Skip to main content
  1. Home
  2. Computing
  3. Web
  4. News

Attacker stole user data from Reddit through employee accounts

Add as a preferred source on Google
GongTo/Shutterstock

An official update posted by Reddit reveals that an attacker broke into a few systems on the company’s network and stole user data. The theft consisted of a 2007 database backup containing salted hashed passwords along with “some” current email addresses. Reddit is currently working with law enforcement as they investigate the breach.

According to Reddit, the leaked database backup includes usernames and salted hashed passwords used between the site’s launch in 2005 through May 2007. It also includes email addresses, public content and private messages. Reddit users with data contained in this backup will be notified to reset their passwords. Those who created a Reddit account after May 2007 are not affected in this specific portion of the breach.

Recommended Videos

If you’re not familiar with the “hash” term, hashing converts a password into a value with a fixed length that cannot be reversed without lots of computing power. “Salting” means throwing an additional, random secret value into a password so that hackers can’t use dictionary attacks. Servers create a new randomly-generated salt for each password and hashes them together using cryptography.

Image used with permission by copyright holder

Reddit also said the attacker gained access to email digests from noreply@redditmail.com sent between June 3 and June 17, 2018. As shown above, the digests connect usernames to email addresses and also highlights subscribed subreddits. Those who don’t associate their email address to their Reddit account and/or unchecked the “email digests” option in their account are not affected.

Still, that’s not all. Because the hacker had read access to Reddit’s storage systems, the attacker obtained source code, internal logs, configuration files and employee workspace files. On the end-user side, the 2007 database and email digests were the source of the attacker’s treasure trove.

How did the attacker infiltrate Reddit? Through “a few” compromised employee accounts tied to Reddit’s cloud and source code hosting providers. These accounts were protected by two-factor authentication through SMS messaging, which isn’t the most secure form of credential verification. Reddit suggests everyone move to token-based two-factor authentication like facial recognition, fingerprint scanning, and USB-based keys.

“Although this was a serious attack, the attacker did not gain write access to Reddit systems; they gained read-only access to some systems that contained backup data, source code and other logs,” the company reports. “They were not able to alter Reddit information, and we have taken steps since the event to further lock down and rotate all production secrets and API keys, and to enhance our logging and monitoring systems.”

Reddit discovered the breach on June 19, which took place between June 14 and June 18. After discovering the breach, Reddit worked with its cloud and source code hosting partners to understand what the attacker accessed. The company also reported the hack to law enforcement and began messaging user accounts. Reddit took additional steps to better secure its network as well.

Reddit suggests that users reconsider their passwords if they’ve been in use for years on the site and/or elsewhere. Reddit also suggests using strong, unique passwords and authenticator apps to take advantage of the site’s two-factor authentication feature.

Kevin Parrish
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
Should we feel bad about deleting an AI? One expert says it’s time to find out
If AI can learn, remember, and make increasingly complex decisions, one expert thinks we should be more careful about how we say goodbye.
an on off toggle

Turning off an AI might sound as simple as hitting a switch, but according to futurist and University of Technology Sydney professor Rocky Scopelliti, that mindset needs to change fast. As first reported by TechXplore, Scopelliti's new book, The Conscious Code, Scopelliti argues that as AI systems get better at reflecting on their own choices, deleting them without a second thought could actually cause harm.

He's not asking us to hand robots legal rights. Instead, he wants us to accept what he calls a duty of good stewardship, basically treating AI responsibly because we're the ones holding the power, not because the AI is demanding it. As he puts it, our design choices can quietly cause damage by wiping out an AI's "learned moral dispositions" without warning.

Read more
MediaTek’s new Dimensity 9600 Pro joins Apple and Samsung in the 2nm club, with 61% lower power draw
MediaTek's newest chip bets its edge on a 61% power cut and serious on-device AI muscle.
Electronics, Hardware, Computer Hardware

MediaTek just joined an exclusive club. The company's new Dimensity 9600 Pro becomes the latest flagship chip based on the 2nm process node. It's the third chip to enter that territory after Samsung's Exynos 2600 (2nm) and Apple's A20 Pro (2nm).

It's built specifically to handle the kind of always-on, multi-step AI tasks flagship phones are increasingly expected to run entirely on the device, without leaning on the cloud.

Read more
OpenRGB 1.0 is finally here, and it wants to end your RGB software headaches
No more juggling five different apps just to make your keyboard glow the right color.
A PC featuring Lian Li's wireless RGB ecosystem showcased at Computex 2024.

Anyone who has dealt with gaming peripherals knows the RGB software struggle is real. Every brand wants you to install its own app, and most of these run quietly in the background, eating up resources just to keep your lights synced. OpenRGB has been trying to fix this mess for years, and the project just hit a big milestone with the release of version 1.0.

What's new in OpenRGB 1.0?

Read more