Earlier quoted context omitted.
Why do you trust the hacker? By definition, hackers are not the trustworthy kind. He may have 7 million emails and passwords from elsewhere and make bold claims to collect bitcoins from lower ranks of hackers. I initially thought that some smartass created a bunch of accounts and posted them to collect some bitcoins from the naive. Particularly, because emails are so similar, i.e. I speculated that he did that to sim…
> By definition, hackers are not the trustworthy kind. That's a pretty bold assertion to make on a a site called "Hacker News"...
Dropbox wasn't hacked
31–38 of 38 posts
Re: Dropbox wasn't hacked
#32Would be interesting to know what third party service it was and how they were able to make that link. Also the pastebin claimed such a large amount (6,937,081) of impacted users but only showed a really small sample that started with the letter 'b'. Based on that sample they were already covering letters (bf, bg, bh). So I doubt this is anywhere near the claimed amount. Asking for 'BTC' to leak more (who wants to pa…
Why do you trust the hacker? By definition, hackers are not the trustworthy kind. He may have 7 million emails and passwords from elsewhere and make bold claims to collect bitcoins from lower ranks of hackers. I initially thought that some smartass created a bunch of accounts and posted them to collect some bitcoins from the naive. Particularly, because emails are so similar, i.e. I speculated that he did that to sim…
Re: Dropbox wasn't hacked
#33So ... what's the lesson here for our non-nerdy friends & family? I immediately sent my closest friends a "change your Dropbox password" email, which is still valid because, whether they were hacked or not, someone may now have their password. Which is probably also their password to Facebook. I suppose the question is, does it matter if Dropbox was hacked or if these credentials were gained by some other means? The…
> So ... what's the lesson here for our non-nerdy friends & family? The sad truth seems to be that Dropbox, iCloud and other cloud services are not safe enough for confidential or sensitive information. Regardless whether or not Dropbox was hacked this time, they have been compromised in the past and most likely will be in the future. In addition to security issues, there have been data loss and integrity issues, so…
Re: Dropbox wasn't hacked
#34This shows more, why we need solutions like http://storj.io/
Re: Dropbox wasn't hacked
#35Earlier quoted context omitted.
> So ... what's the lesson here for our non-nerdy friends & family? The sad truth seems to be that Dropbox, iCloud and other cloud services are not safe enough for confidential or sensitive information. Regardless whether or not Dropbox was hacked this time, they have been compromised in the past and most likely will be in the future. In addition to security issues, there have been data loss and integrity issues, so…
Yeah, but snowden has been saying this for a while, but nobody listens.
Here we're talking about average people's passwords leaked to the general public. Your files could be accessible by anyone. Or irrecoverably lost due to a bug. This has obvious consequences to the average person.
Well, I don't expect the average to understand the issue nor be able (read: want) to do anything about it (ie. encrypt before handing over their data to untrusted third parties).
Quite frankly, Jennifer Lawrence's nude photographs had more influence on the average person's thoughts about computer security than Snowden's revelations. As sad as it is.
Re: Dropbox wasn't hacked
#36Earlier quoted context omitted.
Why do you trust the hacker? By definition, hackers are not the trustworthy kind. He may have 7 million emails and passwords from elsewhere and make bold claims to collect bitcoins from lower ranks of hackers. I initially thought that some smartass created a bunch of accounts and posted them to collect some bitcoins from the naive. Particularly, because emails are so similar, i.e. I speculated that he did that to sim…
It would be really interesting if a hacker found a way to harvest _new_ passwords and faked a huge data breach to get millions of people to change their passwords. Threatening fake data breaches if not paid a ransom could be the next profitable hacker market. It would probably work a few times, and certainly muddy up the waters for both organizations and people. Imagine trying to figure out how to respond when 10 maj…
Re: Dropbox wasn't hacked
#37So ... what's the lesson here for our non-nerdy friends & family? I immediately sent my closest friends a "change your Dropbox password" email, which is still valid because, whether they were hacked or not, someone may now have their password. Which is probably also their password to Facebook. I suppose the question is, does it matter if Dropbox was hacked or if these credentials were gained by some other means? The…
No offence, but in my humble opinion using 1password, or any password manager, does not make you a better or more secure user. Perhaps even lowers your security in ways. Sharing the fact (with the internet) that you use a password manager, lowered your security already, technically speaking. I find the idea to use one password (and a private key etc) to protect all my other accounts and passwords a bit strange, speci…
When you use a password manager and separate passwords for each website, you're effectively eliminating an entire class of potential attacks, because any leaks from the website will not affect your accounts elsewhere (especially bad for accounts with privileges such as your email or bank accounts).
In exchange, you use a password or key to locally decrypt the rest of your passwords. This means for someone to have access to your password store they have to (1) find a vulnerability in the password manager store file or (2) obtain access to your machine. Comparing these, (1) is much less likely than getting a password list from a server with more attack surfaces, and (2) would also leak your passwords even without a password manager.
It may seem strange to think of all your passwords as being protected by a single password, but the key concept is that you aren't sending that password across the wire, but do regularly send the others. If your local machine is insecure, it doesn't really matter whether or not you are using a password manager.
Obviously, it would be even more secure to have different passwords for each website and be able to remember all of them, but it's not a very reliable method of storage and puts too large a burden on the user.
Re: Dropbox wasn't hacked
#38Earlier quoted context omitted.
No offence, but in my humble opinion using 1password, or any password manager, does not make you a better or more secure user. Perhaps even lowers your security in ways. Sharing the fact (with the internet) that you use a password manager, lowered your security already, technically speaking. I find the idea to use one password (and a private key etc) to protect all my other accounts and passwords a bit strange, speci…
I disagree. When you use a password manager and separate passwords for each website, you're effectively eliminating an entire class of potential attacks, because any leaks from the website will not affect your accounts elsewhere (especially bad for accounts with privileges such as your email or bank accounts). In exchange, you use a password or key to locally decrypt the rest of your passwords. This means for someone…
Then somebody managing to capture all my login details in different websites with a per website login in a particular time frame, they would need a year to capture all logins as i don't use all sites daily weekly, or even monthly.
One can discuss it short, one can discuss it long :) but you remain to put all your (generated) eggs in a single basket. A basket (computing security does not exist, it only delays things) that cannot be more secure then your mind.