Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

171–180 of 292 posts

Re: Notes on the Celebrity Data Theft

#171
post #60
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

Or a text file or spreadsheet containing passwords, in a TrueCrypt container (I still trust it).

Don't you run the risk of getting the text file or spreadsheet cached to the temp directory?

Re: Notes on the Celebrity Data Theft

#172
post #120

Earlier quoted context omitted.

Both groups certainly exist, but one is larger than the other by a few orders of magnitude.

(disclaimer: not meaning to start any kind of flame-war) To be honest, the one I perceive (as a straight, white, middle-class, educated male) larger is the misandristic one. As a person who strives to be good and helpful to every human being equally, regardless of race, gender, orientation or whatever, I get everyday on the Internet and I get flooded by articles and comments saying that everything I do or think is mi…

>In my opinion, the reason this leak contains only women celebrities has nothing to do with misogyny...

I'd say the main reason the leaks are all women is that hackers are predominately heterosexual men.

Re: Notes on the Celebrity Data Theft

#173
post #136

Earlier quoted context omitted.

That's not how 1Password works. All passwords for 1Password are stored locally in an AES encrypted file. They never see, touch, or have any control over your passwords on their end. Even if they suddenly shut down tomorrow, all your passwords would still be accessible unless you chose to delete the application and have zero backups to restore from. They even have an export function to dump the passwords (unencrypted)…

You are 100% correct. To add to this all syncing on 1Password is done using 3rd party vendors. You can use dropbox, iCloud, Google Drive, etc to do the actual syncing of the encrypted files.

I use Dropbox, but my password for Dropbox itself is stored inside 1Password. The escape hatch is that the 1Password sync folder is shared publicly, and the URL is copied to a slip of paper in my wallet.

Re: Notes on the Celebrity Data Theft

#175
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

My problem is that 1Password et al are curing symptoms, not solving causes. Personal infosec hasn't evolved quick enough to match the technology it depends on. Sure we're comfortable with 12 character, 3 month rotation passwords, but the average 'civilian'? Probably doesn't even have a passcode on their phone despite the massive personal security risk they're carrying around with them. We need to educate and/or provi…

12 character? Please! ;-)

(Most of mine are markedly longer.)

Though I'll admit to being a tad less aggressive on the rotation than I ought to be.

Re: Notes on the Celebrity Data Theft

#176
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

I got screwed by a password manager that got deleted during upgrading a hard drive. Never again

You really want to ensure that you've got backups / copies of your password safe.

It also _probably_ means having these online somewhere. You're relying on strong crypto (and a really good base password) to protect you here.

Re: Notes on the Celebrity Data Theft

#177
post #95

Earlier quoted context omitted.

Don't use an "idiot" password, use a long password.. Good passwords aren't complex, they're LONG.. "this is a really dumb password" is probably actually a really good password. ;-) And also, your "problem" is simply your decision to trade security for convenience. You need to weigh the risks vs. reward and make the choice for yourself. If something goes wrong, at least you'll know why.

Long passwords (aka the xkcd scheme) aren't secure anymore - https://www.schneier.com/blog/archives/2014/03/choosing_secu... The only good passwords are ones that stay well away from dictionary words..

A good password is one that's not known or readily knowable.

There are archives of know passwords -- millions of them. These should be rejected on any online service.

There are tools for guessing passwords. Any password which falls into any of he likely-to-be-guessed divisions should _also_ be rejected.

Dictionary words _could_ work in a sufficiently large namespace. But that's pretty iffy.

Re: Notes on the Celebrity Data Theft

#178
post #21

I use strong passwords generated by 1Password for everything.. except for iCloud. There I have an idiot password. Why? Because freaking iPhone asks for that when I want to download something from App Store. How do you guys handle that?

I have 1Password for iPhone and copy the generated password from there every time I need it. Certainly a pain but worth it. In the end, it doesn't take that long: 1Password is on my home screen, the Apple login is favorited and I can type my master password fairly fast. The most annoying part really is switching between apps.

I also have my phone set up for iOS not to ask for the password for 5 or 15 minutes (can't remember the exact option) after I entered it.

Re: Notes on the Celebrity Data Theft

#179
post #120

Earlier quoted context omitted.

Both groups certainly exist, but one is larger than the other by a few orders of magnitude.

(disclaimer: not meaning to start any kind of flame-war) To be honest, the one I perceive (as a straight, white, middle-class, educated male) larger is the misandristic one. As a person who strives to be good and helpful to every human being equally, regardless of race, gender, orientation or whatever, I get everyday on the Internet and I get flooded by articles and comments saying that everything I do or think is mi…

Regardless of the truth or falsehood of what you're saying, no good (for you or anyone else) will come of making this one of your personal crusades, which it sounds like it is. There are far nobler causes than standing up to SJWs you feel have crossed some line of hypocrisy, and you are much more likely to be a force for harm than good in the world as a result.

Re: Notes on the Celebrity Data Theft

#180
post #70

Earlier quoted context omitted.

I've seen this argument come up before and I don't understand it. Why do you trust KeePass more than 1Password? In both cases you are sharing the datafile however you'd like (Dropbox, thumbdrive, etc...). The primary difference is if you have access to the source code or not. If KeePass purposefully injected a vulnerability, it would just be that dev/project that would fail. If 1Password were to do the same, that com…

Why do you assume every KeePass user is storing their passwords on a server somewhere? I would never send my password file over a network, and I don't consider USB storage "sharing."

The password file itself is an encrypted DB. Unless you choose a weak password for that, it's pretty secure.
Post reply on HN