Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

91–100 of 292 posts

Re: Notes on the Celebrity Data Theft

#91
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

I got screwed by a password manager that got deleted during upgrading a hard drive. Never again

1Password lets you store your (encrypted) password keychain on Dropbox to sync across devices.

You didn't get screwed by a password manager, you got screwed by a bad backup policy..

Sorry to be pedantic - and I feel your pain for losing your data - but there you go..

Re: Notes on the Celebrity Data Theft

#92
post #70
post #10

Earlier quoted context omitted.

1Password and last pass are pretty awesome. Some people don't want to use a 3rd party and for those, I suggest KeePass databases at the very least. I have all my two-factor reset keys in KeePassX at home and all normal passwords in last pass. I actually lost a two factor code for Linode when I lost my phone with the Google authenticator app on it and having those reset codes in KeePassX was a life saver.

I've seen this argument come up before and I don't understand it. Why do you trust KeePass more than 1Password? In both cases you are sharing the datafile however you'd like (Dropbox, thumbdrive, etc...). The primary difference is if you have access to the source code or not. If KeePass purposefully injected a vulnerability, it would just be that dev/project that would fail. If 1Password were to do the same, that com…

Well, Keepass is free as in beer too, so from a licensing perspective, that's a factor (mainly for adoption) though, 1Password is a totally affordable and solid investment for 99%+ of folks on this board).

Free allows much more organic adoption - I can recommend a friend to use KeePass without worrying a bit that he doesn't think 1Password is a good investment. I can mandate it for my team at work without having to get it expensed.

Re: Notes on the Celebrity Data Theft

#93
post #66

Earlier quoted context omitted.

While I think using password managers with random passwords is far better than sharing the same password between every account, I've never really gotten comfortable with storing passwords in a file on my computer. What I'd really like is a password manager hardware dongle of some kind, like the Bitcoin Trezor wallet.

It doesn't matter. If you have malware lurking in your computer it will just snarf your passwords from the wire and then you're owned all the same. If you use some sort of auth signing system, the request can just be intercepted and modified on the fly.[0] The Trezor is next to useless even for bitcoin for this very reason. Sure they can't steal your money directly, but just replacing the addresses you see and send t…

Doesn't the TREZOR show you the address you're sending from/to as well as the amounts? That would be pretty easy to double-check.

Re: Notes on the Celebrity Data Theft

#94

The thing that bugs me is that you could have good password practices. But if you're having a party, having a fun time (and lets face it, people are going to do shit...), and one of your friends is snapping photos of you, and they have bad password practices, then you are kind of screwed. People don't typically make friends on the basis of: do you have good password practices.

OTOH, if you're a celebrity at a party, and you "do shit" and someone takes a picture of it, the horse has pretty much already left the barn as to whether that picture is going to show up on reddit and it's just a question of when...

Re: Notes on the Celebrity Data Theft

#95
post #21

I use strong passwords generated by 1Password for everything.. except for iCloud. There I have an idiot password. Why? Because freaking iPhone asks for that when I want to download something from App Store. How do you guys handle that?

Don't use an "idiot" password, use a long password.. Good passwords aren't complex, they're LONG..

"this is a really dumb password" is probably actually a really good password. ;-)

And also, your "problem" is simply your decision to trade security for convenience.

You need to weigh the risks vs. reward and make the choice for yourself. If something goes wrong, at least you'll know why.

Re: Notes on the Celebrity Data Theft

#96
post #66

Earlier quoted context omitted.

It doesn't matter. If you have malware lurking in your computer it will just snarf your passwords from the wire and then you're owned all the same. If you use some sort of auth signing system, the request can just be intercepted and modified on the fly.[0] The Trezor is next to useless even for bitcoin for this very reason. Sure they can't steal your money directly, but just replacing the addresses you see and send t…

Doesn't the TREZOR show you the address you're sending from/to as well as the amounts? That would be pretty easy to double-check.

Double check it against what information source? The malicious software has altered the one shown on both devices. They will of course match, but not with the one you're actually meant to be paying to.[0][1]

[0]: http://www.reddit.com/r/Bitcoin/comments/23sjle/chrome_exten....

[1]: http://www.reddit.com/r/Bitcoin/comments/1vrium/a_google_chr...

Re: Notes on the Celebrity Data Theft

#98
post #52
post #2

I wrote this in the other thread on the leak before it died: > Even if the leaks result from one at a time social engineering, it still really calls into question the practical security of the cloud. I doubt it's much harder to steal, e.g. confidential business documents from executives' cloud accounts than it is to steal pictures from celebrities' cloud accounts. > If I were a big organization with confidential info…

> The policy at my previous employer (we handled a lot of extremely sensitive information), was pretty draconian: data never leaves a company desktop, laptop, or blackberry. Really? And how do these devices inter-communicate if data never leaves from anywhere to anywhere? Burying a laptop to the ground would make it safe enough to keep out the bad guys.

You can use citrix or terminal services so the sensitive data never leaves the servers.

Re: Notes on the Celebrity Data Theft

#99
post #79

Earlier quoted context omitted.

For passwords you're right, but at least it prevents theft of every password all at once. For Bitcoin hardware wallets like Trezor, IIRC they either do or will support BIP-70 "Payment Protocol" payment requests that are signed with an X.509 cert, allowing you to verify the request on the dongle's screen .

Nothing stops a threat from just lying and waiting for you to expose a large number of passwords. Having one stolen doesn't raise red flags in itself. I don't think signed addresses will be particularly effective. With the sort of key stores we have now, it seems pretty plausible that a bad actor to get a certificate that would pass on the Trezor device. It raises the barrier of entry a little though.

It should be just as effective as HTTPS is. Of course whether that's effective enough depends on who you ask. Yes, rogue/compromised CAs are occasionally a problem, but it generally works pretty well.
Post reply on HN