
Getty Images
Popular discussion website Reddit this week revealed another security breach resulting from a successful attack to phish employee login credentials, proving its security is still inadequate.
In a post published Thursday, Reddit’s chief technology officer, Chris “KeyserSosa” Slowe, said that after employee accounts were compromised, attackers could access source code, internal documents, internal dashboards, business systems, and accessed the contact details of hundreds of Reddit employees. According to Slowe, investigations into the breach over the past few days have found no evidence that the company’s key production systems or user password data were accessed.
“On the second half of February 5, 2023 (Pacific Standard Time), we became aware of a sophisticated phishing campaign targeting Reddit employees,” Slowe wrote. “Like most phishing campaigns, it sounds plausible that the attacker lures employees to his website that replicates the behavior of his gateway to our intranet in an attempt to steal credentials and second-factor tokens. I sent you a prompt.”
One employee fell for a scam that compromised Reddit.
This isn’t the first time Reddit’s network has been compromised by a successful credential phishing campaign. In 2018, a successful phishing attack against another of his Reddit employees resulted in sensitive data including all user content, including cryptographically salted and hashed password data, corresponding usernames, email addresses, and private messages. A mountain of user data has been stolen.
In previous breaches, phished employee accounts were protected by a weak form of two-factor authentication (2FA) that relied on one-time passwords (OTPs) sent in SMS text. His SMS-based 2FA has been frowned upon by security practitioners for years because it is vulnerable to several attack techniques. One is her so-called SIM swapping, in which an attacker controls a target’s phone number by tricking the mobile operator into forwarding it. Another phishing her OTP.
When a Reddit official uncovered the 2018 breach, he learned from the experience that “SMS-based authentication is not as secure as we’d like it to be,” and “token-based authentication for everyone here.” We point this out to encourage the transition to 2FA.”
Years later, it’s clear that Reddit still hasn’t learned the proper lessons to secure its employee verification process. Reddit didn’t disclose what kind of 2FA system he currently uses, but his admission that the attackers were successful in stealing employee second-factor tokens gives us the need to know. You can see everything there is. Credential phishing attacks.
The reasons for this susceptibility are varied. In some cases, the token is created based on a push that the employee receives during the login process (usually immediately after entering their password). Push requires the employee to click a link or a yes button. When an employee enters a password into a phishing her site, expect to receive a push. The site looks real, so employees see no reason not to click on links and buttons.
OTPs generated by authenticator apps such as Authy and Google Authenticator are similarly vulnerable. The fake site phishes not only his password but also his OTP. A quick attacker, or an automated relay on the other side of your website, will quickly enter data into the actual employee portal. So, invade the targeted company.
The best forms of 2FA available today follow an industry standard known as FIDO (Fast Identity Online). The standard allows for multiple forms of his 2FA that require physical hardware (most often a phone) near the device to log into the account. A phisher logging into an employee account is miles or continents away from the authentication device, thus failing 2FA.
FIDO 2FA goes beyond just proving possession of a registered device, and becomes even stronger when users are required to provide a facial scan or fingerprint to the authentication device. This measure enables 3FA (password, physical key possession, and fingerprint or face scan). Since biometrics never leave the authentication device (relying on fingerprints or face readers on phones), there is no privacy risk for employees.
Last year, real-world case studies of 2FA using OTP versus FIDO were published worldwide. Credential phishers used convincing spoofing of the communication platform Twilio’s employee portal and real-time relay to ensure that credentials were entered into the actual Twilio site before the OTP expired (usually OTP expires within 1 minute). reissue). After tricking one or more employees into entering their credentials, the attackers broke in and began stealing sensitive user data.
Around the same time, content delivery network Cloudflare was hit by the same phishing campaign. Three employees were tricked into entering his fake Cloudflare portal credentials, but he has one reason why the attack failed. Because for 2FA he used FIDO instead of using OTP.
In all fairness to Reddit, there is no shortage of organizations relying on 2FA, which is vulnerable to credential phishing. But as I said, Reddit has been down this road for some time. The company vowed to learn from his 2018 intrusion, but apparently drew the wrong lessons. The correct lesson is that FIDO 2FA is immune to credential phishing. OTP and Push are not.
A Reddit representative did not respond to an email requesting comment on this post.
If you’re trying to decide which service to use and are lured by sales teams or advertisements from multiple competing providers, ask if the provider’s 2FA system is FIDO compliant. All else being equal, a provider that uses FIDO to prevent network breaches is arguably the best option.