Earlier quoted context omitted.
I cannot agree more, I do the same, and invite everyone else to do so. - Useful as a canary of which website has been breached - Useful as a canary of which website sold your details - and if your details are in the wild, you can stop the spam by deleting the address Credit cards should work the same way: a unique authorization code specific to this vendor or this transaction and useless to any other actor.
"a unique authorization code specific to this vendor or this transaction and useless to any other actor" Sounds a lot like a bitcoin address.
The Dropbox hack is real
321–330 of 557 posts
Re: The Dropbox hack is real
#322Earlier quoted context omitted.
Indeed. I would really love to recommend Keepass, but their website is really ugly and makes the impression of a non-polished software - even though Keepass is absolute mature and fine. On the other hand, the PuTTY website is also everything but polished, but people have always been using it. Also, I suspect that most people will get it through the third-party site "www.putty.org" instead of the real PuTTY website, w…
> their website is really ugly I don't think it's ugly -- just dated. Isn't it weird that mentally we trust software less if they have a dated website? Shouldn't it be the opposite? (As in: a dated website means this software is mature and tested?)
Re: The Dropbox hack is real
#323Earlier quoted context omitted.
1Password is well worth the money. It is well designed for both desktop and mobile and I am happy to pay for software that I use every day.
It absolutely blows my mind that people are okay with giving their passwords (encrypted or not, see this very breach for why that's not always enough) to a 3rd party, but are not okay reusing a password somewhere. If 1Password ever got owned, the Internet would be severely fucked. And to stem the potential flood a bit, I realize there are plenty of good counterargument built up over the years to try and combat this g…
Re: The Dropbox hack is real
#324No thanks, I'll keep control over my own data.
Re: The Dropbox hack is real
#325Earlier quoted context omitted.
the website is so poorly designed, it leads to consumer-non-adoptability.
Indeed. I would really love to recommend Keepass, but their website is really ugly and makes the impression of a non-polished software - even though Keepass is absolute mature and fine. On the other hand, the PuTTY website is also everything but polished, but people have always been using it. Also, I suspect that most people will get it through the third-party site "www.putty.org" instead of the real PuTTY website, w…
Re: The Dropbox hack is real
#326Earlier quoted context omitted.
For credit cards, check out privacy.com I recently started using it, works great.
Wondering how this works. If one is using different number per transaction where they are getting so many free numbers?
So, it seems they have some kind of partnership with a bank, which is able to generate unlimited card numbers for them.
Re: The Dropbox hack is real
#327It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could s…
I've not forgotten, and this glitch has kept me from ever considering opening a Dropbox account.
I'm surprised everyone else seems so forgiving of this massive screw up.
Re: The Dropbox hack is real
#328Earlier quoted context omitted.
Is there a service (email host) that can give you "infinite email aliases"? (Yes, I know about the '+' in gmail, but I suspect the word is out on it)
I use Google Apps for Work on my domain, which lets me forward all email to any address on that domain to my inbox. That way I can use adobe@ryanplant.net, github@ryanplant.net, fitbit@ryanplant.net, etc.
I also take this one step further and have inbox rules to automatically send all promotional email (from sites I'm interested in) to the trash folder. If I want a coupon for a website I frequent, I'll just search my trash for the latest offers from that company. Google conveniently purges messages from the trash folder every 30 days or so, and I don't have to worry about a massive backlog of promos.
Re: The Dropbox hack is real
#329Great read. He goes on to say that 1Password has a subscription now and that you should signup for it. No. I will never, ever put all my passwords into a cloud based password store. I simply do not trust them to not fuck it up at one point in time. Am I alone with this view?
1Password is not cloud based...
For some products, they are.
"Your vaults, items, and documents are fully encrypted in your 1Password Families and 1Password Teams and stored on our servers."
Re: The Dropbox hack is real
#330Earlier quoted context omitted.
For credit cards, check out privacy.com I recently started using it, works great.
This looks pretty cool, but seems like they are invite-only for now... Any chance you can drop an invite for a fellow HNer? :)