Ransomware operators are scum and should not be trusted, let alone paid.
lol, fuck reddit, but do they expect us to cheer for them when they’re holding user data hostage? They can fuck right off too.
I wonder if u/spez ordered this hack so he can back off and save face. Of course I don’t know the context but that’s the first thing that comes to mind.
Haha suck shit!
Realizes it’s probably my data too.
Is it weird that I kind of want both groups to lose out here?
The enemy of my enemy is also my enemy.
Maxim 29: The enemy of my enemy is my enemy’s enemy. No more. No less.
-The Seventy Maxims of Maximally Effective Mercenaries
Is there any information on what kind of data they stole? It’s a public forum with a lot of public data, it makes no sense that they negotiate about data that is already public.
Well, assuming that this is even directly related to the forum, as opposed to, say, email logs from the Reddit internal email server or something, things that might not be public:
-
Private messages between users.
-
Browsing data. I mean, maybe a user only posts on /r/politics, and that’s public, but spends a lot of time browsing /r/femdom or whatever.
-
IP addresses of users. Might be able to associate multiple accounts held by a user.
-
Passwords. While hopefully stored in a salted and hashed format, so they can’t be simply trivially obtained, they can still be attacked via dictionary attacks, which is why people are told not to use short and predictable passwords.
-
Email addresses (if a user registered one)
-
Reddit has some private chat feature that I’ve never used, which I imagine is logged.
Reddit used to be open source and the password was hashed using bcrypt.
-
Fuck spez, but this is not the way. Why even ask for money if they don’t expect Reddit to pay? That cheapens their cause.
Their cause is the money. Everything else is marketing.
So they “broke into Reddit” back in February and contacted Reddit in April. After Reddit didn’t react they contacted them again a few days ago at this very opportunistic time.
They never specified exactly what kind of data they stole, nor did they prove it by providing samples.
For all we know this story could be entirely made up and they actually have nothing.
But even if they have something, them trying to come across as the good guys in this is so weird to me. No, you’re not the good guys. You are criminals.
They may be the bad guys, but they’re not necessarily bad guys
“I believe you find life such a problem because you think there are good people and bad people. You’re wrong, of course. There are, always and only, the bad people, but some of them are on opposite sides.”
Is there any way to validate these claims?
No, haha. They also didn’t bother to check what was stolen, so they could have very well gotten 80G of memes.
I took that to mean no one at Reddit bothered to check what was stolen.
How do people even know what’s been stolen? I know if someone logged into my server and copied stuff, they only way I’d know would be higher data usage.
Either server logs, or the hackers sending them part of the data they have to prove they’re ligit. I assume the latter would have happened if Reddit had shown any interest in negotiating.
I want the API changes reverted as much as any other Reddit refugees here, but I can’t stand behind this kind of malfeasant extortion.
Not only is it blatantly obvious they’re using the API change rhetoric as a means of irritating Reddit into giving them their hush money, it also avts towards delegitimising all protest efforts made by the Subreddits thus far
deleted by creator
But as the text says, this extortion began 5 days before the API changes were even announced. These criminals don’t give a f*ck about the API and threaten to leak the data of those same users they’re claiming to protect.
I think we should just ignore this, because it’s a distraction for public pressure and will only make Reddit look better - either by delegitimising the protest or by making them look like a victim instead of the perpetrator they are.
deleted by creator
I’m going to say what you did, more diplomatically:
While I don’t condone extortion via hacking or any other means, I acknowledge that Reddit and its’ dysfunctional, incompetent corporate culture - with Huffman at the top - brought this development upon themselves.