Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

151–160 of 292 posts

Re: Notes on the Celebrity Data Theft

#152
post #95
post #21

I use strong passwords generated by 1Password for everything.. except for iCloud. There I have an idiot password. Why? Because freaking iPhone asks for that when I want to download something from App Store. How do you guys handle that?

Don't use an "idiot" password, use a long password.. Good passwords aren't complex, they're LONG.. "this is a really dumb password" is probably actually a really good password. ;-) And also, your "problem" is simply your decision to trade security for convenience. You need to weigh the risks vs. reward and make the choice for yourself. If something goes wrong, at least you'll know why.

Long passwords (aka the xkcd scheme) aren't secure anymore - https://www.schneier.com/blog/archives/2014/03/choosing_secu...

The only good passwords are ones that stay well away from dictionary words..

Re: Notes on the Celebrity Data Theft

#153

Earlier quoted context omitted.

Yeah, there's some hard-to-accept math in that story. If JenLaw's photos were worth $130 or so, that means that any photos that any of us have are associated with a market value. And it ain't that much.

Well, that our photos have a price tag is kind of obvious. Everything has one. But I'm very surprised by the amounts we're talking about. I'd expect JenLaw to be extorted for hundreds of thousands of dollars, or at least those photos going for many $k (and THB, some other celebs have much worse photos/videos in this leak). So them going for $130 implies that either celeb sex tapes are really common/cheap in the darkn…

Anonymous extortion threatening to release something that is trivial to copy is not going to work, because there is nothing to guarantee more money will be requested next week, or that the material will not be released later.

As far as selling it, the price cannot be very high, because nobody has that much to gain from being the first with the pictures. It's illegal material after all, so magazines can get in trouble for buying it. Put it in a shady, for-pay site, and with it being illegal material and all, it'd be in a torrent in minutes, so how many times will you really sell it?

If it was, say, a presidential candidate doing hard drugs and cheating on his wife with a man, then maybe you could say that the opposition would be willing to pay for the pictures to be released, regardless of how they were obtained: There'd be millions at stake. A naked actress? not so much.

Re: Notes on the Celebrity Data Theft

#154

Earlier quoted context omitted.

I hate those so much. They lock me out of my accounts more often than they help. I always enter bogus answers because I think I'll never need to use the feature, then I run into a situation like: "Resetting your password via email? Ok, you also have to answer these security questions that you entered 'akjhdhksdfsdf' into when you made your account!" or "You've logged in from a new computer! Please try to remember wha…

1Password can store those for you as well.

As can an encrypted text file or a post-it note under your desk. It's still a stupid security anti-pattern.

Re: Notes on the Celebrity Data Theft

#155
post #3
post #2

I wrote this in the other thread on the leak before it died: > Even if the leaks result from one at a time social engineering, it still really calls into question the practical security of the cloud. I doubt it's much harder to steal, e.g. confidential business documents from executives' cloud accounts than it is to steal pictures from celebrities' cloud accounts. > If I were a big organization with confidential info…

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

I currently use PasswordSafe which is clunky as hell but generally works OK.

I checked the 1Password site and it seems like a bit of a bait and switch. Download links without any mention of a price or trial anywhere on the product pages until you create a vault and see a License link in the menus. Then $50+ and another $10 for the mobile app.

I'm sure it's worth it, but I'd much rather they spell out their pricing up front.

Re: Notes on the Celebrity Data Theft

#156
post #155
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

I currently use PasswordSafe which is clunky as hell but generally works OK. I checked the 1Password site and it seems like a bit of a bait and switch. Download links without any mention of a price or trial anywhere on the product pages until you create a vault and see a License link in the menus. Then $50+ and another $10 for the mobile app. I'm sure it's worth it, but I'd much rather they spell out their pricing up…

They have a 'store' link [1] right in their header with all the pricing. They could maybe be a little more upfront about it, but it's not really a bait and switch. Also, the prices do seem fairly reasonable for what it does.

The only thing holding me back has been not having great mobile access (as far as I can tell) on Safari on iOS. Looks like iOS 8 will change that.

[1] https://agilebits.com/store

Re: Notes on the Celebrity Data Theft

#157

Earlier quoted context omitted.

You can use citrix or terminal services so the sensitive data never leaves the servers.

Couldn't someone just screenshot the citrix or terminal services session while the user is using it?

Sure, but that only gets you one screen of a sensitive document, and is a lot harder to do inconspicuously than to surreptitiously look at a file that a user saved to his personal laptop's desktop with the filename "Details of Unannounced IPO.doc."

Re: Notes on the Celebrity Data Theft

#158
post #97

Just to give OP a heads up: the article's font is rendering terribly in Windows Chrome.

I've noticed this with my own websites. Fonts consistently look great in FF and IE but terrible in Chrome. What can be done to fix this?

Use Firefox? Chrome has bad font rendering consistently, it's nothing you've done.

Re: Notes on the Celebrity Data Theft

#159
post #95

Earlier quoted context omitted.

Don't use an "idiot" password, use a long password.. Good passwords aren't complex, they're LONG.. "this is a really dumb password" is probably actually a really good password. ;-) And also, your "problem" is simply your decision to trade security for convenience. You need to weigh the risks vs. reward and make the choice for yourself. If something goes wrong, at least you'll know why.

Long passwords (aka the xkcd scheme) aren't secure anymore - https://www.schneier.com/blog/archives/2014/03/choosing_secu... The only good passwords are ones that stay well away from dictionary words..

Six really random words -- not a sentence -- gives you pretty good security.

Six words chosen from this list http://world.std.com/~reinhold/diceware.wordlist.asc truly at random gives you almost 80 bits of entropy. And six random words are easier to remember than 16 totally random letters.

EDIT seriously, 221073919720733357899776 is a really big search space. If you have a computer that can search a billion per second, it's going to take 1000 computers 1000 years to catalog just 14% of the search space.

Re: Notes on the Celebrity Data Theft

#160
post #95

Earlier quoted context omitted.

Don't use an "idiot" password, use a long password.. Good passwords aren't complex, they're LONG.. "this is a really dumb password" is probably actually a really good password. ;-) And also, your "problem" is simply your decision to trade security for convenience. You need to weigh the risks vs. reward and make the choice for yourself. If something goes wrong, at least you'll know why.

Long passwords (aka the xkcd scheme) aren't secure anymore - https://www.schneier.com/blog/archives/2014/03/choosing_secu... The only good passwords are ones that stay well away from dictionary words..

The Schneier article is puzzling; the security of the diceware/XKCD scheme doesn't rely on the word list being secret, just on the words from the list being chosen randomly. 4 words randomly chosen from a list of 5000 provide about 49 bits of entropy when the list of words is fully known.

Against an attacker who knows exactly how you chose your password, it's (roughly) the same level of security as a 14-digit numeric code, or an 8 letter case-sensitive alphanumeric code. It's just supposed to be easier to remember.

Post reply on HN