Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

111–120 of 292 posts

Re: Notes on the Celebrity Data Theft

#111
post #21

I use strong passwords generated by 1Password for everything.. except for iCloud. There I have an idiot password. Why? Because freaking iPhone asks for that when I want to download something from App Store. How do you guys handle that?

You can use a different password for purchasing apps, and a different password (Apple ID) for your iCloud data.

This goes for Game Center as well. You can use a different one for your mean, nasty, trash talking Gamer persona.

Apple doesn't always make this clear, and I see a lot of people confused about this, but this is an option.

Another login that can use a different Apple ID is Find My iDevice.

Re: Notes on the Celebrity Data Theft

#112

So if I'm understanding this from a technical perspective, the real story is that this is/has been going on for quite some time, and there's an entire ecosystem devoted to it. The general public rarely ever sees behind the curtain, but somebody got greedy in this case and we ended up in a race to the bottom. If true, interesting that such a layered economic structure can exist without much press or public comment --…

Well the fact that JenLaw's photos went for the extremely huge amount of $130 suggests that either there's a lot more of it out there, or that the guy who stole them couldn't fence them (per [0] thread).

Anyway, you summed up the take-away from the article perfectly. Since this seems to be going on for some time, I wonder how the whole ecosystem kept coordinating this well so far, that it's the first time we hear about such big (but still lousy one) defection.

[0] - https://news.ycombinator.com/item?id=8260233

Re: Notes on the Celebrity Data Theft

#113
post #21

I use strong passwords generated by 1Password for everything.. except for iCloud. There I have an idiot password. Why? Because freaking iPhone asks for that when I want to download something from App Store. How do you guys handle that?

I don't get Apple's password based security at all. The stupid question/answer thing they forced everyone to do was just crazy.

You have a physical device in your possession. Apple don't seem to have heard about two factor auth. If the only company on the planet that obsessively ties consumer hardware and software into a single cohesive product can't get their shit together the future worries me.

It should be the default (with an opt out for access from non-apple devices) for every Apple service to authenticate with the device as well as the password. Anyone who steals your Apple login but not your phone should have zero chance of accessing your data.

Re: Notes on the Celebrity Data Theft

#114
If one use Personal Cloud services like owncloud and Tonido the probability of social engineering hack goes down further. First of all the data is stored in your device and one needs to guess both the username and password.

Still one need to be careful what username and password to choose and how to safeguard them.

Re: Notes on the Celebrity Data Theft

#115
post #70
post #10

Earlier quoted context omitted.

1Password and last pass are pretty awesome. Some people don't want to use a 3rd party and for those, I suggest KeePass databases at the very least. I have all my two-factor reset keys in KeePassX at home and all normal passwords in last pass. I actually lost a two factor code for Linode when I lost my phone with the Google authenticator app on it and having those reset codes in KeePassX was a life saver.

I've seen this argument come up before and I don't understand it. Why do you trust KeePass more than 1Password? In both cases you are sharing the datafile however you'd like (Dropbox, thumbdrive, etc...). The primary difference is if you have access to the source code or not. If KeePass purposefully injected a vulnerability, it would just be that dev/project that would fail. If 1Password were to do the same, that com…

I was just offering it as a suggestion. Some people like to keep things on their own computers (or servers) and keepass offers that. I use Lastpass, which is hosted and I trust them with my passwords. I simply use keepassx to store two factor reset codes. I do this because if I store my reset codes in the same system as my passwords, then it's not very two-factor anymore, is it?

Re: Notes on the Celebrity Data Theft

#116
post #7

Why is nobody talking about password reset questions?

Yes Hopefully the idiots who call themselves security experts will stop making me answer "what's my mother's maiden name". If they really want to make it safe, one easy option would be to make the question arbitrary. Of course then average people will have no idea what to put it there. Of course, don't put "What is Love?" with the trivial answer...

> Hopefully the idiots who call themselves security experts will stop making me answer "what's my mother's maiden name".

This is done by developers, not security experts. If security experts had their way, it would be equally bad but for the right reasons, ie client-side certificates or smart cards.

Calling them idiots is also wrong. Its a bad solution to a hard problem, but it works and scales and users have been trained to expect it.

Re: Notes on the Celebrity Data Theft

#117

Earlier quoted context omitted.

I hate those so much. They lock me out of my accounts more often than they help. I always enter bogus answers because I think I'll never need to use the feature, then I run into a situation like: "Resetting your password via email? Ok, you also have to answer these security questions that you entered 'akjhdhksdfsdf' into when you made your account!" or "You've logged in from a new computer! Please try to remember wha…

1Password can store those for you as well.

As can KeePass.

Re: Notes on the Celebrity Data Theft

#118
post #70
post #10

Earlier quoted context omitted.

1Password and last pass are pretty awesome. Some people don't want to use a 3rd party and for those, I suggest KeePass databases at the very least. I have all my two-factor reset keys in KeePassX at home and all normal passwords in last pass. I actually lost a two factor code for Linode when I lost my phone with the Google authenticator app on it and having those reset codes in KeePassX was a life saver.

I've seen this argument come up before and I don't understand it. Why do you trust KeePass more than 1Password? In both cases you are sharing the datafile however you'd like (Dropbox, thumbdrive, etc...). The primary difference is if you have access to the source code or not. If KeePass purposefully injected a vulnerability, it would just be that dev/project that would fail. If 1Password were to do the same, that com…

My concern is that 1Password could shut down at any time and stop being supported, and I may lose access to all my passwords. KeePass is open source, so even if the current maintainer quits, it's likely that others in the community will step up to continue maintaining it. If absolutely necessary, I can edit the source code myself.

Re: Notes on the Celebrity Data Theft

#119

While I am complete appalled by the data breach and hope that similar things never happens to anyone again I would like to propose a purely thought experiment: The hacker reported sold the nude photos of Jennifer lawrence for a mere sum of $130 using bitcoin. If we apply game theory here, these kind of data is very difficult to monetize. If you sell one copy of the data, it is then immediately distributed online for…

While I don't actually have any solid grasp of the code that would be required, I imagine it would be possible to release 1 image to show that one does indeed have a collection of "valuable" photos. Once trust has been established that the person probably does indeed have additional photos, people will be more willing to submit bitcoin.

You overwrite each pixel of each photo with black. You assign every photo a bitcoin address and perhaps give a name describing its content (something kinky, obviously). Each photo has a set amount the person is asking for its release. As bitcoin is sent to each photo's address, more and more pixels are revealed, as a percentage of the remaining bitcoin price.

You can go further by making the first few photos far cheaper the next (potentially more sultry) photos, creating an exponential pricing system that will likely benefit the hacker. Trust is increased as a low cost photos are revealed, demand for more revealing photos increases as trust increases.

Thoughts?

Re: Notes on the Celebrity Data Theft

#120
post #100

Read the comments to this blog post. The misogynistic mouth breathers are out in full force as usual.

Just wait for the misandristic crowd to show up, as they always do. I'm just starting to see first articles in my Facebook feed trying to spin this celebrity leak into women oppression problem.

Both groups certainly exist, but one is larger than the other by a few orders of magnitude.
Post reply on HN