Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

141–150 of 292 posts

Re: Notes on the Celebrity Data Theft

#141
post #10
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

1Password and last pass are pretty awesome. Some people don't want to use a 3rd party and for those, I suggest KeePass databases at the very least. I have all my two-factor reset keys in KeePassX at home and all normal passwords in last pass. I actually lost a two factor code for Linode when I lost my phone with the Google authenticator app on it and having those reset codes in KeePassX was a life saver.

are there any known vulnerabilities for 1Password?

Re: Notes on the Celebrity Data Theft

#142

  > 6. iCloud is the most popular target because Picture Roll backups are enabled
  > by default and iPhone is a popular platform. Windows Phone backups are
  > available on all devices but are disabled by default (it is frequently enabled,
  > although I couldn’t find a statistic) while Android backup is provided by
  > third party applications (some of which are targets).
Fragmentation, for the (security) win!

Not really, of course. The big win (shared by Windows Phone) is simply not turning on the security-sensitive cloud service by default. That being said, it is worth noting that enabling/encouraging third-party service competition can create an extra hurdle by discouraging cloud-service monocultures.

Re: Notes on the Celebrity Data Theft

#143

Earlier quoted context omitted.

Yeah, there's some hard-to-accept math in that story. If JenLaw's photos were worth $130 or so, that means that any photos that any of us have are associated with a market value. And it ain't that much.

Well, that our photos have a price tag is kind of obvious. Everything has one. But I'm very surprised by the amounts we're talking about. I'd expect JenLaw to be extorted for hundreds of thousands of dollars, or at least those photos going for many $k (and THB, some other celebs have much worse photos/videos in this leak). So them going for $130 implies that either celeb sex tapes are really common/cheap in the darkn…

Well.. this is a black market with no ability to self-regulate. So, the prices are going to be incredibly low compared to their everyday value; to be a bit crude, these are crackhead prices.

Re: Notes on the Celebrity Data Theft

#144
post #95

Earlier quoted context omitted.

Don't use an "idiot" password, use a long password.. Good passwords aren't complex, they're LONG.. "this is a really dumb password" is probably actually a really good password. ;-) And also, your "problem" is simply your decision to trade security for convenience. You need to weigh the risks vs. reward and make the choice for yourself. If something goes wrong, at least you'll know why.

The problem is to tap all of that into your phone, every time iOS decides it desperately needs it again, with just stars instead of letters. That's annoying.

It's a pain, but really not that bad. You tweet from your phone (or use email/SMS/whatever else). 20 characters is manageable and secure, as long as it's randomly generated.

Re: Notes on the Celebrity Data Theft

#145
post #28

Earlier quoted context omitted.

Are we still unable to move past this pedantic hosting-vs-linking nitpicking? It's like you willfully ignore how content discovery works on the Internet.

Just to be pedantic: By the same logic, Google is also grossly hosting tonnes of illegal material.

Google doesn't have moderators posting messages like "uh-oh your illegal content is being taken down. Here's a list of other places to post it." Meanwhile, Reddit has precisely that. Warning: link to NSFW board, though this post isn't itself NSFW.

http://www.reddit.com/r/TheFappening/comments/2fa2a1/meta_ef...

In which the mods write: "On another note: please use other hosting sites besides imgur.com. We have a large list of whitelisted domains listed here that you should be uploading to besides imgur. Do not put all of your eggs in one basket."

Re: Notes on the Celebrity Data Theft

#146

Earlier quoted context omitted.

You can use a different password for purchasing apps, and a different password (Apple ID) for your iCloud data. This goes for Game Center as well. You can use a different one for your mean, nasty, trash talking Gamer persona. Apple doesn't always make this clear, and I see a lot of people confused about this, but this is an option. Another login that can use a different Apple ID is Find My iDevice.

OK I must be dumb today, but I can't figure out how to do this and Google isn't helping me either - can you describe, or point me to a link, on how to set this up? Thanks!

First, create a new Apple ID.

If you want to use this for your App Store account, go into Settings then "iTunes & App Store", and sign out of the previous account. Log in using then different (new) Apple ID.

If you want to use this for your iCloud account, go into your iDevice's Settings, then iCloud, then "Delete Account". It will delete the iCloud data on your phone, but it should still be available on iCloud servers, and any other device hooked up to that account. I haven't looked into how to transfer data from one iCloud into another.

Re: Notes on the Celebrity Data Theft

#147
post #24

Reddit should not be listed among the sites hosting the stolen images, as reddit does not support image uploads. Imgur is the primary site hosting the stolen images in that case.

Reddit's the same site with the dedicated subreddit called "/r/thefappening", right? That Reddit? I'm not seeing how they get a completely free pass here, it's like saying UNIX doesn't store file data under file names, but under inodes. Perhaps pedantically correct, but completely missing the point.

Re: Notes on the Celebrity Data Theft

#148
post #58

While I am complete appalled by the data breach and hope that similar things never happens to anyone again I would like to propose a purely thought experiment: The hacker reported sold the nude photos of Jennifer lawrence for a mere sum of $130 using bitcoin. If we apply game theory here, these kind of data is very difficult to monetize. If you sell one copy of the data, it is then immediately distributed online for…

Only someone who knows the market can maximize the profit . These pictures would make a lot of money at the hand of specific low/high (depend on the view) magazines, on someone would wanna destroy JLaw's reputation or as ransom... How much money would JLaw pay for the original files? However, how many people do you think can answer the above questions?? It's like when someone steals a huge pile of jewelery. He steals…

A bit of a tangent, but it's worth noting that the amount JLaw should rationally be prepared to pay for the original files is zero. If you pay a ransom in a situation like that, all that will happen is a) the guy will take the money and then sell the pictures anyway, and b) you set a precedent that you can be blackmailed, which means the next blackmailer might come up with something worse than some rectangles of RGB pixels.

Re: Notes on the Celebrity Data Theft

#149
post #52

Earlier quoted context omitted.

> The policy at my previous employer (we handled a lot of extremely sensitive information), was pretty draconian: data never leaves a company desktop, laptop, or blackberry. Really? And how do these devices inter-communicate if data never leaves from anywhere to anywhere? Burying a laptop to the ground would make it safe enough to keep out the bad guys.

You can use citrix or terminal services so the sensitive data never leaves the servers.

Couldn't someone just screenshot the citrix or terminal services session while the user is using it?

Re: Notes on the Celebrity Data Theft

#150
post #3
post #2

I wrote this in the other thread on the leak before it died: > Even if the leaks result from one at a time social engineering, it still really calls into question the practical security of the cloud. I doubt it's much harder to steal, e.g. confidential business documents from executives' cloud accounts than it is to steal pictures from celebrities' cloud accounts. > If I were a big organization with confidential info…

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

My problem is that 1Password et al are curing symptoms, not solving causes.

Personal infosec hasn't evolved quick enough to match the technology it depends on. Sure we're comfortable with 12 character, 3 month rotation passwords, but the average 'civilian'? Probably doesn't even have a passcode on their phone despite the massive personal security risk they're carrying around with them.

We need to educate and/or provide easier authentication.

Post reply on HN