Story image

User passwords and email addresses compromised in Reddit breach

02 Aug 2018

Reddit has announced that a hacker broke into a few of its systems and managed to access some user data, including some current email addresses and a 2007 database backup containing old salted and hashed passwords.

Reddit has since been conducting a painstaking investigation to figure out just what was accessed and to improve its systems and processes to prevent the incident from happening again.

Timeline

On June 19, Reddit learned that between June 14 and June 18, an attacker compromised a few employee accounts with its cloud and source code hosting providers.

Its primary access points for code and infrastructure had required two-factor authentication (2FA) via SMS-based authentication, and the main attack was via SMS intercept.

Reddit acknowledged that although it was a serious attack, the attacker did not gain write access to Reddit systems; they gained read-only access to systems that contained backup data, source code and other logs.

They were not able to alter Reddit information, and it has since taken steps to further lock down and rotate all production secrets and API keys, and to enhance logging and monitoring systems.

What was accessed

Two key areas of user data were accessed:

·       All Reddit data from 2007 and before including account credentials and email addresses

o   What was accessed: A complete copy of an old database backup containing very early Reddit user data from the site’s launch in 2005 through May 2007. In Reddit’s first years it had fewer features, so the most significant data contained in this backup are account credentials (username + salted hashed passwords), email addresses, and all content (mostly public, but also private messages) from the abovementioned timeframe.

o   How to tell if your information was included: Reddit has messaged affected users and is resetting passwords on accounts where the credentials might still be valid. Users that signed up for Reddit after 2007 are safe. Reddit is advising users to check their private messages and/or email inbox.

·       Email digests sent by Reddit in June 2018

o   What was accessed: Logs containing the email digests sent between June 3 and June 17, 2018. The logs contain the digest emails themselves. The digests connect a username to the associated email address and contain suggested posts from select popular and safe-for-work subreddits users subscribed to.

o   How to tell if your information was included: Users who don’t have an email address associated with their account or if their “email digests” user preference was unchecked during that period are not affected. Otherwise, users can search their email inbox for emails from noreply@redditmail.com between June 3-17, 2018.

As the attacker had read access to storage systems, other data was accessed such as Reddit source code, internal logs, configuration files and other employee workspace files, but these two areas are the most significant categories of user data.

What is Reddit doing about it?

Reddit has reported the issue to law enforcement and is cooperating with their investigation.

It is messaging user accounts if there’s a chance the credentials taken reflect the account’s current password, and it has taken measures to guarantee that additional points of privileged access to Reddit’s systems are more secure (e.g., enhanced logging, more encryption and requiring token-based 2FA to gain entry since it suspects weaknesses inherent to SMS-based 2FA to be the root cause of this incident.)

Webroot senior threat research analyst Tyler Moffitt says that SMS-based authentication has often been used by cybercriminals to hack celebrities.

“In this type of attack, the phone number is the weakest link.

“Cybercriminals can steal a victim’s phone number by transferring it to a different SIM card with relative ease, thereby getting access to text messages and SMS-based authentication,” Moffit says.

“For example, a cybercriminal would simply need to give a wireless provider an address, last 4 digits of a social security number, and perhaps a credit card to transfer a phone number.”

He adds, “This is exactly the type of data that is widely available on the dark web thanks to large database breaches like Equifax.”

Sonatype and HackerOne partner on open source vulnerability reporting
Without a standard for responsible disclosure, even those who want to disclose vulnerabilities responsibly can get frustrated with the process.
OutSystems and Boncode team up for better code analysis
The Boncode and OutSystems alliance aims to help organisations to build fast and feel comfortable that the work they're delivering is at peak quality levels.
Nozomi and RIoT to deliver advanced ICS security solutions to Australia
''As a specialised integrator of robust and resilient ICT and IoT solutions within Australia, we are delighted to be partnering with Nozomi Networks."
Nuance biometrics fight back against fraud
Nuance Communications has crunched the numbers and discovered that it has prevented more than US$1 billion worth of fraud from being passed on to users of its Nuance Security Suite.
SIS announces a partnership with Platform 4
“We are looking forward to a strong future in the New Zealand security industry with this global giant as our strategic partner."
Attacks targeting Cisco Webex extension explode in popularity - WatchGuard
WatchGuard's Internet Security Report for Q4 2018 also finds growing use of a new sextortion phishing malware customised to individual victims.
Developing APAC countries most vulnerable to malware - Microsoft
“As cyberattacks continue to increase in frequency and sophistication, understanding prevalent cyberthreats and how to limit their impact has become an imperative.”
Worldwide spending on security to reach $103.1bil in 2019 - IDC
Managed security services will be the largest technology category in 2019.