Live data from Hacker News

The Dropbox hack is real

troyhunt.com

261–270 of 557 posts

Re: The Dropbox hack is real

#261
post #92
post #69

Earlier quoted context omitted.

I have to disagree with the Authy recommendation. I switched to Authy a few years ago, but it was nothing but painful and I have recently migrated away from it. For a long time the "TouchID Prompt" was slow and buggy, but that does appear to be fixed now. The real pain point is that it managed to corrupt one of my keys (how??) and the app tries to get me to backup my keys to their servers with multiple popups (which…

a major advantage is if I throw my phone into the ocean(not a theoretical attack!) I can still recover my OTP on another machine. Authy offers this pretty nicely I would recommend testing theories of : - losing phone - losing computer - losing both and have reasonable backup strategies for these scenarios.

A good 2FA system involves backup keys which can be stored in a safe or safety deposit box, not handing your private key over to a third party.

Re: The Dropbox hack is real

#262

Earlier quoted context omitted.

> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…

My favourite was the unique email I used for a Russian visa application. Either the consulate was ridden with malware, or they just sold my address.

Were you actually at a consulate? Most russian visas are (pre)processed by private companies.

Re: The Dropbox hack is real

#263
post #76
post #40

Earlier quoted context omitted.

I cannot agree more, I do the same, and invite everyone else to do so. - Useful as a canary of which website has been breached - Useful as a canary of which website sold your details - and if your details are in the wild, you can stop the spam by deleting the address Credit cards should work the same way: a unique authorization code specific to this vendor or this transaction and useless to any other actor.

For credit cards, check out privacy.com I recently started using it, works great.

Wondering how this works. If one is using different number per transaction where they are getting so many free numbers?

Re: The Dropbox hack is real

#264

> 1Password now has a subscription service for $3 a month and you get the first 6 months for free. Don't pay for this people. Use the open source password manager Keepass http://keepass.info/

the website is so poorly designed, it leads to consumer-non-adoptability.

Re: The Dropbox hack is real

#265

Earlier quoted context omitted.

> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…

Oddly enough I have had the opposite experience. I have been running per-service emails for 10 years and wonder to myself if it is worth the bother as I can recall only one ever spreading.

That has been my experience as well. Only one alias in about 10 years ever got undeniably sold, and that was because the company went out of business and probably sold their entire portfolio.

Re: The Dropbox hack is real

#266
post #196

Earlier quoted context omitted.

> Unique-per-service email addresses work pretty well and they're so easy with Gmail - anything following a '+' character after your username (or alias, if using your own/company domain) will go to the same box, but keep the distinct address. Unfortunately, depressingly many sites validate email fields, and get it wrong - thinking '+' is not allowed. IMO it's not even worth trying to get an email regex (or other vali…

I'm pretty sure they do know a `+` is allowed...

I've encountered a number of sites that don't permit + in emails. I've also encountered a bunch that don't permit my hyphenated last name.

Re: The Dropbox hack is real

#267
post #26

It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could s…

> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…

How do you guys do this? IS there a service? Do you add na.melast@gmail Or do you create them on your own domain through the hosting company?

Re: The Dropbox hack is real

#268
post #189
post #108

Earlier quoted context omitted.

Download a password manager like Keepass, Lastpass or Password Safe: https://en.wikipedia.org/wiki/List_of_password_managers I use Keepass, it does exactly what I need. Secure the password manager itself with a long password. Put your logins into it, and generate a unique random password for each one, then go to the website in question and change the password to the new one. When you want to login to that website, op…

Is Keychain Access from OSX a safe password manager? Also, how comes all security-aware people trust 1Password and LastPass, even though they are not open source? Isn't that one of the rules of security, publish the source so we can trust it?

>all security-aware people trust 1Password and LastPass

I don't think this is true at all. Many people do not recommend using these services for exactly that reason. Plenty of so-called experts make lots of compromises in their choices and recommendations for various reasons.

Re: The Dropbox hack is real

#269

Earlier quoted context omitted.

> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…

How do you guys do this? IS there a service? Do you add na.melast@gmail Or do you create them on your own domain through the hosting company?

It's often called plus addressing. Quite a common feature in mail servers and mail services. MyName+ at gmail.com ends up in MyName's mailbox.

Re: The Dropbox hack is real

#270

Earlier quoted context omitted.

> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…

How do you guys do this? IS there a service? Do you add na.melast@gmail Or do you create them on your own domain through the hosting company?

You can use anything after a + character with Gmail.

E.g. myaddress+service1@gmail.com will go to your inbox and you can filter on it.

Post reply on HN