Live data from Hacker News

The Dropbox hack is real

troyhunt.com

491–500 of 557 posts

Re: The Dropbox hack is real

#491
post #26

It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could s…

> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…

> it taught me everything is breached

Everything is breached. From websites to software to hardware, I would estimate the majority of them can be/have been exploited by advanced hackers.

I'm awaiting the time when we all acknowledge that computers are fundamentally insecure.

Re: The Dropbox hack is real

#493

Dropbox is about the only service I use a memorable password for, as it has my 1Password file in it, which has my Google one-time-auth codes in it. If I lose my phone while on the road, only remembering my Dropbox password is going to get me out of the mess. Any sensible other solutions here? It's still ~14 characters, but other than making it more random, what are my options?

All of my passwords are based on the website name that I'm logging in to. I have a small algorithm in my head about how to generate a password from the site name that looks at stuff like first and last letter, number of letters, some kind of prefix/suffix, etc. And I end up with a unique password around 20 characters that I don't need to remember for every website. This way I don't ever remember a password, I just re…

How do you deal with websites that won't let you use >8char or certain characters?

I use this same method, but my method will often generate special characters, and AWS as an example, and several others (apparently following AWS' lead) won't let you use those. (Any punctuation not on the shift-numbers row of USA keyboards are not considered legit for password use)

I still mostly use this system, and given my lucky memory I can memorise the exceptions, but I doubt a vast majority of the population could follow my example.

Re: The Dropbox hack is real

#494
post #420

Earlier quoted context omitted.

Fun fact: Have I Been Pwned neither salts nor hashes the creds which it stores on its website, potentially making itself an interesting target for hackers[0] [0]: http://risky.biz/RB388

HIBP doesn't store passwords, it only stores usernames and email addresses.

[deleted]

Re: The Dropbox hack is real

#497

Earlier quoted context omitted.

I'm not sure how much I can trust the results of a site that claims an email address I only use for one site has been breached on sites and services I've never been to. However it's calculating if what you enter into the form appears in the leaked content sure gives a lot of false positives. Which I suppose forces more awareness, but it doesn't instill a lot of confidence.

A false positive from your perspective doesn't mean your email address isn't actually being used to sign up for things. My primary personal email address is routinely used by a small handful of other real people (all strangers) for all sorts of things - college applications, car insurance, some address books think it belongs to a cousin who gets included in a lot of group threads about reunions and full of photos. I'…

I have the same problem. Do you have any suggestions on how to handle such emails?

Re: The Dropbox hack is real

#498

I suppose this is off topic, but I checked one of my email addresses on https://haveibeenpwned.com/ and found a LinkedIn hack from May 2016. Thing is I've deleted my LinkedIn account thrice in 2013. They have no right to stop have my email after that long.

The hack is from September 2012. LinkedIn knew about it in May 2016.

Re: The Dropbox hack is real

#499
post #420

Earlier quoted context omitted.

Fun fact: Have I Been Pwned neither salts nor hashes the creds which it stores on its website, potentially making itself an interesting target for hackers[0] [0]: http://risky.biz/RB388

HIBP doesn't store passwords, it only stores usernames and email addresses.

apologies, s/"creds"/"user data"

Re: The Dropbox hack is real

#500
post #271

Earlier quoted context omitted.

You can setup wildcard alias in fastmail ( https://fastmail.com ) and literally create addresses on the fly when signing up/sharing your email.

Fastmail has a really nice subdomains feature - I have an alias in fastmail of 'shop@mydomain.com'. Any email for XXX@shop.mydomain.com gets delivered to shop+XXX@mydomain.com. Better than catchall, because all the spam gets sent to JohnSmith@mydomain.com, which is dropped.

But you can't delete that alias if you start receiving spam on it, can you?

Also like realemail+alias@gmail.com, this is really transparent to a spammer and gives away the real email.

Post reply on HN