contact details for hundreds of Reddit employees. An investigation into the breach over the past few days, Slowe said, hasn’t turned up any evidence that the company’s primary production systems or that user password data was accessed.

“On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees,” Slowe wrote. “As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens.”

A single employee fell for the scam, and with that, Reddit was breached.

It’s not the first time a successful credential phishing campaign has led to the breach of Reddit’s network. In 2018, a successful phishing attack on another Reddit employee resulted in the theft of a mountain of sensitive user data, including cryptographically salted and hashed password data, the corresponding user names, email addresses, and all user content, including private messages.

In that earlier breach, the phished employee’s account was protected by a weak form of two-factor authentication (2FA) that relied on one-time passwords (OTP) sent in an SMS text. Security practitioners have frowned on SMS-based 2FA for years because it’s vulnerable to several attack techniques. One is so-called SIM swapping, in which attackers take control of a targeted phone number by tricking the mobile carrier into transferring it. The other phishes the OTP.

Advertisement

When Reddit officials disclosed the 2018 breach, they said that the experience taught them that “SMS-based authentication is not nearly as secure as we would hope” and, “We point this out to encourage everyone here to move to token-based 2FA.”

Fast-forward a few years and it’s obvious Reddit still hasn’t learned the right lessons about securing employee authentication processes. Reddit didn’t disclose what kind of 2FA system it uses now, but the admission that the attacker was successful in stealing the employee’s second-factor tokens tells us everything we need to know—that the discussion site continues to use 2FA that’s woefully susceptible to credential phishing attacks.

The reason for this susceptibility can vary. In some cases the tokens are based on pushes that employees receive during the login process, usually immediately after entering their passwords. The push requires an employee to click a link or a “yes” button. When an employee enters the password into a phishing site, they have every expectation of receiving the push. Because the site looks genuine, the employee has no reason not to click the link or button.

OTPs generated by an authenticator app such as Authy or Google Authenticator are similarly vulnerable. The fake site not only phishes the password, but also the OTP. A fast-fingered attacker, or an automated relay on the other end of the website, quickly enters the data into the real employee portal. With that, the targeted company is breached.

The best form of 2FA available now complies with an industry standard known as FIDO (Fast Identity Online). The standard allows for multiple forms of 2FA that require a physical piece of hardware, most often a phone, to be near the device logging in to the account. Since the phishers logging in to the employee account are miles or continents away from the authenticating device, the 2FA fails.

FIDO 2FA can be made even stronger if, besides proving possession of the enrolled device, the user must also provide a facial scan or fingerprint to the authenticator device. This measure allows for 3FA (a password, possession of a physical key, and a fingerprint or facial scan). Since the biometrics never leave the authenticating device (since it relies on the fingerprint or face reader on the phone), there’s no privacy risk to the employee.

Advertisement

Last year, the world got a real-world case study in the contrast between 2FA with OTPs and FIDO. Credential phishers used a convincing impostor of the employee portal for security firm Twilio and a real-time relay to ensure the credentials were entered into the real Twilio site before the OTP expired (typically, OTPs are valid for a minute or less after they’re issued). After tricking one or more employees into entering their credentials, the attackers were in and proceeded to steal sensitive user data.

Around the same time, content delivery network Cloudflare was hit by the same phishing campaign. While three employees were tricked into entering their credentials into the fake Cloudflare portal, the attack failed for one simple reason: rather than relying on OTPs for 2FA, the company used FIDO.

To be fair to Reddit, there’s no shortage of organizations that rely on 2FA that’s vulnerable to credential phishing. But as already noted, Reddit has been down this path before. The company vowed to learn from its 2018 intrusion, but clearly it drew the wrong lesson. The right lesson is: FIDO 2FA is immune to credential phishing. OTPs and pushes aren’t.

Reddit representatives didn’t respond to an email seeking comment for this post.

People who are trying to decide what service to use and are being courted by sales teams or ads from multiple competing providers would do well to ask if the provider’s 2FA systems are FIDO-compliant. Everything else being equal, the provider using FIDO to prevent network breaches is hands down the best option.

