Beehaw
  • Communities
  • Create Post
  • search
    Search
  • Login
  • Sign Up
red ( red@feddit.de )  to Technology · 3 years ago

Alphv ransomware group claims to have hacked Reddit, threatens to leak data unless money paid and API changes reverted

feddit.de

message-square
103
link
fedilink
332

Alphv ransomware group claims to have hacked Reddit, threatens to leak data unless money paid and API changes reverted

feddit.de

red ( red@feddit.de )  to Technology · 3 years ago
message-square
103
link
fedilink
alert-triangle
You must log in or # to comment.
  • narc0tic_bird ( narc0tic_bird@beehaw.org ) 
    link
    fedilink
    arrow-up
    97
    ·
    3 years ago

    So they “broke into Reddit” back in February and contacted Reddit in April. After Reddit didn’t react they contacted them again a few days ago at this very opportunistic time.

    They never specified exactly what kind of data they stole, nor did they prove it by providing samples.

    For all we know this story could be entirely made up and they actually have nothing.

    But even if they have something, them trying to come across as the good guys in this is so weird to me. No, you’re not the good guys. You are criminals.

    • Stumblinbear ( Stumblinbear@pawb.social ) 
      link
      fedilink
      arrow-up
      34
      ·
      3 years ago

      They may be the bad guys, but they’re not necessarily bad guys

      • Kaldo ( Kaldo@kbin.social ) 
        link
        fedilink
        arrow-up
        26
        ·
        3 years ago

        “I believe you find life such a problem because you think there are good people and bad people. You’re wrong, of course. There are, always and only, the bad people, but some of them are on opposite sides.”

    • SHITPOSTING_ACCOUNT ( SHITPOSTING_ACCOUNT@feddit.de ) 
      link
      fedilink
      arrow-up
      8
      ·
      3 years ago

      February? Then I believe they have obtained a full copy of all posts and comments on the site. /s

      (For those who don’t get the joke: https://github.com/Watchful1/PushshiftDumps - full dumps of all Reddit data up to February exist, and I think archive.org has the March file too)

  • Th4tGuyII ( Th4tGuyII@kbin.social ) 
    link
    fedilink
    arrow-up
    96
    ·
    3 years ago

    I want the API changes reverted as much as any other Reddit refugees here, but I can’t stand behind this kind of malfeasant extortion.

    Not only is it blatantly obvious they’re using the API change rhetoric as a means of irritating Reddit into giving them their hush money, it also avts towards delegitimising all protest efforts made by the Subreddits thus far

    • NumbersCanBeFun ( NumbersCanBeFun@kbin.social ) 
      link
      fedilink
      arrow-up
      42
      ·
      3 years ago

      deleted by creator

      • BlueBockser ( BlueBockser@programming.dev ) 
        link
        fedilink
        arrow-up
        34
        ·
        3 years ago

        But as the text says, this extortion began 5 days before the API changes were even announced. These criminals don’t give a f*ck about the API and threaten to leak the data of those same users they’re claiming to protect.

        I think we should just ignore this, because it’s a distraction for public pressure and will only make Reddit look better - either by delegitimising the protest or by making them look like a victim instead of the perpetrator they are.

        • NumbersCanBeFun ( NumbersCanBeFun@kbin.social ) 
          link
          fedilink
          arrow-up
          18
          ·
          3 years ago

          deleted by creator

          • niktemadur ( niktemadur@kbin.social ) 
            link
            fedilink
            arrow-up
            24
            ·
            3 years ago

            I’m going to say what you did, more diplomatically:

            While I don’t condone extortion via hacking or any other means, I acknowledge that Reddit and its’ dysfunctional, incompetent corporate culture - with Huffman at the top - brought this development upon themselves.

