Live data from Hacker News

My docs got dropped in the Stratfor leak

kyleisom.net

11–20 of 26 posts

Re: My docs got dropped in the Stratfor leak

#13
Why should Lulzsec be held accountable and not the ignorant/arrogant developers of the Stratfor/Mtgox/PS3 sites?

Everyone, EVERYONE, should be using something like LastPass, it makes me like MORE convenient than when I used the same password for everything and it's more secure because I have unique passwords everywhere.

As for credit card data, my understanding is that there are legal recourses for sites that store that data insecurely. Sadly, no one has taken my idea of an oauth style payments system where stealing a "credit card number" would be entirely meaningless.

Re: My docs got dropped in the Stratfor leak

#14

Why should Lulzsec be held accountable and not the ignorant/arrogant developers of the Stratfor/Mtgox/PS3 sites? Everyone, EVERYONE, should be using something like LastPass, it makes me like MORE convenient than when I used the same password for everything and it's more secure because I have unique passwords everywhere. As for credit card data, my understanding is that there are legal recourses for sites that store t…

For passwords, I typically use a Mandylion (http://mandylionlabs.com/products/token.htm). It has helped out quite a bit, the downside being I have to run a Windows VM for the token software.

Re: My docs got dropped in the Stratfor leak

#15
post #14

Why should Lulzsec be held accountable and not the ignorant/arrogant developers of the Stratfor/Mtgox/PS3 sites? Everyone, EVERYONE, should be using something like LastPass, it makes me like MORE convenient than when I used the same password for everything and it's more secure because I have unique passwords everywhere. As for credit card data, my understanding is that there are legal recourses for sites that store t…

For passwords, I typically use a Mandylion ( http://mandylionlabs.com/products/token.htm ). It has helped out quite a bit, the downside being I have to run a Windows VM for the token software.

All I'm getting is jargo overload from that page. I don't understand what that offers me over regular password generation/storage, besides having to use a VM would pretty much mean no deal unless I'm missing out on some killer feature.

Stores 50 passwords at a max of 14 characters? I have many passwords over 20 characters and have well over 200 passwords stored in LastPass. LastPass also supports two-factor auth via Google Authenticator now as well.

I really feel like I must be missing something. Its a glorified notepad? With the ability to XOR the passwords with another string for additional "protection"?

Re: My docs got dropped in the Stratfor leak

#16

Me too. I'm actually pretty pissed at Stratfor because it's a huge inconvenience. Unfortunately, I used an email address that I use on other sites, so now I have to decide whether or not to create a new email account for everywhere else, which is extremely, extremely annoying. Luckily, I used a separate password for Stratfor (12+ characters). Also, unfortunately, the cc was my main cc number, so that means I have to…

Why would you need to change your email account? As long as you don't have a compromised password, you shouldn't need to worry about it. The credit card number seems like your primary concern.

Or have people started spamming that list of emails (more so than every email address in existence gets spammed)?

Post reply on HN