Live data from Hacker News

The Dropbox hack is real

troyhunt.com

501–510 of 557 posts

Re: The Dropbox hack is real

#502
post #396
post #392

Earlier quoted context omitted.

Non tech savvy? Everyone does this. It's practical. Sure most of us have a few passwords we reuse, but I know less than 5 people with truly unique passwords.

Considering the consequences of password breaches, it's decidedly impractical. Password managers make it very easy to have unique passwords for all websites. I don't even know any of my passwords.

I do not have the privileges to install a password manager on my work desktop PC. So that doesn't really work for me.

Re: The Dropbox hack is real

#504
post #378
post #109

Make sure you sign yourself up for something like https://haveibeenpwned.com if you haven't already. Sometimes being timely in responding to leaks can make a big difference on any further leaks.

This was a strange way to find out that I have a Tumblr account.

Lol, that was my initial thought too. Also, I obviously once had an account on vBulletin.

Re: The Dropbox hack is real

#505
http://phukhoathaiha.com/

Bệnh phụ khoa là bệnh mà đa số phụ nữ đều mắc phải ít nhất một lần trong đời, đây là bệnh viêm nhiễm ở cơ quan sinh dục nữ bao gồm cơ quan sinh dục dưới (âm hộ, âm đạo, cổ tử cung) và cơ quan sinh dục trên (tử cung, vòi trứng và buồng trứng). Tuy là bệnh mà phụ nữ thường gặp nhưng nhiều chị em thường không biết rõ những triệu chứng của bệnh phụ khoa nên rất nhiều người lầm tưởng đó là một bệnh khác. Vậy triệu chứng khi bị nhiễm bệnh phụ khoa là như thế nào?

Re: The Dropbox hack is real

#506
post #488
post #392

Earlier quoted context omitted.

Non tech savvy? Everyone does this. It's practical. Sure most of us have a few passwords we reuse, but I know less than 5 people with truly unique passwords.

Use an algorithmic password. Pick some easy to remember keyword, then work some of the letters of the website into the password so each site is unique. For example, your seed could be "horse", and your gmail password would be something like "hgomrasiel". I've been doing this for ten years and haven't forgotten a password yet. :)

I would like to do this, and I thought about using an algorithm that uses the domain name as the seed, however different sites have different password policies, and expiration times which would make this very difficult to manage in practice. I wish all sites support things like OpenID so I can have one central place to sign in with 3-factor authentication.

Re: The Dropbox hack is real

#507
post #109

Make sure you sign yourself up for something like https://haveibeenpwned.com if you haven't already. Sometimes being timely in responding to leaks can make a big difference on any further leaks.

I think it should hash entered email client-side in JS to be more trustworthy. I am a bit worried about giving my various email addresses to some random site.

Re: The Dropbox hack is real

#509
post #500

Earlier quoted context omitted.

Fastmail has a really nice subdomains feature - I have an alias in fastmail of 'shop@mydomain.com'. Any email for XXX@shop.mydomain.com gets delivered to shop+XXX@mydomain.com. Better than catchall, because all the spam gets sent to JohnSmith@mydomain.com, which is dropped.

But you can't delete that alias if you start receiving spam on it, can you? Also like realemail+alias@gmail.com, this is really transparent to a spammer and gives away the real email.

The benefit it has is that the 'shop.' subdomain can't be guessed from the DNS records. I get a lot of spam to @mydomain.com.

Of course, if someone sees my email address, they could certainly infer a new one. But I'll deal with that if and when I get singled out. I don't think the spammers often actually look at the millions of addresses they use.

If I start getting spam on a particular alias, I can set up filtering rules to delete them.

Re: The Dropbox hack is real

#510

Earlier quoted context omitted.

This scares the crap out of me. I have to remember this one, super long and complex password for my password manager. If I ever accidentally paste it somewhere else, type it in somewhere or somehow it's leaked from the password manager then I am completely screwed. This one, tiny thing can completely turn my life upside down. For sites that require security questions those are easy to game so the only way to be secur…

I use a pass phrase which is much easier to remember. I know the source material for my pass phrase so if I need to reconstruct my master password I go to the source material and convert it into the password by encoding the first letters, punctuation symbols and letters from the passphrase into the password. I need to get into the habit of exporting my password list to plaintext csv and storing it in a safe or safe d…

> I am worried about the ability for the 1Password database to be hacked if someone were able to get their hands on that.

This is one among several reasons I don't go in for any "cloud" based syncing of password managers. I use keypass and sync the file with syncthing on LAN only mode.

Post reply on HN