frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: 10-Year Reddit Account Hacked Despite 2FA

7•guilamu•2h ago
My 10-year Reddit account (u/guilamu) was compromised on the night of October 2-3, 2025, despite having proper security measures in place:

- Two-factor authentication enabled with authenticator app

- Unique password generated by Firefox password manager (never reused, itself protected with 2FA)

- Regular activity monitoring

- Clean 10-year history with zero moderation issues

Account statistics:

- 10 years old account

- 3,013 contributions

- 185,224 karma (likely the highest karma account on r/france, not flexing because I don't care at all about karma, just pointing out this is not a random new account)

- Zero violations or warnings in 10 years

Attack timeline (CEST):

- Night of Oct 2-3: Account compromised, attackers posted pornographic content

- Oct 3, morning: Discovered the hack, changed password immediately, warned reddit using their contact form

- Oct 3, ~2:30 PM: Received 3-day temporary ban for "vote manipulation"

- Oct 3, ~6:51 PM: Ban upgraded to permanent

- Oct 4: Submitted appeal with all evidence

- Oct 4: Appeal denied without investigation

Evidence of unauthorized access: clear logins from US IP addresses while I'm located in France and always using the same two (work/home) fixed ip address to use my account for the last 5 years at least:

- 165.123.230.107 (University of Pennsylvania)

- 167.248.80.41 (Allo Communications LLC)

Reddit's response to my appeal was simply: "your appeal will not be granted and your ban will remain in place" - no investigation, no consideration of the evidence showing compromised access from foreign IPs.

This seems to indicate either:

- A security vulnerability in Reddit's 2FA implementation

- Sophisticated cookie theft malware (though no AV detection)

- A broader security issue on Reddit's end

The most concerning aspect is that Reddit's appeal system appears to automatically deny requests without human review, even when there's clear evidence of account compromise. A decade of legitimate participation and community contribution was wiped out instantly with no recourse.

Has anyone experienced similar incidents? What are the options when legitimate account recovery appeals are automatically denied despite evidence of compromise?

Comments

digianarchist•2h ago
Reddit's appeal system should indicate if a human reviewed the decision.

Did it say the words "automation was not used in this decision" or something similar.

I have personally never seen reddit overturn a ban and they don't spend a lot of time on cases because they have so many nonpaying users it probably makes little economic sense for them to do so.

guilamu•1h ago
Thanks for your input.

No, nothing about a human intervention/automation was mentioned.

digianarchist•1h ago
The exact text is:

> Note: This decision was made without the assistance of automation.

At the end of any messages from the Admin team.

guilamu•1h ago
Thanks for the precision. No, I did not get this message.
stop50•1h ago
Maybe the UFC (Union fédérale des consommateur)can help? Some it magazines also help with these problems.

Disclaimer: i have no idea how the ufc can help or if there are french it magazines. I just looked what i could do in germany and looked at wikipedia what would be the french equivalent.

guilamu•18m ago
I really doubt it, but I'll look into it, thanks.
billy99k•39m ago
My guess is that you were unknowingly phished outvof your account.
guilamu•20m ago
It does seems like it, but I'm completely puzzled by the level of sophistication the attacker must have gone to hack my account. I mean super strong unique password + 2FA + firewall + AV? What individual can hack that? It just doesn't make any sense...
al_borland•22m ago
Appeals have always seemed like a waste of time with Reddit. It’s easier for them to just ban the account and not risk second chances. They don’t seem to really care about the users.

I was banned a few years ago over some nonsense. Probably for the best.

SMAAART•7m ago
I was also recently permanently banned by Reddit, the only reason why I can think of is because:

1. periodically like every 3-4 months I would be running a script to delete any and all posts and comments. Also every 1-2 years I would delete my account(s), and start brand-new with new accounts (to avoid doxxing).

2. I had 3 alt accounts, one for professional reasons (AI, coding, etc), one for local interests (NYC), and one for fun/shitposting. All three linked to the same email address.

3. I did not violate any rules (except for running a script), I did not upvoted/downvoted each other's posts or upvoted/downvoted the same post from different accounts, each accounts followed different subs.

IMO Reddit is cleaning up house and surely didn't like my deleting my history.

C'est la vie!

