Live data from Hacker News

The Dropbox hack is real

troyhunt.com

191–200 of 557 posts

Re: The Dropbox hack is real

#191

Earlier quoted context omitted.

I also use a Unique-per-service email address with Paypal, and I noticed that Paypal actually passes on that email address to the retailer when I pay with Paypal. I receive order confirmation emails (from those retailers) and quite a few unwanted newsletters to my unique paypal address now. I have no idea what Paypal is trying to achieve by passing on this fairly personal piece of data. I always have to enter a separ…

Paypal is great at that kind of unintentional disclosure. Six or eight years back, because I liked what she had to say, I used it to donate to someone who was then speaking under a pseudonym as a result of some fairly credible threats. Imagine my surprise when, in the process of transferring funds, Paypal showed me her full legal name and domicile address in the UI! Of course I let her know about it, and I seem to re…

This sounds like she just set up her full name and address with paypal.

It's like her giving out her email address and it being firstname.lastname@gmail.com

I'm not sure the fault lies with the service.

Re: The Dropbox hack is real

#192
post #158

Earlier quoted context omitted.

With Google Mail (and Apps) anything after a + in the first part of the address is ignored, so foo+dropbox@gmail.com would be routed to foo@gmail.com. That's the easiest way to do it that I know of. No need for managing separate aliases.

Whilst great info, unfortunately most of the sites that one would actually try to use this on don't accept addresses containing a "+" as valid. Another Google Mail trick is to use periods. Not as useful as the +, but for those sites that don't accept +, one can usually add in a few extra periods to place sites into buckets (multiple adjacent periods don't work). m.y.e.m.a.i.l@example.com

Even if they did accept it, haven't spammers figured out the pattern by now?

Re: The Dropbox hack is real

#193
post #31
post #12

Self hosting is my way to go. Had enough of this. > My wife uses a password manager. If your significant other doesn't (and I'm assuming you do by virtue of being here and being interested in security), go and get them one now! 1Password now has a subscription service for $3 a month and you get the first 6 months for free. How about...not? There are tiny open source tools for every OS. You can do it locally, save it…

I trust 1Password more than lastpass or keypassx.

I use them too, and like how they operate. They have the best update notes of any company I've seen (on Apple's App store) - enthusiastic, entertaining, detailed, consistent. None of this guarantees quality, but it certainly paints a picture of a committed team.

Re: The Dropbox hack is real

#194
post #103

Earlier quoted context omitted.

Password manager + two factor authentication whenever possible. As for the former: Opinions here differ but my recommendation would be not to trust a "cloud" password manager and employ an offline password manager instead. KeePass works great for instance and is open source and cross-platform.

While an offline password manager is inherently more secure, at some point you're either going to have to store the database on a cloud somewhere or worry about constantly keeping your databases in sync. Whether you store it in Dropbox/OneDrive/Google/etc. or use LastPass or another service, there's always going to be some risk. At present I still recommend LastPass because that way you can easily have everything syn…

I just sync my 1Password via WiFi between my phone, work computer and personal computer. It's really not that much work either. Well worth keeping the vault of the internet.

Re: The Dropbox hack is real

#196
post #26

It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could s…

    > Unique-per-service email addresses work pretty well 
and they're so easy with Gmail - anything following a '+' character after your username (or alias, if using your own/company domain) will go to the same box, but keep the distinct address.

Unfortunately, depressingly many sites validate email fields, and get it wrong - thinking '+' is not allowed.

IMO it's not even worth trying to get an email regex (or other validation) right - you're probably going to send out an activation email anyway!

Re: The Dropbox hack is real

#197
post #87
post #26

It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could s…

I've been using unique-per-service email addresses quite a while, and I maintain a list[1] of all offenders that have leaked my PII. 1. https://gist.github.com/eligrey/5084991

That's a much smaller list than I expected. I don't differentiate between those that sold and those that ignore unsubscribe (and a few that just have very contrived unsubscribe systems), but I have over a hundred per-service emails attached to disabled accounts (as aliases) to block them forever.

One that stands out in my head is Cadillac. I had requested a brochure for a CTS, and I got random unrelated spam just days later!

Re: The Dropbox hack is real

#198
post #26

It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could s…

> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…

Oddly enough I have had the opposite experience.

I have been running per-service emails for 10 years and wonder to myself if it is worth the bother as I can recall only one ever spreading.

Re: The Dropbox hack is real

#199
post #26

It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could s…

> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…

My favourite was the unique email I used for a Russian visa application. Either the consulate was ridden with malware, or they just sold my address.

Re: The Dropbox hack is real

#200

Earlier quoted context omitted.

Paypal is great at that kind of unintentional disclosure. Six or eight years back, because I liked what she had to say, I used it to donate to someone who was then speaking under a pseudonym as a result of some fairly credible threats. Imagine my surprise when, in the process of transferring funds, Paypal showed me her full legal name and domicile address in the UI! Of course I let her know about it, and I seem to re…

This sounds like she just set up her full name and address with paypal. It's like her giving out her email address and it being firstname.lastname@gmail.com I'm not sure the fault lies with the service.

It's been a while, so that might be true and I just don't remember, but it would be a surprising mistake to make for someone with a great deal of professional experience in operational security.
Post reply on HN