            • NumbersCanBeFun ( NumbersCanBeFun@kbin.social ) 
              link
              fedilink
              arrow-up
              5
              ·
              3 years ago

              deleted by creator

          • Th4tGuyII ( Th4tGuyII@kbin.social ) 
            link
            fedilink
            arrow-up
            6
            ·
            3 years ago

            But when that spanking both threatens the very users they’re claiming to fight for, and threatens to delegitimise all of those user’s and moderator’s protest efforts by giving Reddit a victimhood, I think it is downright stupid to cheer that on

      • Th4tGuyII ( Th4tGuyII@kbin.social ) 
        link
        fedilink
        arrow-up
        19
        ·
        3 years ago

        Karma IS a bitch, but I for one am still not going to stand behind illegalities like this. It’s not the way.

        As I said before, these hackers don’t care. The grandstanding is their way of getting attention off the backs of the protests. All supporting these criminals does is delegitimise the real protest by making Reddit look like the victim.

        That aside, even from a practical standpoint this wouldn’t work longterm. If extorted into backpeddalling, Reddit will just quietly up their data security, and once they’ve made sure the threat of a leak is dealt with, they’ll go right on back to the API change.

        • NumbersCanBeFun ( NumbersCanBeFun@kbin.social ) 
          link
          fedilink
          arrow-up
          6
          ·
          3 years ago

          deleted by creator

    • ipkpjersi ( ipkpjersi@lemmy.one ) 
      link
      fedilink
      arrow-up
      5
      ·
      3 years ago

      While I agree with you, it’s also hard for me to feel bad for Reddit in this scenario.

      I think it’s not relevant to our cause either way and it’s something that will be forgotten about eventually even if whatever data gets leaked publicly.

      We just gotta focus on making Lemmy better and more desirable.

  • redcalcium ( redcalcium@c.calciumlabs.com ) 
    link
    fedilink
    arrow-up
    63
    ·
    3 years ago

    Ransomware operators are scum and should not be trusted, let alone paid.

    • cowvin ( cowvin@kbin.social ) 
      link
      fedilink
      arrow-up
      42
      ·
      3 years ago

      This isn’t ransomware. This is standard blackmail.

      • YMS ( YMS@kbin.social ) 
        link
        fedilink
        arrow-up
        16
        ·
        3 years ago

        Correct, but done by ransomware operators.

        • zalack ( zalack@kbin.social ) 
          link
          fedilink
          arrow-up
          19
          ·
          edit-2
          3 years ago

          Not that this isn’t scummy but my understanding is that “ransomware” refers to software that locks a user or organization out of their systems until a fee is paid, generally my encrypting the disk.

          This seems like a more traditional “hack” of a system where you get in and download data. Which makes threatening them is traditional blackmail.

          • red ( red@feddit.de ) OP
            link
            fedilink
            arrow-up
            16
            ·
            3 years ago

            The point is that Alphv is an operator of ransomware as a service (RaaS), specifically BlackCat, independent of whether they used ransomware in this specific attack (which it indeed doesn’t sound like).

            • zalack ( zalack@kbin.social ) 
              link
              fedilink
              arrow-up
              6
              ·
              3 years ago

              Oh I see. I misunderstood the comment then. Thanks for the clarification!

      • redcalcium ( redcalcium@c.calciumlabs.com ) 
        link
        fedilink
        arrow-up
        8
        ·
        3 years ago

        I’ll have more respect if the leak were done by disgruntled employees, but this attempt to leak is done by a ransomware operator who failed to extort them in the first place.

        • mobyduck648 ( mobyduck648@beehaw.org ) 
          link
          fedilink
          arrow-up
          1
          ·
          3 years ago

          deleted by creator

    • gds ( gds@kbin.social ) 
      link
      fedilink
      arrow-up
      18
      ·
      3 years ago

      Agreed they definitely shouldn’t pay these guys.

      unfolds chair

      • HopeOfTheGunblade ( HopeOfTheGunblade@kbin.social ) 
        link
        fedilink
        arrow-up
        9
        ·
        3 years ago

        Yup. They absolutely shouldn’t pay, for decision theoretic reasons, but that doesn’t mean there won’t be interesting fireworks to watch.

