Earlier quoted context omitted.
I got screwed by a password manager that got deleted during upgrading a hard drive. Never again
1Password lets you store your (encrypted) password keychain on Dropbox to sync across devices. You didn't get screwed by a password manager, you got screwed by a bad backup policy.. Sorry to be pedantic - and I feel your pain for losing your data - but there you go..
Notes on the Celebrity Data Theft
101–110 of 292 posts
Re: Notes on the Celebrity Data Theft
#102While I am complete appalled by the data breach and hope that similar things never happens to anyone again I would like to propose a purely thought experiment: The hacker reported sold the nude photos of Jennifer lawrence for a mere sum of $130 using bitcoin. If we apply game theory here, these kind of data is very difficult to monetize. If you sell one copy of the data, it is then immediately distributed online for…
[deleted]
Re: Notes on the Celebrity Data Theft
#103Reddit should not be listed among the sites hosting the stolen images, as reddit does not support image uploads. Imgur is the primary site hosting the stolen images in that case.
Are we still unable to move past this pedantic hosting-vs-linking nitpicking? It's like you willfully ignore how content discovery works on the Internet.
Imgur revealed earlier this year that they have similar image detection built into their back end. Despite the ease with which they could use this to automatically sweep 99.9% of the Jennifer Lawrence photos off of their site the instant they're uploaded and shadowban the uploaders, and despite the fact that every one of their 12+ employees knew about this leak the instant it happened and also knew that their own site would probably be one of the two most actively used to spread the images around the world, half of the Jennifer Lawrence albums I checked there still have all images intact. One album has over 30,000 views and has existed for two days. Why haven't they activated their similar image detection algorithm in this case? At best, this is neglect bordering on malice.
The damage Imgur does by actually hosting these stolen images and dragging their feet for as long as possible when responding to DMCA takedown requests has nothing whatsoever to do with a text-only discussion thread on reddit. The author should correct this accusation and lay the blame where it belongs.
Re: Notes on the Celebrity Data Theft
#104Why is nobody talking about password reset questions?
I hate those so much. They lock me out of my accounts more often than they help. I always enter bogus answers because I think I'll never need to use the feature, then I run into a situation like: "Resetting your password via email? Ok, you also have to answer these security questions that you entered 'akjhdhksdfsdf' into when you made your account!" or "You've logged in from a new computer! Please try to remember wha…
Re: Notes on the Celebrity Data Theft
#105The thing that bugs me is that you could have good password practices. But if you're having a party, having a fun time (and lets face it, people are going to do shit...), and one of your friends is snapping photos of you, and they have bad password practices, then you are kind of screwed. People don't typically make friends on the basis of: do you have good password practices.
Yup. And that very reason is why many people don't have social networking accounts. You can control what you share, but you can't control what your friends share.
Re: Notes on the Celebrity Data Theft
#106> Password reset is answering the date of birth and security question challenges (often easy to break using publicly available data – birthdays and favorite sports teams, etc. are often not secrets) I really dislike this trend of "personal questions" to reset your password. The first car I owned or where I'd like to retire is easily obtained information. When are websites going to stop doing this? I answer these ques…
What about just using a basic cipher for your questions? It is what I do. So if the question is "What was your first car?" Answer could be: Ford Instead it is Enqc or droF or Gpse
Re: Notes on the Celebrity Data Theft
#107While I am complete appalled by the data breach and hope that similar things never happens to anyone again I would like to propose a purely thought experiment: The hacker reported sold the nude photos of Jennifer lawrence for a mere sum of $130 using bitcoin. If we apply game theory here, these kind of data is very difficult to monetize. If you sell one copy of the data, it is then immediately distributed online for…
Re: Notes on the Celebrity Data Theft
#108Earlier quoted context omitted.
Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.
While I think using password managers with random passwords is far better than sharing the same password between every account, I've never really gotten comfortable with storing passwords in a file on my computer. What I'd really like is a password manager hardware dongle of some kind, like the Bitcoin Trezor wallet.
It'll basically push specialized requirements to the hardware dongle (ie deciding whether it's enough to confirm user registration/authorization with the touch of a buttom, or whether it needs to be with a 4 digit pin, or even with biometrics like voice or fingerprint or iris scan). The test device in the following presentation video only uses a button press to confirm user intent, but it could have arbitrary requirements, making the protocol usable for both trivial website logins to online banking to eventually perhaps even a replacement for defense department CACs.
Here's a good fairly in-depth video presentation of what the FIDO Alliance is working on (there are functional test devices, and a functional test branch of Chrome that works with them):
Re: Notes on the Celebrity Data Theft
#109The thing that bugs me is that you could have good password practices. But if you're having a party, having a fun time (and lets face it, people are going to do shit...), and one of your friends is snapping photos of you, and they have bad password practices, then you are kind of screwed. People don't typically make friends on the basis of: do you have good password practices.
I once resisted signing up to Viber because it required that I upload my entire address book. However, I found out how many of my friends are already on Viber, which means the likelihood that Viber didn't already have someone's contact information was very low. It also meant Viber already had all of my contact information.
Another scenario is Facebook's tagging. Even if I don't confirm all (or any) of my friends' tags on my face, the fact that they manually tagged the face as mine likely counts a lot for FB, so that battle is already lost.
Re: Notes on the Celebrity Data Theft
#110Read the comments to this blog post. The misogynistic mouth breathers are out in full force as usual.