Live data from Hacker News

Quora User Data Compromised

blog.quora.com

321–330 of 525 posts

Re: Quora User Data Compromised

#321

In 2013 a quora moderator contacted me and demanded that I provide my real name, and information that my name is real or they would ban my account. I tried reasoning with them, that I just wanted to view content and did not attend to write answers or interact etc, plus, they had a valid email address and facebook profile (also fake name on facebook). They fought back "we actually want proof of your real name like a s…

The sad things is that even if you received and apology, it would mean nothing, empty words repeated over and over and over.

Companies are not people and cannot have human attributes

Re: Quora User Data Compromised

#322

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

They provide login with Google and Facebook too.

Would it be possible those logins are more secure?

Re: Quora User Data Compromised

#323
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

I use keepassx, a local password manager. I don't trust centralized online password managers with browser extensions. Huge attack surface. I copy and paste usernames and passwords.

I also do that (almost, keeweb + dropbox) and copy paste logins, but a serious problem is that you need to clear the clipboard after, otherwise any other site you visit can read it.

Re: Quora User Data Compromised

#324
> While the passwords were encrypted (hashed with a salt that varies for each user), it is generally a best practice not to reuse the same password across multiple services, and we recommend that people change their passwords if they are doing so.

According to my trusted Password Safe (https://pwsafe.org/) I call about 400 accounts my own - each one with a unique random password.

Re: Quora User Data Compromised

#325
Feels good to have left Quora and gotten confirmation that they'd wiped my account shortly after they hit mainstream. (Cannot remember exactly what happened but I think they defaulted to showing every question I visited in my public timeline or something.)

Re: Quora User Data Compromised

#326

In 2013 a quora moderator contacted me and demanded that I provide my real name, and information that my name is real or they would ban my account. I tried reasoning with them, that I just wanted to view content and did not attend to write answers or interact etc, plus, they had a valid email address and facebook profile (also fake name on facebook). They fought back "we actually want proof of your real name like a s…

It's so inconsistent. I was a Quora member for years and wrote a lot of answers as well as participating in a lot of discussions. Despite this I was never asked to confirm my identity!

I deleted my account last year (got cold feet as I was using my real name and picture and people I know IRL had started to stumble across some of my answers) but I'm sure my data is probably involved in this breach somewhow.

Re: Quora User Data Compromised

#327

In 2013 a quora moderator contacted me and demanded that I provide my real name, and information that my name is real or they would ban my account. I tried reasoning with them, that I just wanted to view content and did not attend to write answers or interact etc, plus, they had a valid email address and facebook profile (also fake name on facebook). They fought back "we actually want proof of your real name like a s…

Let me write an apology for them: "the security and privacy of your information is our utmost priority" Feel better, don't you?

And it must end with "-The Quora Team"

Because we will leak your data, but we won't bother designating a responsible spokeperson be it security officer, cto, vp of engineering or principal architect. It will be the all nebulous quora team.

Re: Quora User Data Compromised

#328
post #245

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

I got an email that included “personalization data” in the list of data types that were stolen. The help page also says that information on “actions” was stolen. Does this mean that every question or answer I’ve viewed is now in the hands of the attacker?

This is what I am wondering. Quora will email you after viewing a question with something to the effect of, “Still looking for answers to ____?”

Your email address and hashed password being exposed is one thing. That information plus your search history is quite another.

Re: Quora User Data Compromised

#330
post #152

Earlier quoted context omitted.

virtual card #s is a great system, why did it rot? I assume it's because the whole industry prefers data-brokering your purchase history, joined on credit-card # to establish identity.

That's one good reason, another is probably pushback from merchants. Having these virtual cards completely shuts down the "free-trial-we-hope-you'll-forget-and-let-us-ding-you-for-a-month-or-two" business model that's so popular for online services.

Also usability, most people just don't care enough. (which is reasonable often)
Post reply on HN