        • PelicanPersuader ( PelicanPersuader@beehaw.org ) 
          link
          fedilink
          arrow-up
          4
          ·
          3 years ago

          I’ll be real curious if they have browsing data or subs tied to email addresses. How many .gov emails are subbed to nothing but fetish and porn subreddits?

  • Neopolitan ( neo@lemmy.comfysnug.space ) 
    link
    fedilink
    English
    arrow-up
    62
    ·
    3 years ago

    Is it weird that I kind of want both groups to lose out here?

    • gk99 ( gk99@kbin.social ) 
      link
      fedilink
      arrow-up
      34
      ·
      3 years ago

      The enemy of my enemy is also my enemy.

      • BLAMM67 ( BLAMM67@beehaw.org ) 
        link
        fedilink
        arrow-up
        18
        ·
        3 years ago

        Maxim 29: The enemy of my enemy is my enemy’s enemy. No more. No less.

        -The Seventy Maxims of Maximally Effective Mercenaries

      • Steeve ( Steeve@lemmy.ca ) 
        link
        fedilink
        arrow-up
        14
        ·
        3 years ago

        It’s enemies all the way down

        • ID10T ( ID10T@lemmy.dbzer0.com ) 
          link
          fedilink
          arrow-up
          4
          ·
          3 years ago

          Always has been.

  • iAmTheTot ( iAmTheTot@kbin.social ) 
    link
    fedilink
    arrow-up
    43
    ·
    3 years ago

    Nah you’re not going to catch me rooting for a ransomware attacker

  • bumbly ( bumbly@readit.buzz ) 
    link
    fedilink
    arrow-up
    42
    ·
    3 years ago

    If it hurts the IPO, I’m all for it. My data on reddit is worthless anyway…

  • totorohno ( totorohno@lemmy.one ) 
    link
    fedilink
    arrow-up
    40
    ·
    3 years ago

    Fuck spez, but this is not the way. Why even ask for money if they don’t expect Reddit to pay? That cheapens their cause.

    • firebreathingbunny ( firebreathingbunny@kbin.social ) Banned
      link
      fedilink
      arrow-up
      22
      ·
      edit-2
      3 years ago

      Removed by mod

      • Rentlar ( Rentlar@beehaw.org ) 
        link
        fedilink
        arrow-up
        26
        ·
        3 years ago

  • Laille ( Laille@kbin.social ) 
    link
    fedilink
    arrow-up
    39
    ·
    3 years ago

    lol, fuck reddit, but do they expect us to cheer for them when they’re holding user data hostage? They can fuck right off too.

  • primbin ( primbin@lemmy.one ) 
    link
    fedilink
    arrow-up
    31
    ·
    3 years ago

    Is there any way to validate these claims?

    • cowvin ( cowvin@kbin.social ) 
      link
      fedilink
      arrow-up
      42
      ·
      3 years ago

      Usually what happens is that these sorts of blackmailers will leak small, verifiable pieces of data so people know they really got something. We don’t see that here, so for now there’s no reason to take them seriously yet.

      • bstix ( bstix@feddit.dk ) 
        link
        fedilink
        arrow-up
        8
        ·
        3 years ago

        It would still be really easy for Reddit to say “nah homie, thats not our data” even if it is and even if Reddit knows that it is.

        How are the hackers able to verify that the data did come from Reddit?

    • red ( red@feddit.de ) OP
      link
      fedilink
      arrow-up
      22
      ·
      3 years ago

      No. If Reddit would negotiate with them, they’d probably leak small subsets as proof that they have actual data that isn’t available publicly. But with no negotiations, there’s not really any need for that.

    • vandrw ( vandrw@mander.xyz ) 
      link
      fedilink
      arrow-up
      22
      ·
      3 years ago

      No, haha. They also didn’t bother to check what was stolen, so they could have very well gotten 80G of memes.

