Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

241–250 of 292 posts

Re: Notes on the Celebrity Data Theft

#241
post #136

Earlier quoted context omitted.

You are 100% correct. To add to this all syncing on 1Password is done using 3rd party vendors. You can use dropbox, iCloud, Google Drive, etc to do the actual syncing of the encrypted files.

I still don't see the benefits of 1Password from a cost perspective, regardless of a trust perspective. I can spend $40-80 and buy a bunch of 1Password license packages, or I can use KeePass and place the database in my Dropbox folder. Yes, 1Password has a more aesthetic interface, but otherwise it basically does the exact same thing.

IMO, the big question is: Who do you trust more when it comes to cryptography and security engineering? The 1Password developers or the KeePass developers?

Re: Notes on the Celebrity Data Theft

#242
post #230
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

Stupid question but what happens if you forget the master password or someone steals it?

Then you have to reset every password and start over.

Re: Notes on the Celebrity Data Theft

#243
post #3
post #2

I wrote this in the other thread on the leak before it died: > Even if the leaks result from one at a time social engineering, it still really calls into question the practical security of the cloud. I doubt it's much harder to steal, e.g. confidential business documents from executives' cloud accounts than it is to steal pictures from celebrities' cloud accounts. > If I were a big organization with confidential info…

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

Looks like they still don't have a native Linux client though.

Re: Notes on the Celebrity Data Theft

#244
post #7

Why is nobody talking about password reset questions?

I'm not sure if it's completely fair, but everytime I see "security questions" I can't help think: "Oh, it's an American site". Silly "security" questions about mothers, dogs and favorite teachers seems to be cultural to the US (and maybe Canada), why is that?

The whole "mother's maiden name" thing is pretty popular in US banks. I'd wager this is where it came from.

Then again, you are talking about a country where the only thing people need to steal your identity is your ... social security number. Brilliant.

Re: Notes on the Celebrity Data Theft

#245
post #192
post #142

> 6. iCloud is the most popular target because Picture Roll backups are enabled > by default and iPhone is a popular platform. Windows Phone backups are > available on all devices but are disabled by default (it is frequently enabled, > although I couldn’t find a statistic) while Android backup is provided by > third party applications (some of which are targets). Fragmentation, for the (security) win! Not really, of…

Does Android really not provide an auto upload of snapped pictures to the cloud? I was under the impression that they did this way before iCloud even came up. First it was to Picasa or some place, then to the google+ place somewhere. Either way, I don't even remember if the iCloud upload was default or not. When it was introduced I took an interest to find out how to deactivate that in case it was enabled by default.…

> Does Android really not provide an auto upload of snapped pictures to the cloud? I was under the impression that they did this way before iCloud even came up. First it was to Picasa or some place, then to the google+ place somewhere.

When you sign into Google+ or Dropbox (among others), you are presented with a screen where you can enable photo uploads to those cloud accounts.

Re: Notes on the Celebrity Data Theft

#246
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

Looks like they still don't have a native Linux client though.

pass - http://www.passwordstore.org/

Re: Notes on the Celebrity Data Theft

#247
post #120

Earlier quoted context omitted.

Both groups certainly exist, but one is larger than the other by a few orders of magnitude.

(disclaimer: not meaning to start any kind of flame-war) To be honest, the one I perceive (as a straight, white, middle-class, educated male) larger is the misandristic one. As a person who strives to be good and helpful to every human being equally, regardless of race, gender, orientation or whatever, I get everyday on the Internet and I get flooded by articles and comments saying that everything I do or think is mi…

> To be honest, the one I perceive (as a straight, white, middle-class, educated male) larger is the misandristic one. As a person who strives to be good and helpful to every human being equally, regardless of race, gender, orientation or whatever, I get everyday on the Internet and I get flooded by articles and comments saying that everything I do or think is misogynistic, wrong and overprivileged.

This is just another not-all-men complaint. Certainly if you are a man who doesn't do the things someone is complaining about, then you have nothing to worry about. Unless, of course, the things you are doing on the internet are wrong and misogynistic, in which case people are sending you articles and comments for a reason.

Re: Notes on the Celebrity Data Theft

#248
post #124

Earlier quoted context omitted.

I got screwed by a password manager that got deleted during upgrading a hard drive. Never again

That's more or less why I use LastPass. Same concept, only decrypts client-side, but is automatically preserved across machines and hardware failure.

I use Lastpass. I just logged in online and can see all my passwords so it doesn't seem terribly secure. I there was key-logging malware on my machine it could have got my master password and hence all my passwords off Lastpass. It seems handy for all the crap passwords but I would not want to rely on it for anything that lets people nick money. Unless I'm missing something...

Re: Notes on the Celebrity Data Theft

#249

Earlier quoted context omitted.

They've had two-step authentication since March of 2013: http://support.apple.com/kb/ht5570

Only available in certain countries though. Mine being one that isn't yet available (Finland).

Their FAQ says it's available in Finland

Re: Notes on the Celebrity Data Theft

#250

Earlier quoted context omitted.

The problem is to tap all of that into your phone, every time iOS decides it desperately needs it again, with just stars instead of letters. That's annoying.

It's a pain, but really not that bad. You tweet from your phone (or use email/SMS/whatever else). 20 characters is manageable and secure, as long as it's randomly generated.

20 chars: bu-Y6Bx(94ijk1Y5$kWx
Post reply on HN