Live data from Hacker News

Disqus cracked – Security flaw reveals users’ e-mail addresses

cornucopia-en.cornubot.se

71–80 of 92 posts

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#71

If a political organisation was revealing the identities behind anonymous speech on a jewish forum, the world would be up in arms. If the identities on a gay board was published, Obama himself would be apologising. Now the identities of thousands of people commenting on politics in Sweden was revealed, and it's OK because "they" are the bad guys, says the extreme left organisation Researchgruppen. The slippery slope…

Being born into a jewish family isn't a choice. Being gay isn't a choice.

Being politically affiliated with hate speech IS a choice.

That is some straight up false equivalency bullshit.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#72
post #17

I don't get it, if your email address is so private then why you share it with 3rd parties? Also, why would your email address be so private if the spam filters are so efficient nowadays, what's the harm in having a public email address? Please enlighten me.

Why share it with 3rd parties? Because that's the typical method of creating an account and managing it in case you forget your password and they will typically claim that they aren't going to share it with anyone and the cost of finding an anonymous mail that they will accept is quite a bit of time. (I typically do not use my email to sign up for anything.)

Why not public? I guess it's fine if everyone knows it assuming a perfect spam filter (they aren't perfect btw) but I don't want it to be public knowledge what websites I use and what I say on those sites. Non-sinster example; I could be publicly discussing a sexual encounter and just not want the whole world to know (non-psuedonymously) that I did that.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#73
post #6

In all our worry about NSA taps, the simple fact is that gravatar and now disqus allows anyone NSA, your health insurance company, groups who dislike your group, etc., to track your blog comments, help desk comments, any comment you make around the net. Your comments to gay rights groups, anti-gay rights groups, cancer support groups, aids support groups, abortion groups, democratic politics, tea party groups, gun ri…

Really what we should be doing is explaining to people that "foo@example.com" is a valid email address and that they should use it everywhere.

I am foo@bar.com. I don't know who owns that email, but I want to preemptively apologize to them about Disqus comment responses they've received.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#74
post #29

Surely any hashing would be susceptible? Even a slower or more "secure" hash wouldn't help much, because I can take your starting known email address and find comments you have made. i.e. I can start with "bill@example.com", slowly hash that to 901e54d1 and then search google for 901e54d1 to find comments you've made. Speed isn't a big deal if I'm interested in attacking specific subsets of emails. (Which could still…

I think encryption would be the correct way, since you don't want people to be able to compute either plaintext from ciphertext or ciphertext from plaintext. You would still have to provide an encryption oracle, which would allow bruteforcing, but that could be rate limited.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#75

Earlier quoted context omitted.

So why do you feel compelled to post when you know what you are saying is old news? You just adds to the noise and make it off putting for anyone else to post that actually knows about this event including your obvious point.

Now I'm confused.. why do you feel compelled to reply? You just add to the noise.

Men = Ego.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#76

Earlier quoted context omitted.

True. A percentage of the union of Adobe and Disqus users will use the same password for both services.

But if they haven't changed their password after the Adobe hack then they're already boned, aren't they? How doe the Disqus vuln add to that?

Maybe you remembered to change your email password, but forgot to change your disqus password.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#77

If a political organisation was revealing the identities behind anonymous speech on a jewish forum, the world would be up in arms. If the identities on a gay board was published, Obama himself would be apologising. Now the identities of thousands of people commenting on politics in Sweden was revealed, and it's OK because "they" are the bad guys, says the extreme left organisation Researchgruppen. The slippery slope…

Being born into a jewish family isn't a choice. Being gay isn't a choice. Being politically affiliated with hate speech IS a choice. That is some straight up false equivalency bullshit.

The British probably thought those behind the movement that ultimately resulted in the United States were engaging in hate speech. Be careful not to use a tinted lens to evaluate the world. We all do it. I am not critical of your statement. I am merely pointing out that dissenting points of view throughout history have often met with push-back. Very often, years later, those responsible for the "hate speech" were recognized as being at the root of positive world-changing developments. Imagine the people who dared to engage in "hate speech" against the flat earth and geocentric dogma, voting rights, slavery, etc.

I am disagreeing with you on one point. Being Jewish is a choice, just like being Christian is a choice. I was born into a family, like most, with generations of religious belief. I, however, am an atheist. You don't have to be a Jew. You can have jewish culture in your life, respect it and enjoy it. That does not mean you have no choice but to also be religious. That part is a choice. Just as it is for anyone from any other religion.

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#78
post #63
post #43

Another reason to not use your real name or email address when commenting across the web.

Or you know just be a decent person and not post things you wouldn't say in person yourself.

Things like... I think gays shouldn't be beaten up and jailed in Russia for engaging in gay "propaganda?" Things that people who are under the threat of being beaten up and jailed for saying fear?

Re: Disqus cracked – Security flaw reveals users’ e-mail addresses

#79
post #17

I don't get it, if your email address is so private then why you share it with 3rd parties? Also, why would your email address be so private if the spam filters are so efficient nowadays, what's the harm in having a public email address? Please enlighten me.

I think the point isn't that the emails were exposed so much as the exposure of the emails allowed the identity of commentors to be revealed.
Post reply on HN