Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

281–290 of 292 posts

Re: Notes on the Celebrity Data Theft

#281
post #80

Choice quote: To reiterate what the main bugs are that are being exploited here, roughly in order of popularity / effectiveness: Password reset (secret questions / answers) Phishing email Password recovery (email account hacked) Social engineering / RAT install / authentication keys Note: Not weak passwords.

Here's a question: How did the attacker get the usernames of the celebrities? Those aren't exactly public info (unless they used the same name as their Instagram account or something).

The article discusses this very point in some detail (see especially point 7 about iCloud email testing).

Re: Notes on the Celebrity Data Theft

#282
post #171
post #60

Earlier quoted context omitted.

Or a text file or spreadsheet containing passwords, in a TrueCrypt container (I still trust it).

Don't you run the risk of getting the text file or spreadsheet cached to the temp directory?

Good point. I doubt Notepad caches anything on a different drive, but Excel would if auto-save is enabled.

Re: Notes on the Celebrity Data Theft

#283

Earlier quoted context omitted.

Yep, I do the same. Master truecrypt container on a USB stick that just contains a text file with all my logons. Then whenever I change that file I backup the truecypt container to Spideroak so I'm not hosed if I my stick gets lost/broken/stolen.

That is completely unusable on mobile. As someone who consistently needs my passwords on the go, a password manager is really the best way to go.

Do you have to trust that the password manager doesn't upload the passwords? I trust TrueCrypt since it isn't specifically for passwords.

Re: Notes on the Celebrity Data Theft

#284

Earlier quoted context omitted.

I use Dropbox, but my password for Dropbox itself is stored inside 1Password. The escape hatch is that the 1Password sync folder is shared publicly, and the URL is copied to a slip of paper in my wallet.

Why would you ever expose the sync folder publicly? Just keep a copy on a local computer with Dropbox if need be.

Because I only have one computer and no mobile devices— therefore I only have one copy of the password database, and I need the password database to access Dropbox.

The sync folder is encrypted—is there some risk I'm not seeing?

Re: Notes on the Celebrity Data Theft

#285
post #261

Earlier quoted context omitted.

What if you're not on your computer and you want to check something on gmail, or facebook, or airbnb, etc...

They have a mobile version that syncs your passwords across devices. I use the iOS app frequently.

Yeah but still, if you don't have a smartphone, or you don't have your mobile, or you can't use your mobile (different country, no wifi). You're pretty much kicked out of your own accounts.

Re: Notes on the Celebrity Data Theft

#286
post #179

Earlier quoted context omitted.

(disclaimer: not meaning to start any kind of flame-war) To be honest, the one I perceive (as a straight, white, middle-class, educated male) larger is the misandristic one. As a person who strives to be good and helpful to every human being equally, regardless of race, gender, orientation or whatever, I get everyday on the Internet and I get flooded by articles and comments saying that everything I do or think is mi…

Regardless of the truth or falsehood of what you're saying, no good (for you or anyone else) will come of making this one of your personal crusades, which it sounds like it is. There are far nobler causes than standing up to SJWs you feel have crossed some line of hypocrisy, and you are much more likely to be a force for harm than good in the world as a result.

SJWs are not beyond criticism, nor should they be:

http://studentaffairsfeature.com/ten-counterproductive-behav...

Re: Notes on the Celebrity Data Theft

#287

Earlier quoted context omitted.

The whole "mother's maiden name" thing is pretty popular in US banks. I'd wager this is where it came from. Then again, you are talking about a country where the only thing people need to steal your identity is your ... social security number. Brilliant.

Stealing the social security number in Denmark is just as bad and possible easier than in the US. If you know a persons birthday and gender you have at least a 1 in 500 chance of simply guessing the last four digits.

That's exactly not the point. The point is that it shouldn't matter that other people know your SSN. What effect does it have in Denmark when other people know your SSN?

Re: Notes on the Celebrity Data Theft

#288
post #187

Earlier quoted context omitted.

12 character? Please! ;-) (Most of mine are markedly longer.) Though I'll admit to being a tad less aggressive on the rotation than I ought to be.

A lot of sites don't allow more than 12 chars. Of the top of my head, Nintendo's rewards scheme has a limit on the number of characters, it lets you use more but actually truncates the password to 12 or so. Some sites truncate it on the sly then say "incorrect username or password!" when you enter your stored 16+ character password. Other sites silently break if you use characters outside A-Za-z0-9. e.g. you set a pa…

Oh, I know. God do I ever know.

I use a password generator. My defaults are _long_. But the nice thing is that I can pass it most constraint rules reasonably readily to create a valid password if I need to fit another use-case.

I don't use Ebay, but that sounds particularly annoying. Conversation on G+ suggests that the copy/paste defeat is to combat copy/paste exploits elsewhere, though by that point you might as well declare game over anyhow.

I'm definitely _not_ using "Monkey123" everywhere. But a lot of sites get a perfectly cromulent password ... and a mailinator.com email address (also randomly generated). I never use the same tokens twice (mostly registration-required but no real utility / long-term state storage).

Re: Notes on the Celebrity Data Theft

#289
post #238

Earlier quoted context omitted.

Are you by chance a purchasing manager for a large corporation? Do you feel that signing a $100K-$1M Oracle contract is worth it because "if MySQL or PostgreSQL were worth something, then they would charge you for it?"

Thanks for the straw man and entirely manufactured quote. We're talking about paying $50 for software that manages your passwords for everything, not paying hundreds of thousands to millions of dollars.

> Free as in beer is a reason to be more distrustful of the software.

> this seems to be an area where it's really worth investing money in getting the more reliable solution.

You're stating that "Free as in Beer" == "Less Reliable" and the fact that something costs money implies with 100% accuracy that it is reliable. Neither of these are true. Arguing that I'm bringing up a strawman because I said "Free vs. Millions of Dollars" instead of "Free vs. $50" is beside the point.

Re: Notes on the Celebrity Data Theft

#290
post #289

Earlier quoted context omitted.

Thanks for the straw man and entirely manufactured quote. We're talking about paying $50 for software that manages your passwords for everything, not paying hundreds of thousands to millions of dollars.

> Free as in beer is a reason to be more distrustful of the software. > this seems to be an area where it's really worth investing money in getting the more reliable solution. You're stating that "Free as in Beer" == "Less Reliable" and the fact that something costs money implies with 100% accuracy that it is reliable. Neither of these are true. Arguing that I'm bringing up a strawman because I said "Free vs. Million…

I am not saying either. I'm saying "Free as in beer" is not a reason to trust software in this particular field, i.e. the field of security software where one error can undermine the whole point of the software and expose your secret data to the world.

And I never even came close to saying that "something costs money implies with 100% accuracy that it is reliable". You are once again making up words to put in my mouth.

The fact is, a lot of people still believe the "open source == more eyeballs" myth, even though that is a myth. Open source does not equate to reliability. And when it comes to software that requires this much trust, a company built around a product is more inherently trustworthy than open source, as the entire company is on the line with their product (and the livelihood of all their employees), whereas with the open source product only the reputation of the author(s) is at stake.

Please note that, once again, I am not saying this is a "100% accurate" indicator of reliability. There are many factors at play. One important factor would be whether the software in question has ever undergone a security audit. Another would be whether there's proper documentation on the encryption (i.e. 1Password's file format is completely documented, both so third party software can use it if need be, and so the security of the file format can be vetted). A third would be the involvement of anyone who is already previously known to be an expert in the field. Etc.

Edit: Come on guys, please stop drive-by downvoting. If you disagree, comment!

Post reply on HN