Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

51–60 of 292 posts

Re: Notes on the Celebrity Data Theft

#51
post #10
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

1Password and last pass are pretty awesome. Some people don't want to use a 3rd party and for those, I suggest KeePass databases at the very least. I have all my two-factor reset keys in KeePassX at home and all normal passwords in last pass. I actually lost a two factor code for Linode when I lost my phone with the Google authenticator app on it and having those reset codes in KeePassX was a life saver.

Agreed. Keepass + A fileshare service to sync your database to all devices is heavenly.

Re: Notes on the Celebrity Data Theft

#52
post #2

I wrote this in the other thread on the leak before it died: > Even if the leaks result from one at a time social engineering, it still really calls into question the practical security of the cloud. I doubt it's much harder to steal, e.g. confidential business documents from executives' cloud accounts than it is to steal pictures from celebrities' cloud accounts. > If I were a big organization with confidential info…

> The policy at my previous employer (we handled a lot of extremely sensitive information), was pretty draconian: data never leaves a company desktop, laptop, or blackberry.

Really? And how do these devices inter-communicate if data never leaves from anywhere to anywhere?

Burying a laptop to the ground would make it safe enough to keep out the bad guys.

Re: Notes on the Celebrity Data Theft

#53
post #8
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

Installed! I guess I knew I should use a password manager, but the analysis paralysis of figuring out which one to use is crippling. I just want someone to tell me what to do!

For everyone suffering from analysis paralysis: KeepassX, KeepassDroid, and KeepassWhateverYourPlataform.

It's not my favorite manager by any dimension, except for portability... but portability is just killer for it.

Re: Notes on the Celebrity Data Theft

#54
post #3
post #2

I wrote this in the other thread on the leak before it died: > Even if the leaks result from one at a time social engineering, it still really calls into question the practical security of the cloud. I doubt it's much harder to steal, e.g. confidential business documents from executives' cloud accounts than it is to steal pictures from celebrities' cloud accounts. > If I were a big organization with confidential info…

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

While I think using password managers with random passwords is far better than sharing the same password between every account, I've never really gotten comfortable with storing passwords in a file on my computer.

What I'd really like is a password manager hardware dongle of some kind, like the Bitcoin Trezor wallet.

Re: Notes on the Celebrity Data Theft

#55
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

aka 1PointOfFailure. Having spent several years maintaining and repairing computer systems for corporate and professional clients, I can tell you from experience that it is trivially easy to social engineer someone's credentials out of them.

I'm currently having a failure of imagination here, but how would you social engineer a password manager?

The tricks I'm thinking of involve fooling the user into thinking a site is something it's not or guessing some sort of personal information. But with a separate application the former seems unlikely and the latter is stopped if you use a scheme such as diceware (https://en.wikipedia.org/wiki/Diceware). I understand that naive, theoretical musings on security are no match for experience, so how would you break that set up?

Re: Notes on the Celebrity Data Theft

#56
post #15

While I am complete appalled by the data breach and hope that similar things never happens to anyone again I would like to propose a purely thought experiment: The hacker reported sold the nude photos of Jennifer lawrence for a mere sum of $130 using bitcoin. If we apply game theory here, these kind of data is very difficult to monetize. If you sell one copy of the data, it is then immediately distributed online for…

I believe that this applies to many products using digital distribution that meet the following: 1. The asset takes requires a significant amount of resources. 2. The asset will require all resources in order to distribute. 3. No further resources are required after distribution. Music, books, art, and even software that does not require updates would fall into this category.

See, for example, perhaps, this album from the Wu Tang Clan:

http://www.forbes.com/sites/zackomalleygreenburg/2014/05/06/...

Re: Notes on the Celebrity Data Theft

#57
post #4
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

>Dude. 1Password. Password managers only protect against certain kinds of attack. Many cloud services do not or can not properly encrypt their users' data, so having a strong password won't help in the event that your cloud provider's datacenter gets rooted.

You can't, but if you use a password manager, you can actually use different passwords on every service.

And you can use stronger passwords (if the service permits), thus if they only lost the passwords datbased (assuming it's hashed) you are still safe.

Re: Notes on the Celebrity Data Theft

#58

While I am complete appalled by the data breach and hope that similar things never happens to anyone again I would like to propose a purely thought experiment: The hacker reported sold the nude photos of Jennifer lawrence for a mere sum of $130 using bitcoin. If we apply game theory here, these kind of data is very difficult to monetize. If you sell one copy of the data, it is then immediately distributed online for…

Only someone who knows the market can maximize the profit. These pictures would make a lot of money at the hand of specific low/high (depend on the view) magazines, on someone would wanna destroy JLaw's reputation or as ransom... How much money would JLaw pay for the original files?

However, how many people do you think can answer the above questions??

It's like when someone steals a huge pile of jewelery. He steals it, but he needs the mob to sell it... Otherwise he can't monetize.

Re: Notes on the Celebrity Data Theft

#59

Earlier quoted context omitted.

aka 1PointOfFailure. Having spent several years maintaining and repairing computer systems for corporate and professional clients, I can tell you from experience that it is trivially easy to social engineer someone's credentials out of them.

I'm currently having a failure of imagination here, but how would you social engineer a password manager? The tricks I'm thinking of involve fooling the user into thinking a site is something it's not or guessing some sort of personal information. But with a separate application the former seems unlikely and the latter is stopped if you use a scheme such as diceware ( https://en.wikipedia.org/wiki/Diceware ). I under…

By getting the user to give me control of it, same as if the user was moving everything to a new computer. You don't have to do this via a website; you use a website to create a problem and then make yourself available to fix it.

Not that I'm into this sort of thing, but I've had a few people attempt to co-opt me into criminal activity in the past so I wouldn't be at all surprised to read about such attacks.

Re: Notes on the Celebrity Data Theft

#60
post #3
post #2

I wrote this in the other thread on the leak before it died: > Even if the leaks result from one at a time social engineering, it still really calls into question the practical security of the cloud. I doubt it's much harder to steal, e.g. confidential business documents from executives' cloud accounts than it is to steal pictures from celebrities' cloud accounts. > If I were a big organization with confidential info…

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

Or a text file or spreadsheet containing passwords, in a TrueCrypt container (I still trust it).
Post reply on HN