• const_void@lemmy.ml
    link
    fedilink
    English
    arrow-up
    4
    ·
    2 years ago

    Probably should’ve invested in better security instead of trying to chase tech trends like NFTs.

  • FarceMultiplier@lemmy.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 years ago

    No website is invulnerable. Since we know from Reddit’s godawful official app they don’t do development very well, no doubt the website also has vulnerable holes.

    • femboy_link.mp4@beehaw.org
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 years ago

      They didn’t access the data through a vulnerability in the code, they phished some employee credentials and access it that way.

    • Phoeniqz@lemmy.dbzer0.comOP
      link
      fedilink
      arrow-up
      1
      ·
      2 years ago

      The article says, the data supposedly contains information about Reddit’s tracking system. I don’t think we want that in the FediVerse

  • tojikomori@kbin.social
    link
    fedilink
    arrow-up
    0
    ·
    2 years ago

    I’ve seen a few sites welcome the news with glee, as though Reddit’s leadership is going to be strongly affected. That’s childish and myopic. This is bad news for everyone.

    Whether or not Reddit pays, we should assume the data will make its way into the hands of people who (further) weaponize it against Reddit’s users, e.g. people who’ve posted risque photos of themselves or shared compromising details through throwaway accounts can be doxxed or matched to their normal accounts via their IP or other common details. PMs and other private account details might contain mailing addresses and other private or compromising information, too. (Edit: as Phoeniqz points out in replies, the article author assumes this is not the case based on Reddit’s and BlackCat’s statements about the leak.)

    If Reddit knew about the breach earlier and didn’t do their due diligence to alert users, then that’s further condemnation of their leadership and priorities, but it doesn’t undo the damage this might cause users.

    If Reddit were to pay BlackCat, then it would further enrich, reward, and encourage them. If, as is more likely, it doesn’t, then the blowback it receives (especially from any high profile consequences of the leak) might encourage other companies to pay up in future.

    • Phoeniqz@lemmy.dbzer0.comOP
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      2 years ago

      From the article:

      We can be pretty sure of what to doesn’t include, and that’s user data such as account details, passwords or payment information. That’s because, from the very start, Reddit made it quite clear that the ‘live’ production systems holding such data were not breached.

      • SickIcarus@kbin.social
        link
        fedilink
        arrow-up
        1
        ·
        2 years ago

        That’s because, from the very start, Reddit made it quite clear that the ‘live’ production systems holding such data were not breached.

        Because Reddit is known for being forthright and honest…

  • gentleman@kbin.social
    link
    fedilink
    arrow-up
    0
    ·
    2 years ago

    @Phoeniqz If Reddit is only announcing the hack now then that is very likely going to be a legal problem in a number of US jurisdictions, not to mention EU and others.