Google Publishers

Google Publishers

Related Posts

Save $200 on this 86-inch LG QNED 4K TV with this flash deal | Digital Trends
Tech

Save $200 on this 86-inch LG QNED 4K TV with this flash deal | Digital Trends

by Google Publishers
March 26, 2023

LG is one of the best OLED TV manufacturers out there right now, so we love seeing big discounts on...

Where to watch England vs. Ukraine live stream for free online from anywhere
Tech

Where to watch England vs. Ukraine live stream for free online from anywhere

by Google Publishers
March 26, 2023

When you buy through our links, Insider may earn an affiliate commission. Learn more.This could be a tasty game in...

Get lifetime access to unlimited web hosting for just $86 with code

Get lifetime access to unlimited web hosting for just $86 with code

March 26, 2023
Next Post
Comcast becomes the latest ISP caught providing false coverage data to the FCC

Comcast becomes the latest ISP caught providing false coverage data to the FCC

Recommended

Magna Announces Senior Notes Offerings

Magna Announces Senior Notes Offerings

3 weeks ago
Love HBO’s ‘The Last of Us’? Here’s where you can buy the game that inspired it.

Love HBO’s ‘The Last of Us’? Here’s where you can buy the game that inspired it.

2 months ago

Popular News

  • Na Na Na ( Official Song ) Osekhon Ft – Tej Gill

    Na Na Na ( Official Song ) Osekhon Ft – Tej Gill

    0 shares
    Share 0 Tweet 0
  • Bundles – Go Bad Bitch Go Bad Bitch Go (TikTok Remix)

    0 shares
    Share 0 Tweet 0
  • Zubair_Nawaz_New_Song_2022_|_Dunya_|_Pashto_new_song_2022_

    0 shares
    Share 0 Tweet 0
  • conscience x Ashtin Larold – I Made A TikTok (Tiktok remix) “you that kid from tiktok”🔥

    0 shares
    Share 0 Tweet 0
  • Ser Nai Palosda – ammy virk – latest new punjabi song 2022

    0 shares
    Share 0 Tweet 0

Connect with us

Facebook Twitter Youtube RSS

About Us

GOOGLE PUBLISHERS NETWORK is the largest local-to-national digital media organization in the country. Our national flagship brand, sits at the center of the NETWORK, surrounded by hundreds of local media properties reporting on the stories and cultural moments happening across America and in our communities.

Recent News

Korean fund house Mirae Asset eyes Rs 1.5 trillion AUM by December

Korean fund house Mirae Asset eyes Rs 1.5 trillion AUM by December

March 26, 2023
I switched from my iPhone 14 Pro but iMessage wouldn’t let me go

I switched from my iPhone 14 Pro but iMessage wouldn’t let me go

March 26, 2023
A judge sided with publishers in a lawsuit over the Internet Archive’s online library

A judge sided with publishers in a lawsuit over the Internet Archive’s online library

March 26, 2023

Site Links

  • About Us
  • Corrections & Clarifications
  • Ethical Principles
  • Privacy Policy
  • Terms & Conditions
  • Contact

© 2023 Google Publishers -

No Result
View All Result
  • World
    • Africa
    • China
    • Asia
    • Australia
    • India
      • राजनीति
      • राशिफल
    • Europe
    • Middle East
    • United Kingdom
  • Politics
  • Lifestyle
    • food
    • Fashion
    • Diet and Weight Loss
    • Mindfulness
    • Relationships
  • Entertainment
    • Celebrities
    • Gaming
    • Movie
    • Music
    • Television
  • Sports
  • Business
    • Market
    • Media
    • Perspectives
    • Success
    • Tech
    • Videos
  • Travel
    • Destinations
    • Food & Drinks
    • Stay
  • Style
    • Architecture
    • Arts
    • Beauty
    • Design
    • Luxury
  • Tech
    • AI World
    • Future
    • Gadget
    • Innovate
    • Innovative Cities

© 2023 Google Publishers -

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In