      • AtomicPurple ( AtomicPurple@kbin.social ) 
        link
        fedilink
        arrow-up
        33
        ·
        3 years ago

        I took that to mean no one at Reddit bothered to check what was stolen.

        • BLÅHAJ ( blahaj@beehaw.org ) 
          link
          fedilink
          arrow-up
          25
          ·
          3 years ago

          Likewise, to me I interpreted as “There was no attempt (from reddit) to find out what we took.”

        • I_Miss_Daniel ( I_Miss_Daniel@kbin.social ) 
          link
          fedilink
          arrow-up
          6
          ·
          3 years ago

          How do people even know what’s been stolen? I know if someone logged into my server and copied stuff, they only way I’d know would be higher data usage.

          • AtomicPurple ( AtomicPurple@kbin.social ) 
            link
            fedilink
            arrow-up
            11
            ·
            3 years ago

            Either server logs, or the hackers sending them part of the data they have to prove they’re ligit. I assume the latter would have happened if Reddit had shown any interest in negotiating.

      • waz ( waz@feddit.uk ) 
        link
        fedilink
        English
        arrow-up
        18
        ·
        3 years ago

        I read that to mean Reddit didn’t try to identify the stolen data, rather than the exploitists. Is that right?

    • pitninja ( stu@lemmy.pit.ninja ) 
      link
      fedilink
      arrow-up
      16
      ·
      3 years ago

      If Reddit were to reach out privately to this group, the first thing they’d probably do is ask for proof. It’s trivially easy to provide proof you’ve carried out a hack; you just present some specific information that was not public and describe what all else you have in specific enough terms they know you’re not bluffing. (Or, I suppose you could just send them your whole dump if you really want to make it clear what all you have). The only way the rest of us will be able to validate these claims is if they leak and it either matches users’ own private account info or Reddit issues a disclosure about the hack (which I’m pretty sure they’re supposed to do regardless).

    • BrooklynMan ( BrooklynMan@lemmy.ml ) Banned
      link
      fedilink
      arrow-up
      1
      ·
      3 years ago

      yeah, they could release the data, lol

  • Otome-chan ( Otome-chan@kbin.social ) 
    link
    fedilink
    arrow-up
    26
    ·
    3 years ago

    >reddit fucks over users

    >hackers fuck over users

    why do this?

    • postmeridiem ( postmeridiem@lemmy.antemeridiem.xyz ) 
      link
      fedilink
      arrow-up
      12
      ·
      3 years ago

      Money lol. If they do have it and reddit negotiates then they’ll probably expect to be offered a higher price for dropping the API demand. They are just upping the ante.

  • sourcery ( sourcery@lemmy.one ) 
    link
    fedilink
    arrow-up
    22
    ·
    3 years ago

    deleted by creator

    • tal ( tal@kbin.social ) 
      link
      fedilink
      arrow-up
      16
      ·
      3 years ago

      I kind of assumed that everything that could be logged was, and that it would be data-mined insofar as value could be extracted from it down the line.

      • StudioLE ( StudioLE@programming.dev ) 
        link
        fedilink
        arrow-up
        8
        ·
        3 years ago

        If that were the case it would likely breach GDPR.

    • Deestan ( Deestan@beehaw.org ) 
      link
      fedilink
      arrow-up
      1
      ·
      3 years ago

      Negotiating is futile. They can never prove beyond “trust me bro” that they deleted the data, nor that they kept it secret, so why would they actually follow up?

      Whatever they have, if it is good they have already sold it to several interested parties under the table, and they will continue to do so. This is just an attempt to grift out a bit of extra cash.

  • JWBananas ( JWBananas@kbin.social ) 
    link
    fedilink
    arrow-up
    22
    ·
    3 years ago

    john-oliver-cool-sarcastic.gif

    Put up or shut up

  • Rachel ( Rachel@derp.foo ) 
    link
    fedilink
    arrow-up
    19
    ·
    3 years ago

    Is there any information on what kind of data they stole? It’s a public forum with a lot of public data, it makes no sense that they negotiate about data that is already public.