Pigsty – Battery-Included PostgreSQL Distribution as a RDS Alternative

https://pigsty.io/
1•akagusu•2m ago•0 comments

Show HN: ESIM Panel – Shopify-Like SaaS for ESIM Resellers

https://esimpanel.io/en
1•kdrmlhcn•7m ago•0 comments

The origins of hallucinations are traced in specialized brain cells

https://www.washingtonpost.com/science/2025/10/05/brain-cells-illusions-schizoaffective-disorder/
1•bookofjoe•10m ago•1 comments

The purpose of the human chin and its link to stress and cooperation

https://github.com/beakbahama/log/blob/main/docs/stress.md
1•mnm•10m ago•2 comments

Taskwarrior – What Have We Learned from running this Open Source Project?

https://taskwarrior.org/docs/advice/
1•walterbell•11m ago•0 comments

Cargo-subspace: Make rust-analyzer work better with large cargo workspaces

https://github.com/ethowitz/cargo-subspace
1•todsacerdoti•13m ago•0 comments

Ask HN: iPhone 17 buggy for anyone else?

1•escot•13m ago•1 comments

Autonomous and intelligent guide for people who are blind or have low vision

https://glidance.io/
1•geox•14m ago•0 comments

ZettaOffice – WASM LibreOffice in the Browser

https://github.com/allotropia/zetajs
1•ewuhic•16m ago•0 comments

Provoking Through Prototypes

https://grillopress.github.io/2025/10/04/provoking-through-prototypes.html
1•angrymouse•17m ago•0 comments

Blackout in Spain and Portugal 'first of its kind', report finds

https://www.bbc.com/news/articles/cg7d4vjdlrmo
1•akyuu•19m ago•0 comments

Packing the World for Longest Lines of Sight

https://tombh.co.uk/packing-world-lines-of-sight
2•tombh•19m ago•0 comments

StoryRiff – Daily Crowd Sourced Story Web Game

https://keymash.com/games/storyriff/
1•keymash•21m ago•0 comments

The Death of Industrial Design and the Era of Dull Electronics

https://hackaday.com/2025/07/23/the-death-of-industrial-design-and-the-era-of-dull-electronics/
2•CharlesW•26m ago•0 comments

Two hours of exercise a week reduces joint pain and visits to GP

https://www.theguardian.com/society/2025/oct/05/two-hours-exercise-week-reduces-joint-pain-gp-nhs
1•vinni2•26m ago•0 comments

Five Costly Legal Mistakes California Startups Should Avoid with Their Employees

https://www.sanfranciscoemploymentlawfirm.com/start-ups-legal-mistakes-with-employees-california/
2•jdenquin•27m ago•0 comments

Show HN: Orchestro – Trello for Claude Code (open-source MCP server)

https://www.orchestro.org/
1•danielepelleri•29m ago•0 comments

ESLint plugin for React Compiler users to flag manual memoization

https://github.com/BellCubeDev/eslint-plugin-react-no-manual-memo
1•BellCube•30m ago•0 comments

Drones, sabotage, surveillance: Moscow's hybrid warfare takes to the high seas

https://www.france24.com/en/europe/20251003-drones-sabotage-surveillance-moscow-s-hybrid-warfare-...
1•rntn•30m ago•0 comments

Show HN: I hate paying for GPUs while developing – this is how I solved it

https://adithyask.medium.com/write-deep-learning-code-locally-and-run-on-gpus-instantly-6f173104b334
1•Adithya-Kolavi•31m ago•0 comments

Theses on Globalization (2023)

https://branko2f7.substack.com/p/eleven-theses-on-globalization
1•mooreds•34m ago•0 comments

Scientists found the "dark matter" of electronics

https://www.sciencedaily.com/releases/2025/10/251003033928.htm
2•westurner•35m ago•1 comments

Ask HN: Any advice on pivoting out of VC-backed tech?

5•AbstractH24•35m ago•1 comments

OWASP WAFControl

https://nest.owasp.org/projects/wafcontrol
1•mooreds•36m ago•0 comments

'Perfect Days' spent pondering the Japanese potty

https://www.japantimes.co.jp/commentary/2025/09/16/japan/japans-high-tech-toilets-and-culture/
2•PaulHoule•39m ago•0 comments

A contribution to the development of Algol. (Algol W, Wirth and Hoare)

https://dl.acm.org/doi/10.1145/365696.365702
2•fanf2•39m ago•0 comments

Governor, AG and Mayor Denounce Unauthorized Troop Deployment to Oregon

https://mailchi.mp/oregon/governor-kotek-attorney-general-rayfield-mayor-wilson-denounce-unauthor...
2•pera•41m ago•1 comments

Barn to House Conversion

https://www.instructables.com/Barn-to-House-Conversion/
2•mooreds•42m ago•0 comments

Apt Down – The North Korea Files

https://phrack.org/issues/72/7_md#article
2•maximilianthe1•43m ago•0 comments

Memory access is O(N^[1/3])

https://vitalik.eth.limo/general/2025/10/05/memory13.html
2•jxmorris12•47m ago•0 comments