Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

231–240 of 292 posts

Re: Notes on the Celebrity Data Theft

#231
post #219

Earlier quoted context omitted.

They've had two-step authentication since March of 2013: http://support.apple.com/kb/ht5570

Except the article seems to be saying that Apple's two-factor auth isn't required to access iCloud backups and that it only protects account details, payment methods, etc.

Adding two-factor gets rid of the security questions and would have prevented them from getting the password though.

Re: Notes on the Celebrity Data Theft

#233
I use a Yubikey with a generated key.

This is only half of my password; the first part is a password I can remember easily with numbers and letters, the second is the generated key.

This means that even I don't really know my password and if someone found my Yubikey then it's useless to them without the other half that only I know.

(I do have a printout in a safe place of the key and also a backup Yubikey)

I use this password for my computer as well as my 1password vault which is generally filled with randomly generated keys for each website.

Might sound a bit overkill but if you can; why not?

Re: Notes on the Celebrity Data Theft

#234
post #136

Earlier quoted context omitted.

That's not how 1Password works. All passwords for 1Password are stored locally in an AES encrypted file. They never see, touch, or have any control over your passwords on their end. Even if they suddenly shut down tomorrow, all your passwords would still be accessible unless you chose to delete the application and have zero backups to restore from. They even have an export function to dump the passwords (unencrypted)…

You are 100% correct. To add to this all syncing on 1Password is done using 3rd party vendors. You can use dropbox, iCloud, Google Drive, etc to do the actual syncing of the encrypted files.

I still don't see the benefits of 1Password from a cost perspective, regardless of a trust perspective.

I can spend $40-80 and buy a bunch of 1Password license packages, or I can use KeePass and place the database in my Dropbox folder. Yes, 1Password has a more aesthetic interface, but otherwise it basically does the exact same thing.

Re: Notes on the Celebrity Data Theft

#235

I use a Yubikey with a generated key. This is only half of my password; the first part is a password I can remember easily with numbers and letters, the second is the generated key. This means that even I don't really know my password and if someone found my Yubikey then it's useless to them without the other half that only I know. (I do have a printout in a safe place of the key and also a backup Yubikey) I use this…

What's the advantage to this over simply using 1password?

Re: Notes on the Celebrity Data Theft

#236

I use a Yubikey with a generated key. This is only half of my password; the first part is a password I can remember easily with numbers and letters, the second is the generated key. This means that even I don't really know my password and if someone found my Yubikey then it's useless to them without the other half that only I know. (I do have a printout in a safe place of the key and also a backup Yubikey) I use this…

That sounds secure, but help me understand: Is it the same password everywhere? How do you manage the different passwords for different services? How do you enter your password to login on an ipad, or on your phone?

My biggest problem with the Apple's password policy is that I'm required to enter it periodically on an ipad or iphone - meaning I can't keep it lastpass and that complex alphanumeric passwords are even harder to enter.

Re: Notes on the Celebrity Data Theft

#237

I use a Yubikey with a generated key. This is only half of my password; the first part is a password I can remember easily with numbers and letters, the second is the generated key. This means that even I don't really know my password and if someone found my Yubikey then it's useless to them without the other half that only I know. (I do have a printout in a safe place of the key and also a backup Yubikey) I use this…

What's the advantage to this over simply using 1password?

It's mainly for my laptop to be honest but as it's just a tap away why not secure my 1password vault more securely at the same time?

I also run software on my MacBook Pro so that when I pull the Yubikey it automatically engages the screensaver which in turn requires the password to disable.

Re: Notes on the Celebrity Data Theft

#238
post #92

Earlier quoted context omitted.

Well, Keepass is free as in beer too, so from a licensing perspective, that's a factor (mainly for adoption) though, 1Password is a totally affordable and solid investment for 99%+ of folks on this board). Free allows much more organic adoption - I can recommend a friend to use KeePass without worrying a bit that he doesn't think 1Password is a good investment. I can mandate it for my team at work without having to g…

Free as in beer is a reason to be more distrustful of the software. Sure it's more convenient, but this seems to be an area where it's really worth investing money in getting the more reliable solution.

Are you by chance a purchasing manager for a large corporation? Do you feel that signing a $100K-$1M Oracle contract is worth it because "if MySQL or PostgreSQL were worth something, then they would charge you for it?"

Re: Notes on the Celebrity Data Theft

#239
post #92

Earlier quoted context omitted.

Well, Keepass is free as in beer too, so from a licensing perspective, that's a factor (mainly for adoption) though, 1Password is a totally affordable and solid investment for 99%+ of folks on this board). Free allows much more organic adoption - I can recommend a friend to use KeePass without worrying a bit that he doesn't think 1Password is a good investment. I can mandate it for my team at work without having to g…

Free as in beer is a reason to be more distrustful of the software. Sure it's more convenient, but this seems to be an area where it's really worth investing money in getting the more reliable solution.

IMHO, the license is not really the big question for this type of software. The most important thing is the competence of the team(s) who wrote and audited the software.

Re: Notes on the Celebrity Data Theft

#240
post #236

I use a Yubikey with a generated key. This is only half of my password; the first part is a password I can remember easily with numbers and letters, the second is the generated key. This means that even I don't really know my password and if someone found my Yubikey then it's useless to them without the other half that only I know. (I do have a printout in a safe place of the key and also a backup Yubikey) I use this…

That sounds secure, but help me understand: Is it the same password everywhere? How do you manage the different passwords for different services? How do you enter your password to login on an ipad, or on your phone? My biggest problem with the Apple's password policy is that I'm required to enter it periodically on an ipad or iphone - meaning I can't keep it lastpass and that complex alphanumeric passwords are even h…

My iOS accounts are, unfortunately limited to a password that I can remember but I use one with numbers and letters and a mixture of uppercase and lowercase characters.

Most of my website passwords are generated keys; each different - all stored within 1password, should there be an issue at any point (doubtful) I can always go through the "forgot password" features on any given website to reset it to something temporarily that I can use easily.

Post reply on HN