Live data from Hacker News

Quora User Data Compromised

blog.quora.com

121–130 of 525 posts

Re: Quora User Data Compromised

#121
post #45
post #28

Earlier quoted context omitted.

You would be correct. In the US, which I might remind you, does not have a national law on the books regarding data breach notification. Even at the state levels, it’s varies pretty wildly on top of, most notifications are only required if there is evidence. So here is the challenge: what if I keep no logs, and have terrible security monitoring capability? If I am notified or discover a critical vulnerability on my o…

Still, I would have thought it is good practice to notify your users if you leak their data to thieves. Quora did the right thing and should be applauded. As a counterexample, it seems that Newegg had a massive breach (thieves installed JavaScript that skimmed credit card numbers for weeks) in August, and even though my credit card was likely stolen, I hever heard about it from Newegg.

Not sure why you didn't hear from Newegg, but they did send out a mass email notification with details of the breach.

Re: Quora User Data Compromised

#122
post #67

I'm experiencing a sense of schadenfruede because I'm embittered by Quora's arrogant "real names" policy. They won't "let me" contribute. Nothing insightful. I'm just here to kick them while they're down.

I believe you're being cynical, because this forced name policy allows for answers to be of higher quality, which is basically their entire selling point - being a better yahoo answers. If you want anonymity there are other platforms for that, stackexchange for example.

That's a false dichotomy.

Ask MetaFilter is a much better Yahoo Answers, but I can be pseudonymous there. Also, my pseudonym is much closer to a real identity than what's on my driver's license.

I don't have any real reason to fear sharing my "real name" with Quora. I'm lucky. But I'm not the only person in the world. Good thing I'm not trans or a religious dissident. Good thing the only thing stopping me from contributing to Quora is my ornery nature. I would hate to for the world to miss out on my Quora contributions for a good reason.

Good thing Quora doesn't have my "real name" is all I'm saying. I have an interest in privacy, even though I use the same pseudonym as my identity on LinkedIn, Twitter, Facebook, and Instagram. And Ask MetaFilter. And so many other places. I shouldn't have to beg to use my preferred name on Quora's bulletin board, regardless of my reasons. It's none of their business.

There's nothing about a "real names" policy that automatically turns a shitposter into a quality contributor. There are plenty of reasons not to wear a target on your back and self-doxx. Today's misadventure is one very good reason.

Re: Quora User Data Compromised

#123
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

Hmmm, I have been using the Keepass + Dropbox combo. Wanted to change to a more streamlined experience. The current choices of 1Password, LastPass and Dashlane didn't seem to attract me.

I will give Bitwarden a try.

Re: Quora User Data Compromised

#124
> ...there’s little hope of sharing and growing the world’s knowledge if those doing so ... cannot trust that their information will remain private.

Here's a crazy idea, circa 1990's: don't store their personal information! Allow people to browse Quora without using their real names. I'm very happy I deleted my Quora account when I did.

Re: Quora User Data Compromised

#126

>I didn’t know I had a Quora account. How is it that my email or information was exposed? You may have signed up for Quora some time ago. While you might not have regularly visited or used Quora, your account remained, and this breach may have exposed some of your information, such as the email address you signed up with, the password you used, or actions you took on Quora. Would be nice if websites measured user act…

Byond (2d tile/sprite based online gaming platform) does this. After a year of no activity they inactivate your account, and delete the hashed password. You have to reset your password to regain access.

Re: Quora User Data Compromised

#127
Is Quora legally liable for compromised data? Making companies legally liable for compromised data might be one way for them to be scrupulous about minimal data retention.

Re: Quora User Data Compromised

#128

I'm angry at them for this, but more angry at myself for not deleting my data years ago when I stopped logging in.

I am angry at myself for signing up for this stupid quora. Nothing but advertising of offshore "web developers" explaining how their "product" can solve the "question" they asked with their fake accounts.

I would love to punch the CTO of this company in the nose with passion.

Re: Quora User Data Compromised

#129

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

Also snail and email invoices automatically provide you with your own copy they cannnot delete. In contrast to “past 12 months viewable online”.

Re: Quora User Data Compromised

#130
post #116

Earlier quoted context omitted.

You could just use a normal Citi or BoA or any other card that generates virtual card numbers and that'll also lock it to that vendor after the first charge. So that they couldn't even hit it for $0.80 if they wanted to.

Last time I checked, both Citi and BofA give me virtual card numbers via a Flash plugin. I really have no desire to run Flash any more. Has that changed?

Nope it hasn’t changed. It’s the same FIA Card Services Flash app from 2005.
Post reply on HN