25 points

Is there any way to validate these claims?

permalink
report
reply
20 points

No. If Reddit would negotiate with them, they’d probably leak small subsets as proof that they have actual data that isn’t available publicly. But with no negotiations, there’s not really any need for that.

permalink
report
parent
reply
17 points

No, haha. They also didn’t bother to check what was stolen, so they could have very well gotten 80G of memes.

permalink
report
parent
reply
15 points

I read that to mean Reddit didn’t try to identify the stolen data, rather than the exploitists. Is that right?

permalink
report
parent
reply
26 points

I took that to mean no one at Reddit bothered to check what was stolen.

permalink
report
parent
reply
19 points

Likewise, to me I interpreted as “There was no attempt (from reddit) to find out what we took.”

permalink
report
parent
reply
5 points

How do people even know what’s been stolen? I know if someone logged into my server and copied stuff, they only way I’d know would be higher data usage.

permalink
report
parent
reply
34 points

Usually what happens is that these sorts of blackmailers will leak small, verifiable pieces of data so people know they really got something. We don’t see that here, so for now there’s no reason to take them seriously yet.

permalink
report
parent
reply
7 points

It would still be really easy for Reddit to say “nah homie, thats not our data” even if it is and even if Reddit knows that it is.

How are the hackers able to verify that the data did come from Reddit?

permalink
report
parent
reply
13 points

If Reddit were to reach out privately to this group, the first thing they’d probably do is ask for proof. It’s trivially easy to provide proof you’ve carried out a hack; you just present some specific information that was not public and describe what all else you have in specific enough terms they know you’re not bluffing. (Or, I suppose you could just send them your whole dump if you really want to make it clear what all you have). The only way the rest of us will be able to validate these claims is if they leak and it either matches users’ own private account info or Reddit issues a disclosure about the hack (which I’m pretty sure they’re supposed to do regardless).

permalink
report
parent
reply
12 points
*

lol, ok. i mean, even if this is true (which, eh, maybe it is), I’m not really sure it’s worth what they’re asking for it. if this threat is genuine, and they follow through, it will certainly be publically embarrassing for spez at a really bad time. but there’s zero chance he’s going to give in to their demands.

i don’t expect the data dump would contain anything particularly juicy, or these demands would have been made months ago. it’s just that it would be embarrassing for reddit (and spez) if it happened, particularly right now.

permalink
report
reply
19 points

Is there any information on what kind of data they stole? It’s a public forum with a lot of public data, it makes no sense that they negotiate about data that is already public.

permalink
report
reply
7 points

reddit has private messaging and a chat feature as well.

permalink
report
parent
reply
14 points

Well they mention Github artifacts in that message so it sounds like it’s more like they may have obtained source code and that sort of non public stuff.

permalink
report
parent
reply
10 points

Their code was open source until 2017 and it’s got progressively more dogshit for the end user since, I suspect if this is real it’s probably a bit juicier.

permalink
report
parent
reply
24 points
*

Well, assuming that this is even directly related to the forum, as opposed to, say, email logs from the Reddit internal email server or something, things that might not be public:

  • Private messages between users.

  • Browsing data. I mean, maybe a user only posts on /r/politics, and that’s public, but spends a lot of time browsing /r/femdom or whatever.

  • IP addresses of users. Might be able to associate multiple accounts held by a user.

  • Passwords. While hopefully stored in a salted and hashed format, so they can’t be simply trivially obtained, they can still be attacked via dictionary attacks, which is why people are told not to use short and predictable passwords.

  • Email addresses (if a user registered one)

  • Reddit has some private chat feature that I’ve never used, which I imagine is logged.

permalink
report
parent
reply
13 points

Reddit used to be open source and the password was hashed using bcrypt.

permalink
report
parent
reply
15 points

Oooo, juicy. I’m looking forward to seeing how this goes down.

permalink
report
reply
18 points
*

I wouldn’t give them a cent or negotiate at all either, and the public aren’t going to give a shit about how they’re being tracked.

permalink
report
reply
14 points

I kind of assumed that everything that could be logged was, and that it would be data-mined insofar as value could be extracted from it down the line.

permalink
report
parent
reply
6 points

If that were the case it would likely breach GDPR.

permalink
report
parent
reply
1 point

Negotiating is futile. They can never prove beyond “trust me bro” that they deleted the data, nor that they kept it secret, so why would they actually follow up?

Whatever they have, if it is good they have already sold it to several interested parties under the table, and they will continue to do so. This is just an attempt to grift out a bit of extra cash.

permalink
report
parent
reply

Technology

!technology@beehaw.org

Create post

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

Community stats

  • 3K

    Monthly active users

  • 3.3K

    Posts

  • 81K

    Comments