Live data from Hacker News

The Dropbox hack is real

troyhunt.com

81–90 of 557 posts

Re: The Dropbox hack is real

#81
Can someone in the know indicate how to BEST manage passwords for different services in a secure way in 2016? Should I be using password managers (à la 1Password, LastPassword and others), or use something like Keychain Access on Mac OS X (what are the Windows equivalents?), anything else? It's important to note that not everyone is well-educated on the matter, despite the fact that most people on HN are technical people.

EDIT: Thanks everyone for your answers, this is a good example of the power of communities.

Re: The Dropbox hack is real

#82
post #31

Earlier quoted context omitted.

I trust 1Password more than lastpass or keypassx.

Why?

For me, it's that 1Password runs locally and doesn't need to phone home, whereas LastPass is "cloud". Also, LastPass being owned by LogMeIn doesn't sit right with me, but that's definitely personal.

No idea about Keepass(x), although I found that ecosystem to be confusing, with different apps for different platforms you might accidentally download a rouge one on e.g. your phone. I know, paranoia.

Re: The Dropbox hack is real

#83
post #23

Earlier quoted context omitted.

Anyone know of automated ways to rotate all the passwords on all of our accounts across the web?

Wow, single point of failure for all my accounts, all my credential, all my personal, private and public data. I would love to use it!

I know you're being sarcastic, but with lastpass you can rotate most of your passwords.

https://blog.lastpass.com/2014/12/introducing-auto-password-...

Re: The Dropbox hack is real

#84
post #21

Earlier quoted context omitted.

It's a common feature of password managers.

Honest question: Why does any none need password managers? Does not chrome password sync or firefox sync do the job? Thanks

Chrome and Firefox are password managers :)

People use other managers for many reasons: storing passwords (and other secrets) which aren't used on a site, using them on different browsers (say, Safari on the desktop and Chrome on mobile) and lack of trust on the browser's password manager.

Also, for a long time, browsers didn't save passwords with forms marked with autocomplete=off.

Re: The Dropbox hack is real

#85

Dropbox is about the only service I use a memorable password for, as it has my 1Password file in it, which has my Google one-time-auth codes in it. If I lose my phone while on the road, only remembering my Dropbox password is going to get me out of the mess. Any sensible other solutions here? It's still ~14 characters, but other than making it more random, what are my options?

Use 2 factor authentication and rotate both passwords. I have the opposite setup - Dropbox password is random and the password manager (stored inside) is memorized. It would be harsh to lose access, but not unrecoverable.

Re: The Dropbox hack is real

#86

Earlier quoted context omitted.

Honest question: Why does any none need password managers? Does not chrome password sync or firefox sync do the job? Thanks

To generate random, strong passwords. Also not to be locked into a browser. Better actual password management (e.g. last changed). Tags. A canary of chrome did have the ability to generate random passwords, but password management in chrome is still a pain IMO. Not sure about FF, but a quick google suggests it doesn't generate random passwords automatically.

FF doesn't, but as usual, there are addons for that :)

Re: The Dropbox hack is real

#87
post #26

It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could s…

I've been using unique-per-service email addresses quite a while, and I maintain a list[1] of all offenders that have leaked my PII.

1. https://gist.github.com/eligrey/5084991

Re: The Dropbox hack is real

#89
post #26

It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could s…

My LogMeIn unique address gets tons of spam - their response was that I must have given it away elsewhere. I no longer use LogMeIn.

Re: The Dropbox hack is real

#90
post #26

It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could s…

I do the same, but some companies don't seem to be interested. I've had two different emails linked to a magazine's website and had spam to both.

When I've contacted them about it, they've been absolutely adamant that the spammer must have (twice) guessed the exact email address that I've had there.

Post reply on HN