Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

131–140 of 292 posts

Re: Notes on the Celebrity Data Theft

#131

Earlier quoted context omitted.

Well the fact that JenLaw's photos went for the extremely huge amount of $130 suggests that either there's a lot more of it out there, or that the guy who stole them couldn't fence them (per [0] thread). Anyway, you summed up the take-away from the article perfectly. Since this seems to be going on for some time, I wonder how the whole ecosystem kept coordinating this well so far, that it's the first time we hear abo…

Yeah, there's some hard-to-accept math in that story. If JenLaw's photos were worth $130 or so, that means that any photos that any of us have are associated with a market value. And it ain't that much.

Well, that our photos have a price tag is kind of obvious. Everything has one. But I'm very surprised by the amounts we're talking about. I'd expect JenLaw to be extorted for hundreds of thousands of dollars, or at least those photos going for many $k (and THB, some other celebs have much worse photos/videos in this leak). So them going for $130 implies that either celeb sex tapes are really common/cheap in the darknet, or we have no frikkin' clue what's going on out there.

Re: Notes on the Celebrity Data Theft

#132
post #95
post #21

I use strong passwords generated by 1Password for everything.. except for iCloud. There I have an idiot password. Why? Because freaking iPhone asks for that when I want to download something from App Store. How do you guys handle that?

Don't use an "idiot" password, use a long password.. Good passwords aren't complex, they're LONG.. "this is a really dumb password" is probably actually a really good password. ;-) And also, your "problem" is simply your decision to trade security for convenience. You need to weigh the risks vs. reward and make the choice for yourself. If something goes wrong, at least you'll know why.

The problem is to tap all of that into your phone, every time iOS decides it desperately needs it again, with just stars instead of letters. That's annoying.

Re: Notes on the Celebrity Data Theft

#133

Earlier quoted context omitted.

You can use a different password for purchasing apps, and a different password (Apple ID) for your iCloud data. This goes for Game Center as well. You can use a different one for your mean, nasty, trash talking Gamer persona. Apple doesn't always make this clear, and I see a lot of people confused about this, but this is an option. Another login that can use a different Apple ID is Find My iDevice.

OK I must be dumb today, but I can't figure out how to do this and Google isn't helping me either - can you describe, or point me to a link, on how to set this up? Thanks!

I think it's that you can use different Apple IDs for each of these things.

Re: Notes on the Celebrity Data Theft

#135
post #8
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

Installed! I guess I knew I should use a password manager, but the analysis paralysis of figuring out which one to use is crippling. I just want someone to tell me what to do!

Another happy 1Password user here. I've been using it for probably about 18 months now and I can never go back to manual account management. It took a bit of upfront time investment to migrate all my existing accounts into the tool but once that was done, it's been a pretty seamless experience overall.

There's browser add-ons you can use to auto-populate your login details that work well for most login forms with mostly no or minimal configuration required. It can get a little annoying when the login form has a CAPTCHA or some other non-standard requirement, but generally all that means is a few extra clicks. When creating new account details, configurable (e.g. length, allowed characters, etc.) password generation is built in.

You can keep your encrypted data store file on a cloud service for syncing between devices, should you wish. Which brings me to the 1Password mobile apps, which allow you to take your details mobile.

Probably the greatest friction point I've encountered has been when I'm on a foreign computer that doesn't have any of my 1Password support tools installed on it. In this case I usually just pull out my phone, navigate to the login details I need and enter them manually. But I take this as a small price to pay for markedly greater peace of mind.

I really can't recommend using a password manager enough. If 1Password is not it for you, then use some other password manager. But just use one.

Re: Notes on the Celebrity Data Theft

#136

Earlier quoted context omitted.

My concern is that 1Password could shut down at any time and stop being supported, and I may lose access to all my passwords. KeePass is open source, so even if the current maintainer quits, it's likely that others in the community will step up to continue maintaining it. If absolutely necessary, I can edit the source code myself.

That's not how 1Password works. All passwords for 1Password are stored locally in an AES encrypted file. They never see, touch, or have any control over your passwords on their end. Even if they suddenly shut down tomorrow, all your passwords would still be accessible unless you chose to delete the application and have zero backups to restore from. They even have an export function to dump the passwords (unencrypted)…

You are 100% correct.

To add to this all syncing on 1Password is done using 3rd party vendors.

You can use dropbox, iCloud, Google Drive, etc to do the actual syncing of the encrypted files.

Re: Notes on the Celebrity Data Theft

#137
post #113
post #21

I use strong passwords generated by 1Password for everything.. except for iCloud. There I have an idiot password. Why? Because freaking iPhone asks for that when I want to download something from App Store. How do you guys handle that?

I don't get Apple's password based security at all. The stupid question/answer thing they forced everyone to do was just crazy. You have a physical device in your possession. Apple don't seem to have heard about two factor auth. If the only company on the planet that obsessively ties consumer hardware and software into a single cohesive product can't get their shit together the future worries me. It should be the def…

They've had two-step authentication since March of 2013: http://support.apple.com/kb/ht5570

Re: Notes on the Celebrity Data Theft

#138
post #70
post #10

Earlier quoted context omitted.

1Password and last pass are pretty awesome. Some people don't want to use a 3rd party and for those, I suggest KeePass databases at the very least. I have all my two-factor reset keys in KeePassX at home and all normal passwords in last pass. I actually lost a two factor code for Linode when I lost my phone with the Google authenticator app on it and having those reset codes in KeePassX was a life saver.

I've seen this argument come up before and I don't understand it. Why do you trust KeePass more than 1Password? In both cases you are sharing the datafile however you'd like (Dropbox, thumbdrive, etc...). The primary difference is if you have access to the source code or not. If KeePass purposefully injected a vulnerability, it would just be that dev/project that would fail. If 1Password were to do the same, that com…

Why do you assume every KeePass user is storing their passwords on a server somewhere? I would never send my password file over a network, and I don't consider USB storage "sharing."

Re: Notes on the Celebrity Data Theft

#139

Earlier quoted context omitted.

Yup. And that very reason is why many people don't have social networking accounts. You can control what you share, but you can't control what your friends share.

How not having a social networking account helps with that? Not only you still can't control what your friends (that is, the real-life ones) share, now you're the last to know if they share something about you.

Perfect example is Facebook. You don't have to be on it for them to know your phone number. If 2 of your friends have the "Share your Contacts with Facebook" option turned on, chances are Facebook has your phone number/whatever else your friends store on their friend about you.

Re: Notes on the Celebrity Data Theft

#140
post #10
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

1Password and last pass are pretty awesome. Some people don't want to use a 3rd party and for those, I suggest KeePass databases at the very least. I have all my two-factor reset keys in KeePassX at home and all normal passwords in last pass. I actually lost a two factor code for Linode when I lost my phone with the Google authenticator app on it and having those reset codes in KeePassX was a life saver.

are there any known vulnerabilities for 1Password?
Post reply on HN