    • tal ( tal@kbin.social ) 
      link
      fedilink
      arrow-up
      27
      ·
      edit-2
      3 years ago

      Well, assuming that this is even directly related to the forum, as opposed to, say, email logs from the Reddit internal email server or something, things that might not be public:

      • Private messages between users.

      • Browsing data. I mean, maybe a user only posts on /r/politics, and that’s public, but spends a lot of time browsing /r/femdom or whatever.

      • IP addresses of users. Might be able to associate multiple accounts held by a user.

      • Passwords. While hopefully stored in a salted and hashed format, so they can’t be simply trivially obtained, they can still be attacked via dictionary attacks, which is why people are told not to use short and predictable passwords.

      • Email addresses (if a user registered one)

      • Reddit has some private chat feature that I’ve never used, which I imagine is logged.

      • redcalcium ( redcalcium@c.calciumlabs.com ) 
        link
        fedilink
        arrow-up
        15
        ·
        3 years ago

        Reddit used to be open source and the password was hashed using bcrypt.

    • cowvin ( cowvin@kbin.social ) 
      link
      fedilink
      arrow-up
      14
      ·
      3 years ago

      Well they mention Github artifacts in that message so it sounds like it’s more like they may have obtained source code and that sort of non public stuff.

      • mobyduck648 ( mobyduck648@beehaw.org ) 
        link
        fedilink
        arrow-up
        12
        ·
        3 years ago

        Their code was open source until 2017 and it’s got progressively more dogshit for the end user since, I suspect if this is real it’s probably a bit juicier.

    • Otome-chan ( Otome-chan@kbin.social ) 
      link
      fedilink
      arrow-up
      7
      ·
      3 years ago

      reddit has private messaging and a chat feature as well.

  • HisNoodlyServant ( HisNoodlyServant@beehaw.org ) 
    link
    fedilink
    arrow-up
    17
    ·
    3 years ago

    80gb? That isn’t too much but guess if it’s internal information and docs could be damaging to a public offering.

    • heartlessevil ( heartlessevil@lemmy.one ) 
      link
      fedilink
      arrow-up
      28
      ·
      3 years ago

      For context, based on historical pushshift data:

      • 80gb zipped decompresses to ~1100GB of text data
      • 80gb zipped would only be the most recent ~4 months of comments

      They do indicate that the data they have is more valuable though, particularly pointing out how users are being tracked (GDPR alarm bells ringing) or censored.

    • maynarkh ( maynarkh@feddit.nl ) 
      link
      fedilink
      arrow-up
      11
      ·
      3 years ago

      Might be a single weird Bee Movie video meme as well.

  • grehund ( grehund@beehaw.org ) 
    link
    fedilink
    arrow-up
    16
    ·
    3 years ago

    Oooo, juicy. I’m looking forward to seeing how this goes down.

Technology

technology

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@beehaw.org

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:

  • Free and Open Source Software
  • Programming
  • Operating Systems

This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 196 users / day
  • 1.27K users / week
  • 2.24K users / month
  • 5.29K users / 6 months
  • 5.11K local subscribers
  • 43.6K subscribers
  • 6.38K Posts
  • 107K Comments
  • Modlog
  • mods:
  • Chris Remington ( remington@beehaw.org ) 
  • alyaza [they/she] ( alyaza@beehaw.org ) 
  • TheRtRevKaiser ( TheRtRevKaiser@beehaw.org ) 
  • gyrfalcon ( gyrfalcon@beehaw.org ) 
  • rs5th ( rs5th@beehaw.org ) 
  • coldredlight ( coldredlight@beehaw.org ) 
  • Leigh ( SemioticStandard@beehaw.org ) 
  • TheRtRevKaiser ( TheRtRevKaiser@kbin.social ) 
  • BE: 0.19.15
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code