Live data from Hacker News

The Bare Minimum You Should Do to Protect Your Family's Data

blog.mozilla.org

41–50 of 119 posts

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#41

I expected better from Mozilla. Connecting to unsecured WiFi is mostly not a problem. Most websites and applocations encrypt traffic and the security of the channel does not matter. Plus, the recommendation to installl shady antivirus software throws the motivation of this article into doubt.

I agree. The section on "Use tough passwords and change them frequently", except for the final suggestion to use a password manager, felt like antiquated password advice.

As long as the password manager is trusted. Some are run by a single person nobody's heard of. I met a woman in Vegas who ran one and who couldn't believe that people trusted it so much.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#42

> They should be at least eight characters and have a combination of letters, numbers, and special characters, such as 5pEAzhawh$ for “five pizzas.” Obligatory xkcd telling you to not do this: https://xkcd.com/936/

I'm by no means and expert is this field, but I thought at some point I had heard that using words like the xkcd comic were actually less secure, I thought what I heard was that there is a type of dictionary search that can be more efficient in cracking those "all words" passwords (as in, you don't really have 44 bits of entropy). Again, I've got no source, and am not very knowledgeable in this space, so someone correct me.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#43

Also avoid DNA services. If one family member does it it can compromise the entire family.

"Compromise" in what sense?

I don't find any sort of value in DNA services, but I don't feel "compromised" one bit that my brother uses them.

Anyway, the idea of "family" when we get into DNA is not useful, a skilled person can track you down because a total stranger who you share great great great grandparents with uploaded their DNA into an open source DNA database, which is what happened with the Last Area Rapist.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#44
post #43

Also avoid DNA services. If one family member does it it can compromise the entire family.

"Compromise" in what sense? I don't find any sort of value in DNA services, but I don't feel "compromised" one bit that my brother uses them. Anyway, the idea of "family" when we get into DNA is not useful, a skilled person can track you down because a total stranger who you share great great great grandparents with uploaded their DNA into an open source DNA database, which is what happened with the Last Area Rapist.

If you murder someone, they might be able to find you via 32andme.

Some people would say, "Don't murder people, then!" but folks sometimes prefer, "How dare they catch you, what a violation of your privacy!"

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#46
post #22

> Use tough passwords and change them frequently. The best practice for passwords is to use real words or phrases you can remember easily — but spell them incorrectly. They should be at least eight characters and have a combination of letters, numbers, and special characters, such as 5pEAzhawh$ for “five pizzas.” The result of encouraging frequent changes: 5pEAzhawh$, 5pEAzhawh$2, 5pEAzhawh$3, 5pEAzhawh$4, 5pEAzhawh$…

Yes, they clearly didn't consult (and/or use) security researchers' most recent recommendations about passwords. Password managers have become a nearly non-negotiable necessity. Telling people just use a password manager is becoming kind of like telling developers just use source control 15 years ago. You just won't know how important they are (or the true cost/benefit) until you start using one yourself.

15 years ago?

Source control was very, very standard 15 years ago. 15 years ago I would have run, not walked, from a job if they didn't use source control.

There was no git, we used CVS, which was almost old enough to vote at that time.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#47
post #43

Also avoid DNA services. If one family member does it it can compromise the entire family.

"Compromise" in what sense? I don't find any sort of value in DNA services, but I don't feel "compromised" one bit that my brother uses them. Anyway, the idea of "family" when we get into DNA is not useful, a skilled person can track you down because a total stranger who you share great great great grandparents with uploaded their DNA into an open source DNA database, which is what happened with the Last Area Rapist.

Your brother and you share a lot of your DNA. You could be flagged by an insurance company for genes that your brother has.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#48
post #34
post #23

Earlier quoted context omitted.

Previously, from a former Mozilla developer [1]: > At best, there is negligible evidence that major non-MS AV products give a net improvement in security. More likely, they hurt security significantly; for example, see bugs in AV products listed in Google's Project Zero. These bugs indicate that not only do these products open many attack vectors, but in general their developers do not follow standard security practi…

Vulnerability is not lack of security. You need a threat actor exploiting the weakness for it to become actual insecurity.

Insecurity is having a vulnerability. Whether a threat actor exploited it and what results you can detect are part of a useless variant of Schrödingers cat that everyone prefers you focus on to sell useless software.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#49
post #43

Earlier quoted context omitted.

"Compromise" in what sense? I don't find any sort of value in DNA services, but I don't feel "compromised" one bit that my brother uses them. Anyway, the idea of "family" when we get into DNA is not useful, a skilled person can track you down because a total stranger who you share great great great grandparents with uploaded their DNA into an open source DNA database, which is what happened with the Last Area Rapist.

Your brother and you share a lot of your DNA. You could be flagged by an insurance company for genes that your brother has.

No you can't.

https://en.wikipedia.org/wiki/Genetic_Information_Nondiscrim...

And if GINA was repealed, (and it wouldn't be, it was passed the House 420-3 a and passed the Senate 95-0), the insurance companies aren't going to beat around the bush and try to hack 23andMe, they'd just demand DNA samples directly as a requirement of being insured.

Re: The Bare Minimum You Should Do to Protect Your Family's Data

#50
post #43

Earlier quoted context omitted.

"Compromise" in what sense? I don't find any sort of value in DNA services, but I don't feel "compromised" one bit that my brother uses them. Anyway, the idea of "family" when we get into DNA is not useful, a skilled person can track you down because a total stranger who you share great great great grandparents with uploaded their DNA into an open source DNA database, which is what happened with the Last Area Rapist.

If you murder someone, they might be able to find you via 32andme. Some people would say, "Don't murder people, then!" but folks sometimes prefer, "How dare they catch you, what a violation of your privacy!"

So don't use 23 and me to make sure if your relatives can get away with murder?
Post reply on HN