Story image

User passwords and email addresses compromised in Reddit breach

02 Aug 2018

Reddit has announced that a hacker broke into a few of its systems and managed to access some user data, including some current email addresses and a 2007 database backup containing old salted and hashed passwords.

Reddit has since been conducting a painstaking investigation to figure out just what was accessed and to improve its systems and processes to prevent the incident from happening again.

Timeline

On June 19, Reddit learned that between June 14 and June 18, an attacker compromised a few employee accounts with its cloud and source code hosting providers.

Its primary access points for code and infrastructure had required two-factor authentication (2FA) via SMS-based authentication, and the main attack was via SMS intercept.

Reddit acknowledged that although it was a serious attack, the attacker did not gain write access to Reddit systems; they gained read-only access to systems that contained backup data, source code and other logs.

They were not able to alter Reddit information, and it has since taken steps to further lock down and rotate all production secrets and API keys, and to enhance logging and monitoring systems.

What was accessed

Two key areas of user data were accessed:

·       All Reddit data from 2007 and before including account credentials and email addresses

o   What was accessed: A complete copy of an old database backup containing very early Reddit user data from the site’s launch in 2005 through May 2007. In Reddit’s first years it had fewer features, so the most significant data contained in this backup are account credentials (username + salted hashed passwords), email addresses, and all content (mostly public, but also private messages) from the abovementioned timeframe.

o   How to tell if your information was included: Reddit has messaged affected users and is resetting passwords on accounts where the credentials might still be valid. Users that signed up for Reddit after 2007 are safe. Reddit is advising users to check their private messages and/or email inbox.

·       Email digests sent by Reddit in June 2018

o   What was accessed: Logs containing the email digests sent between June 3 and June 17, 2018. The logs contain the digest emails themselves. The digests connect a username to the associated email address and contain suggested posts from select popular and safe-for-work subreddits users subscribed to.

o   How to tell if your information was included: Users who don’t have an email address associated with their account or if their “email digests” user preference was unchecked during that period are not affected. Otherwise, users can search their email inbox for emails from noreply@redditmail.com between June 3-17, 2018.

As the attacker had read access to storage systems, other data was accessed such as Reddit source code, internal logs, configuration files and other employee workspace files, but these two areas are the most significant categories of user data.

What is Reddit doing about it?

Reddit has reported the issue to law enforcement and is cooperating with their investigation.

It is messaging user accounts if there’s a chance the credentials taken reflect the account’s current password, and it has taken measures to guarantee that additional points of privileged access to Reddit’s systems are more secure (e.g., enhanced logging, more encryption and requiring token-based 2FA to gain entry since it suspects weaknesses inherent to SMS-based 2FA to be the root cause of this incident.)

Webroot senior threat research analyst Tyler Moffitt says that SMS-based authentication has often been used by cybercriminals to hack celebrities.

“In this type of attack, the phone number is the weakest link.

“Cybercriminals can steal a victim’s phone number by transferring it to a different SIM card with relative ease, thereby getting access to text messages and SMS-based authentication,” Moffit says.

“For example, a cybercriminal would simply need to give a wireless provider an address, last 4 digits of a social security number, and perhaps a credit card to transfer a phone number.”

He adds, “This is exactly the type of data that is widely available on the dark web thanks to large database breaches like Equifax.”

Aerohive launches guide to cloud-managed network access control
NAC for Dummies teaches the key aspects of network access control within enterprise IT networks and how you can secure all devices on the network.
Sungard AS named DRaaS leader by Forrester
It was noted for its disaster-recovery-as-a-service solution’s ability to “serve client needs at all stages of their need for business continuity.”
Gartner: The five priorities of privacy executives
The priorities highlight the need for strategic approaches to engage with shifting regulatory, technology, customer and third-party risk trends.
emt Distribution adds risk intelligence vendor
Flashpoint has signed emt Distribution to provide channel partners in Oceania and South East Asia a solution for illicit threat actor communities.
CrowdStrike: Improving network security with cloud computing solutions
Australian spending on public cloud services is expected to reach $6.5 billion this year according to Gartner
Thycotic debunks top Privileged Access Management myths
Privileged Access encompasses access to computers, networks and network devices, software applications, digital documents and other digital assets.
Veeam reports double-digit Q1 growth
We are now focussed on an aggressive strategy to help businesses transition to cloud with Backup and Cloud Data Management solutions.
Paving the road to self-sovereign identity using blockchain
Internet users are often required to input personal information and highly-valuable data from contact numbers to email addresses to make use of the various platforms and services available online.