Live data from Hacker News

Quora User Data Compromised

blog.quora.com

151–160 of 525 posts

Re: Quora User Data Compromised

#151

Earlier quoted context omitted.

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

I do love lastpass but since switching to Firefox 100% away from Chrome, the lack of copying a password to the clipboard without seeing it first really stings. What if someone is sitting next to me, or someone is grabbing screenshots or streaming my screen? It's like having this super secure electrified iron door installed but neglecting to lock it. Is anyone aware of a technical reason that copy to clipboard is abse…

Install the lastpass binary in addition to the browser plugin. It re-adds that functionality back.

Re: Quora User Data Compromised

#152
post #132
post #116

Earlier quoted context omitted.

Last time I checked, both Citi and BofA give me virtual card numbers via a Flash plugin. I really have no desire to run Flash any more. Has that changed?

It hasn't changed for either one, sadly. [1] [2] [1]: https://www.bankofamerica.com/privacy/accounts-cards/shopsaf... [2]: http://www.citibank.com/transactionservices/home/card_soluti...

virtual card #s is a great system, why did it rot?

I assume it's because the whole industry prefers data-brokering your purchase history, joined on credit-card # to establish identity.

Re: Quora User Data Compromised

#153
post #148

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

Companies hate users who don't want to sign up. They do not want that relationship. So it's a win-win if you dont' sign up. Why would companies feel obligated to generate content for free? If their systems get hacked and they have your snail mail address, they get your snail mail address as well. Email doesn't change that story.

They (Quora) don't hate you if get to their site via a Google referer. That's really shameful.

Re: Quora User Data Compromised

#154
post #61
post #28

Earlier quoted context omitted.

You would be correct. In the US, which I might remind you, does not have a national law on the books regarding data breach notification. Even at the state levels, it’s varies pretty wildly on top of, most notifications are only required if there is evidence. So here is the challenge: what if I keep no logs, and have terrible security monitoring capability? If I am notified or discover a critical vulnerability on my o…

>In the US, which I might remind you, does not have a national law on the books regarding data breach notification. Our federal government is beholden to corporations, so I don't see any legislation ever happening to punish nor place a regulatory significance on breaches. If the Equifax debacle didn't move the needle, nothing will. How they didn't get a death penalty for not protecting one of the supports of our fina…

> dutifully sign up for the monitoring offered

and then the monitoring company gets breached.

I don't give any real info besides my first name to any site that doesn't have a legitimate reason to need it. If they force me to confirm an email address, depending on the site, I may use one of my main emails, or may go generate a disposable address.

Re: Quora User Data Compromised

#155
The Quora link to more details is a masterpiece of corporate obfuscation. Posing as a FAQ, it presents questions, then proceeds to not answer them (at least, as of a few minutes ago).

https://help.quora.com/hc/en-us/articles/360020212652

What happened? - not answered in any detail

What kind of user data was affected? - answered!

How do I know if I was affected? - not answered

How was it brought to your attention? - not answered

How many Quora users are affected? - not answered

Re: Quora User Data Compromised

#156
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

I moved from LastPass to 1Password recently. Had been using LastPass for several years, but filling failures, the lack of copy password in FF (and no binary workaround for Linux), and generally unhelpful support when I contacted them prompted me to move.

Very happy with 1PasswordX (the browser-only version) - filling is much better, copy is supported out of the box, support have been very helpful when I've reached out. Much better customer experience.

Re: Quora User Data Compromised

#158
post #95

Earlier quoted context omitted.

Luckily your bank and your health provider probably have decent security, because those two industries face extra heavy fines for breaches.

Yes, heavily regulated banks and medical providers have wonderful security. You can see that they do whenever they require punctuation (but not spaces or $) in the password, and demand an 8 character password (but reject anything over 16 or 24 characters). /sarcasm I especially like financial companies that have you login by using symantec VIP[1] which you append to your password. There's no way anyone thought that w…

Heavily regulated companies have a lot of Microsoft Word paperwork to fill out and months long approval cycles to wait through to get any work done, but even nastier, more bug- and vulnerability-riddled legacy codebases than the rest. Security is inextricable from software quality. Not exactly something EHR systems are known for.

Re: Quora User Data Compromised

#159
post #95

At this point I am operating on the assumption that ALL businesses that have my data are going to inadvertently leak it at some point, and thus I am attemtping to provide individual companies with as little information about me as possible. The toughest ones here are my online banking and my online health portal, but other than that, I have gotten pretty picky about what information I give any company.

Luckily your bank and your health provider probably have decent security, because those two industries face extra heavy fines for breaches.

I work in medical devices and sometimes it feels like we have so much regulation that doing the right thing is too expensive and cumbersome. I wouldn't bet on banks and medical institutions to be extra secure. And Equifax has shown that a massive breach is not really hurting the company.

Re: Quora User Data Compromised

#160

Earlier quoted context omitted.

Yes, heavily regulated banks and medical providers have wonderful security. You can see that they do whenever they require punctuation (but not spaces or $) in the password, and demand an 8 character password (but reject anything over 16 or 24 characters). /sarcasm I especially like financial companies that have you login by using symantec VIP[1] which you append to your password. There's no way anyone thought that w…

Heavily regulated companies have a lot of Microsoft Word paperwork to fill out and months long approval cycles to wait through to get any work done, but even nastier, more bug- and vulnerability-riddled legacy codebases than the rest. Security is inextricable from software quality. Not exactly something EHR systems are known for.

And fixing things is very difficult because you have to go through endless approval cycles with the approvers mostly not being security experts.
Post reply on HN