Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

221–230 of 292 posts

Re: Notes on the Celebrity Data Theft

#221
post #192
post #142

> 6. iCloud is the most popular target because Picture Roll backups are enabled > by default and iPhone is a popular platform. Windows Phone backups are > available on all devices but are disabled by default (it is frequently enabled, > although I couldn’t find a statistic) while Android backup is provided by > third party applications (some of which are targets). Fragmentation, for the (security) win! Not really, of…

Does Android really not provide an auto upload of snapped pictures to the cloud? I was under the impression that they did this way before iCloud even came up. First it was to Picasa or some place, then to the google+ place somewhere. Either way, I don't even remember if the iCloud upload was default or not. When it was introduced I took an interest to find out how to deactivate that in case it was enabled by default.…

[deleted]

Re: Notes on the Celebrity Data Theft

#222
post #21

I use strong passwords generated by 1Password for everything.. except for iCloud. There I have an idiot password. Why? Because freaking iPhone asks for that when I want to download something from App Store. How do you guys handle that?

lastpass on android has the ability to insert your passwords into app login forms (via a custom keyboard / accessibility API, I think). I don't know if the same is true on iOS

No, but there's hope it'll be supported under iOS8's app extensions and custom keyboards. It does have it's built-in browser for now.

Re: Notes on the Celebrity Data Theft

#223

The thing that bugs me is that you could have good password practices. But if you're having a party, having a fun time (and lets face it, people are going to do shit...), and one of your friends is snapping photos of you, and they have bad password practices, then you are kind of screwed. People don't typically make friends on the basis of: do you have good password practices.

Or you can use two-factor and strong passwords everywhere, but if your spouse is still using "letmein" on every account, you're gonna have a bad day soon.

Re: Notes on the Celebrity Data Theft

#224
post #78

> Password reset is answering the date of birth and security question challenges (often easy to break using publicly available data – birthdays and favorite sports teams, etc. are often not secrets) I really dislike this trend of "personal questions" to reset your password. The first car I owned or where I'd like to retire is easily obtained information. When are websites going to stop doing this? I answer these ques…

I'm moving to nonsense and random answers stored in Lastpass but what I had been doing is just answering them as if I were one of my friends. I have a dozen friends where I know most of those answers.

Re: Notes on the Celebrity Data Theft

#225

I'm wondering if simple GeoIP check can prevent lots of intrusion attempts - if the user consistently logs in from one location and then suddenly tries to log in with the wrong password from the distant one, that's the red flag that warrants temporary account lockout at least.

I swear Apple did this to me repeatedly last year while I was travelling for a month. I could never purchase apps.

One problem with this is VPNs. I regularly VPN (both to my house and via a service like Private Internet Access) so my location can change quit a bit.

Re: Notes on the Celebrity Data Theft

#226

Earlier quoted context omitted.

It's a pain, but really not that bad. You tweet from your phone (or use email/SMS/whatever else). 20 characters is manageable and secure, as long as it's randomly generated.

If it's randomly generated, it's impossible to remember to fill in on your phone. Unless you have it on a piece of paper in your wallet.

Really? I remember quite a few four-word (xkcd-style) random passphrases.

Re: Notes on the Celebrity Data Theft

#227
post #211

Earlier quoted context omitted.

You can't, but if you use a password manager, you can actually use different passwords on every service. And you can use stronger passwords (if the service permits), thus if they only lost the passwords datbased (assuming it's hashed) you are still safe.

No because say your cloud provider recycle your hard drive to another client with a bad password, then the attacker not only can access the data of the other client but can run a file recovery tool and get some of your files. Most providers don't erase disks properly. Takes too much time.

AFAIK most providers who don't erase disk get them destroyed. At least in EU.

Re: Notes on the Celebrity Data Theft

#228
post #179

Earlier quoted context omitted.

(disclaimer: not meaning to start any kind of flame-war) To be honest, the one I perceive (as a straight, white, middle-class, educated male) larger is the misandristic one. As a person who strives to be good and helpful to every human being equally, regardless of race, gender, orientation or whatever, I get everyday on the Internet and I get flooded by articles and comments saying that everything I do or think is mi…

Regardless of the truth or falsehood of what you're saying, no good (for you or anyone else) will come of making this one of your personal crusades, which it sounds like it is. There are far nobler causes than standing up to SJWs you feel have crossed some line of hypocrisy, and you are much more likely to be a force for harm than good in the world as a result.

You're right; therefore I try to limit my "crusading" to occasional venting out on social networks. As you said, there are far nobler causes to care about, with better ROI on effort.

Re: Notes on the Celebrity Data Theft

#229
post #122
post #24

Reddit should not be listed among the sites hosting the stolen images, as reddit does not support image uploads. Imgur is the primary site hosting the stolen images in that case.

You would have a point, but having just scanned the text, I couldn't find anywhere that it says the images are hosted on Reddit. It says they were "posted to Reddit" which is ambiguous at worst, very far from the allegation you are making.

The text says the stolen images "appeared" on reddit, which reads as an accusation that reddit users or admins were directly embedding the stolen images in pages on reddit itself via CSS or the tag.

The text also repeatedly clumps reddit together with 4chan and anon-ib, with the implication being that they are all sites capable of accepting direct image uploads.

What allegation do you feel I've made?

Re: Notes on the Celebrity Data Theft

#230
post #3
post #2

I wrote this in the other thread on the leak before it died: > Even if the leaks result from one at a time social engineering, it still really calls into question the practical security of the cloud. I doubt it's much harder to steal, e.g. confidential business documents from executives' cloud accounts than it is to steal pictures from celebrities' cloud accounts. > If I were a big organization with confidential info…

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

Stupid question but what happens if you forget the master password or someone steals it?
Post reply on HN