Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Attackers got into Reddit’s systems in June 2018 by intercepting an employee’s SMS-based second-factor code, according to Reddit’s incident disclosure reported by SecurityWeek. The breach did not give them write access to production systems, but it exposed sensitive material, including an old database backup with account credentials and email addresses. The incident showed why enabling two-factor authentication is not enough if the second factor can be redirected or intercepted.
How the attackers got past Reddit’s two-factor authentication
The reported entry point was an employee account protected by a password and an SMS code. Reddit said the main attack was “via SMS intercept.” If an attacker has a password and can capture or redirect the texted code, the second step may not stop them from signing in.
SMS travels through telecommunications systems that can be vulnerable to interception or redirection. SecurityWeek discussed risks including SIM swapping, malware and SS7-related attacks. The specific mechanism used against Reddit’s employee was described as SMS interception; the disclosure does not establish which of those techniques was used.
NIST guidance quoted in the SecurityWeek report warns that, because SMS messages may be intercepted or redirected, implementers of new systems “SHOULD carefully consider alternative authenticators.” The lesson is not that all two-factor authentication is ineffective: it is that a second factor’s security depends on how it is delivered and whether an attacker can capture it.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What the 2018 breach exposed
Reddit reported read-only access to selected systems, not write access to production systems. The material accessed included:
- A complete copy of an old database backup containing account credentials and email addresses from 2005–2007.
- Email-digest logs covering June 3–17, 2018.
- Internal source code, logs, configuration files and employee-workspace data.
The fact that access was read-only limited what the attacker could do to those systems, but it did not make the exposed data harmless. The old backup is a reminder that credentials and personal information can remain sensitive long after the systems that created them have changed. Data-retention decisions and controls around backups matter alongside protections on live services.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How to choose a second factor
SMS codes, authenticator-app codes and FIDO2/WebAuthn security keys address different risks. A security key is the strongest option in this comparison against both intercepted SMS and real-time phishing, when the service supports it. App codes avoid the telephone-network interception problem but can still be tricked out of a user by a convincing phishing site.
| Option | SIM-swap and SMS interception | Real-time phishing | Recovery and replacement | Cost and administration | Service support |
|---|---|---|---|---|---|
| SMS code | Vulnerable to risks involving interception or redirection of text messages. | A user can be tricked into giving a code to an attacker posing as a legitimate sign-in page. | Depends on continued access to the phone number and the service’s account-recovery process. | Uses a phone number; no separate authenticator purchase is needed. | Available on services that offer text-message verification, but availability varies. |
| Authenticator-app code | Not delivered over SMS, so it avoids SIM-swap and SMS-network interception risks. | One-time codes can still be relayed to a phishing site in real time. | Requires a plan for restoring or re-enrolling the authenticator if the device is lost; exact steps depend on the service. | Typically requires installing and managing an authenticator app; service-specific setup applies. | Only works where a service supports app-generated codes. |
| FIDO2/WebAuthn security key | Does not rely on SMS delivery, so SIM swaps and SMS interception do not capture the key’s authentication. | Designed to bind authentication to the legitimate website, making it resistant to credential phishing and real-time code relay. | Keep a registered backup key or another recovery method; replacement procedures depend on the service. | Requires obtaining and registering compatible key hardware, with some added administration. | Requires service support for security keys or passkeys using FIDO2/WebAuthn. |
Reddit’s response to the 2018 incident included requiring token-based two-factor authentication for employees, alongside stronger privileged-access controls, enhanced logging and encryption. For an individual user, the practical upgrade is to choose a phishing-resistant security key where a service supports it, then keep the service’s recovery options secure. An authenticator app is a useful alternative where keys are not supported. SMS remains better than having no second factor when it is the only option, but it should not be treated as equivalent to a phishing-resistant method.
Rank #3
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
What the later Reddit phishing incident adds
In February 2023, Reddit disclosed a separate attack. The company said an attacker sent plausible prompts leading employees to a site that imitated Reddit’s intranet gateway in an attempt to steal credentials and second-factor tokens. The attacker accessed limited internal documents, code, dashboards and business information; an employee reported the incident, and Reddit removed the attacker’s access.
This was a different technique from the SMS interception reported in 2018. Together, the incidents illustrate two distinct weaknesses: a texted code can be intercepted or redirected, while a code or token entered into a convincing fake sign-in flow can be stolen through phishing. A FIDO2/WebAuthn key’s website binding addresses the latter pattern; it does not make every account-recovery route or every endpoint risk-free.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Steps users and organizations can take
For individual accounts
- Use a unique, strong password for each account and store it in a password manager. Reddit’s later security guidance recommends strong unique passwords, a password manager and two-factor authentication.
- Where available, enable a FIDO2/WebAuthn security key or passkey. If unavailable, use an authenticator app rather than SMS when the service supports it.
- Set up recovery methods deliberately. Protect recovery email accounts, store backup codes somewhere secure, and avoid relying solely on a phone number that could be transferred or lost.
- Do not enter a one-time code into a page reached from an unexpected message. Navigate to the service directly and verify the site before signing in.
For organizations
- Use phishing-resistant authentication for privileged accounts where feasible, and limit privileged access to what each role requires.
- Protect backups and internal systems with access controls and encryption; define retention periods so obsolete copies do not preserve sensitive data indefinitely.
- Keep enhanced logging in place to help identify suspicious access, and make reporting a suspected phishing attempt fast and straightforward.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

