this post was submitted on 19 Jun 2023
25 points (100.0% liked)
Asklemmy
43946 readers
508 users here now
A loosely moderated place to ask open-ended questions
Search asklemmy ๐
If your post meets the following criteria, it's welcome here!
- Open-ended question
- Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
- Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
- Not ad nauseam inducing: please make sure it is a question that would be new to most members
- An actual topic of discussion
Looking for support?
Looking for a community?
- Lemmyverse: community search
- sub.rehab: maps old subreddits to fediverse options, marks official as such
- [email protected]: a community for finding communities
~Icon~ ~by~ ~@Double_[email protected]~
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
@Phoeniqz
@gentleman
My read was that BlackCat only got non-prod data. So perhaps it's sourcecode.
In which case.. they've likely got nothing of value other than the code used to track users.
@dismalnow having the code out there that Reddit uses to track accounts doesn't give me warm fuzzies. I'm not a technical guy but it seems that it would be better if that code had not been hacked and put in the hands of people with malicious intent. I have to defer to others on whether the hack compromises Reddit users' security.
@gentleman
And if a frog had wings...
Now that it's out, it's best for affected parties to try to determine if immediate action is required to reduce damage to themselves via reddit's mistake - and all we have is a preliminary, and likely heavily redacted report from the company foolish enough to have allowed itself to get hacked.
So far the information points to non-production data. But the truth is that nobody knows the full scope of egressed data until BlackCat proves it, or reddit runs the fastest penetration forensics team EVER.
Therefore, it's unlikely to be user information of substance unless you e been uploading photos of your taint, connected your work email address, and have pm'd your credit card number to people.
@dismalnow Maybe I should try that before I delete my Reddit account...at least the taint part. A parting gift to F u/spez. I think you proved my point. There a lot of people that read the revised terms of use and privacy policy when those came out and have an appreciation of the ramifications, but I suspect that a sizable percentage of Redditors do not. So as we are both no doubt are aware there are data-brokers that will piece together information in what we used to call a "mosaic approach" to create a profile - which is in part the cause for my concern.
@Phoeniqz