Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

61–70 of 292 posts

Re: Notes on the Celebrity Data Theft

#61
post #26

Earlier quoted context omitted.

TouchID.

Yeah, how about the first time? I mean, I do not buy apps all the time, maybe once a week. And I'd have my battery dead or something like that in between those attempts. So, I never had a chance to just hold my thumb on the home button and go my way.

This is really easy. You have one good password for 1pass, and one good password for iCloud.

If you can manage to memorize one, you can memorize two.

Re: Notes on the Celebrity Data Theft

#62
i have to laugh at all this shit.

these celebutards have been posing nude of decades and crave the attention and the “me too” sluttiness of it all.

all it takes is for ANY women to catch their fuck-partners with nudies of some other freak for a women to join the party and start snapping away.

in fact, every chick i know loves taking butt-naked selfies of their twats and asses and sends them to every dude they are interested in dorking.

its a cootche arms race, plain and simple

who in the hell in this day, ESP CELEBRITIES, and age thinks digital privacy exists??

Re: Notes on the Celebrity Data Theft

#63

i have to laugh at all this shit. these celebutards have been posing nude of decades and crave the attention and the “me too” sluttiness of it all. all it takes is for ANY women to catch their fuck-partners with nudies of some other freak for a women to join the party and start snapping away. in fact, every chick i know loves taking butt-naked selfies of their twats and asses and sends them to every dude they are int…

Please don't post

Re: Notes on the Celebrity Data Theft

#64
post #28
post #24

Reddit should not be listed among the sites hosting the stolen images, as reddit does not support image uploads. Imgur is the primary site hosting the stolen images in that case.

Are we still unable to move past this pedantic hosting-vs-linking nitpicking? It's like you willfully ignore how content discovery works on the Internet.

Just to be pedantic: By the same logic, Google is also grossly hosting tonnes of illegal material.

Re: Notes on the Celebrity Data Theft

#65

i have to laugh at all this shit. these celebutards have been posing nude of decades and crave the attention and the “me too” sluttiness of it all. all it takes is for ANY women to catch their fuck-partners with nudies of some other freak for a women to join the party and start snapping away. in fact, every chick i know loves taking butt-naked selfies of their twats and asses and sends them to every dude they are int…

Please don't post

why does reality somehow offend you?

Re: Notes on the Celebrity Data Theft

#66
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

While I think using password managers with random passwords is far better than sharing the same password between every account, I've never really gotten comfortable with storing passwords in a file on my computer. What I'd really like is a password manager hardware dongle of some kind, like the Bitcoin Trezor wallet.

It doesn't matter. If you have malware lurking in your computer it will just snarf your passwords from the wire and then you're owned all the same. If you use some sort of auth signing system, the request can just be intercepted and modified on the fly.[0] The Trezor is next to useless even for bitcoin for this very reason. Sure they can't steal your money directly, but just replacing the addresses you see and send to accomplishes exactly the same thing. If your platform isn't trusted, no amount if smart crypto or hardware dongles can make it safe.[1]

[0]: The rebuttal for this will be signing every request with details of it with a hardware dongle, but would you want to do this for every action in your email client? If the answer is "no", you're owned. Ultimate security is unusable, and doesn't really solve anything outside of the most astute of professional users. Just writing this post I would need 4 signatures, one to log in, one to post, one to fix a typo, and yet another to add this footnote. Would I be able to handle that? No way, I'm far too lazy for that.

[1]: The issue is that perfect compromise is impossible to detect. I can be reasonably confident on a heavily sandboxed device like an iPhone that there's little in the way of malware that would affect me. The downside being that I have no tools or methods of analysis if I thought it was compromised. There's no such confidence on the computers I use on a daily basis. I've always thought we have confirmation bias with malicious software. We only notice the dumb stuff while the smart goes unnoticed.

Re: Notes on the Celebrity Data Theft

#67

While I am complete appalled by the data breach and hope that similar things never happens to anyone again I would like to propose a purely thought experiment: The hacker reported sold the nude photos of Jennifer lawrence for a mere sum of $130 using bitcoin. If we apply game theory here, these kind of data is very difficult to monetize. If you sell one copy of the data, it is then immediately distributed online for…

[deleted]

Re: Notes on the Celebrity Data Theft

#68
post #7

Why is nobody talking about password reset questions?

I hate those so much. They lock me out of my accounts more often than they help. I always enter bogus answers because I think I'll never need to use the feature, then I run into a situation like:

"Resetting your password via email? Ok, you also have to answer these security questions that you entered 'akjhdhksdfsdf' into when you made your account!"

or

"You've logged in from a new computer! Please try to remember what you thought your favorite band was 4 years ago. You have 3 tries remaining."

Shit people, if you want me to write this stuff down, at least tell me when I'm creating my account that you basically expect me to have 4 passwords.

Re: Notes on the Celebrity Data Theft

#69
post #56
post #15

Earlier quoted context omitted.

I believe that this applies to many products using digital distribution that meet the following: 1. The asset takes requires a significant amount of resources. 2. The asset will require all resources in order to distribute. 3. No further resources are required after distribution. Music, books, art, and even software that does not require updates would fall into this category.

See, for example, perhaps, this album from the Wu Tang Clan: http://www.forbes.com/sites/zackomalleygreenburg/2014/05/06/...

That's a very interesting read, and I'll have to give some thought to the implications therein.

I was originally thinking of something more along the lines of Radiohead's In Rainbows, released online for a donation, but may combined with a kickstarter-like fundraising effort to pay the upfront costs.

http://en.wikipedia.org/wiki/In_Rainbows

Re: Notes on the Celebrity Data Theft

#70
post #10
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

1Password and last pass are pretty awesome. Some people don't want to use a 3rd party and for those, I suggest KeePass databases at the very least. I have all my two-factor reset keys in KeePassX at home and all normal passwords in last pass. I actually lost a two factor code for Linode when I lost my phone with the Google authenticator app on it and having those reset codes in KeePassX was a life saver.

I've seen this argument come up before and I don't understand it. Why do you trust KeePass more than 1Password? In both cases you are sharing the datafile however you'd like (Dropbox, thumbdrive, etc...). The primary difference is if you have access to the source code or not.

If KeePass purposefully injected a vulnerability, it would just be that dev/project that would fail. If 1Password were to do the same, that company and all the people that work for it would go down. I'd personally see this as more of a reason to trust 1Password over KeePass.

The primary argument is that the code is open and you can audit it, but in reality that doesn't really happen unless there is a real drive to do it (like we saw recently with TrueCrypt).

I trust/distrust both about the same amount. But 1Password has more resources behind it so they are doing more to try and secure the data within the encrypted store.

Post reply on HN