Probably should’ve invested in better security instead of trying to chase tech trends like NFTs.
You mean the 100th award I could buy was starting to be overkill? /s
Thanks for the gold kind stranger! 🤮
Thanks for the puke kind strager
Thanks for the thanks thanks thanks.
May I gift you a Guilded Reddit Gold NFT Snoo Platinum Anniversary edition for only 50 USD?
No website is invulnerable. Since we know from Reddit’s godawful official app they don’t do development very well, no doubt the website also has vulnerable holes.
They didn’t access the data through a vulnerability in the code, they phished some employee credentials and access it that way.
That in itself is a vulnerability. In my company we check for impossible travel, browser variance, etc. Credentials are only one aspect of this.
True, I just interpreted your comment differently to that.
@Phoeniqz If Reddit is only announcing the hack now then that is very likely going to be a legal problem in a number of US jurisdictions, not to mention EU and others.
Great. Fuck em and if they leak it EU citizens can sue the shit out of them :)
No user data was accessed according to Reddit.
See, there is the problem, “according to reddit” they probably don’t even know themselves currently. I don’t believe them anyway.
according to Reddit
A super trustworthy source as we all know.
Hopefully they publish the data so we can add to the fediverse
The article says, the data supposedly contains information about Reddit’s tracking system. I don’t think we want that in the FediVerse
If you think this will change anything at Reddit, think again.
Reddit will not pay them or meet their demands. If they do reverse any of their API changes, it won’t be because of this. Businesses can’t been seen to be caving to ransomware groups and rightly so, as it just encourages more of these types of attacks. ALPHV is 100% trying to cash in on the current resentment towards Reddit and it shows.
We also don’t know what exactly has been accessed, as neither the group nor Reddit will confirm beyond Reddit stating that no production systems or user data was accessed. It could be 80GB of cat GIFs for all we know - I’m going to need more evidence that they have something big than a screenshot of the attacker saying “trust me bro”.