Thursday, August 2, 2018

Wake-up call to those who still rely on SMS-based authentication and believes it is secure (don't give up, just replace SMS with OTP apps)


According to Reddit, the unknown hacker(s) managed to gain read-only access to some of its systems that contained its users' backup data, source code, internal logs, and other files

According to Slowe, the most significant data contained in the backup was account credentials (usernames and their corresponding salted and hashed passwords), email addresses and all content including private messages.

The hack was accomplished by intercepting SMS messages that were meant to reach Reddit employees with one-time passcodes, eventually circumventing the two-factor authentication (2FA) Reddit had in place attacks.

https://thehackernews.com/2018/08/hack-reddit-account.html

No comments:

Post a Comment