Live data from Hacker News

The Dropbox hack is real

troyhunt.com

131–140 of 557 posts

Re: The Dropbox hack is real

#131
post #119
post #79

Earlier quoted context omitted.

They are a company focussing on just one commercial product. Also I find there's some kind of pride in quality amongst mac-developers. Plus the lastpass vulnerability that was disclosed a couple of month ago seemed pretty basic and I haven't heard from serious vulnerabilities in 1password for a while. And that 1Password is local. All of that is just a feeling though, of course.

> They are a company focussing on just one commercial product. Or: "they are a company depending on just one commercial product". Doesn't look that good anymore hm? Try keepass for excample. It's local too and it's open source.

Keepass doesn't even serve it's updates over HTTPS, so who knows what i'm getting.

This fact alone make me lose all trust in it's developers.

Re: The Dropbox hack is real

#132

Earlier quoted context omitted.

> Self hosting is the way to go. Because you can secure it better than them? Or because you'll be less of a target?

It's not clear to me whether the grandparent is referring to self-hosting password management or file synchronisation. However, one obvious security advantage of self-hosting is that you can use end-to-end encryption (which most cloud sync services don't support). E.g., I use Resilio Sync (formerly Bittorrent Sync) for file sync with encryption-only keys on my cloud peer. The cloud peer participates in the mesh, prov…

> Resilio Sync (formerly Bittorrent Sync)

Good job they changed their name. Couldn't get the product adopted in a corporate environment because of all the cries of "Witch! Witch!" when the suits saw the word Bittorrent in there.

Re: The Dropbox hack is real

#133
post #119
post #79

Earlier quoted context omitted.

They are a company focussing on just one commercial product. Also I find there's some kind of pride in quality amongst mac-developers. Plus the lastpass vulnerability that was disclosed a couple of month ago seemed pretty basic and I haven't heard from serious vulnerabilities in 1password for a while. And that 1Password is local. All of that is just a feeling though, of course.

> They are a company focussing on just one commercial product. Or: "they are a company depending on just one commercial product". Doesn't look that good anymore hm? Try keepass for excample. It's local too and it's open source.

> Or: "they are a company depending on just one commercial product". Doesn't look that good anymore hm?

Actually it does. They depend on selling their product to security-savy users, so they will ensure it's quality.

Re: The Dropbox hack is real

#134
Great read.

He goes on to say that 1Password has a subscription now and that you should signup for it.

No. I will never, ever put all my passwords into a cloud based password store. I simply do not trust them to not fuck it up at one point in time.

Am I alone with this view?

Re: The Dropbox hack is real

#135
post #6

Since lots of people will be rotating passwords, this is probably a good time to set up Two-Factor Authentication (2FA) as well. I recommend Authy as your 2FA app, as it lets you set a backup password, which you can use to move your 2FA tokens between devices. For your critical services, keeping encrypted copies of your backup codes is a must.

And what happens if 2FA seeds are stolen from the site?

Re: The Dropbox hack is real

#136

Earlier quoted context omitted.

Why?

For me, it's that 1Password runs locally and doesn't need to phone home, whereas LastPass is "cloud". Also, LastPass being owned by LogMeIn doesn't sit right with me, but that's definitely personal. No idea about Keepass(x), although I found that ecosystem to be confusing, with different apps for different platforms you might accidentally download a rouge one on e.g. your phone. I know, paranoia.

Keepass isn't served over HTTPS.

http://www.lifehacker.com.au/2016/06/keepass-vulnerability-l...

Re: The Dropbox hack is real

#137
post #26

It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could s…

unique-per-service email addresses sound indeed interesting. How did you set it up?

I am a google apps customer and already have a few 20 aliases in there but having to go through their UI every time I sign up seems very tiresome. Can I create a wildcard email in the terms of service-*@bar.com being a alias of email foo@bar.com?

Do you know of a non-selfhosted provider that is able to do that?

/EDIT: Looks like fastmail, a service many on HN recommended is able to do something similar [0], though if one email gets added into a spam list, it seems to be not possible to remove one particular one.

/EDIT2: Fastmail just confirmed to be on Twitter that it is possible to set individual emails to rejected. Though this requires effectively creating a new alias and setting it to bounce which falls under the account limitations [1], so 600 for a single person account.

[0]: https://www.fastmail.com/help/receive/alias-catchall.html

[1]: https://www.fastmail.com/help/account/limits.html

Re: The Dropbox hack is real

#138
post #26

It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could s…

Yes but at the time, there was only evidence of password reuse leading to some comprised email lists... Not that password hashes themselves had been stolen. Sigh.

Re: The Dropbox hack is real

#139
post #77

Earlier quoted context omitted.

Except that the merchant still gets to see my credit card numbers (both sides). But it's how paypal works. The merchant only get an authorization code from paypal, and this code is useless to a hacker.

> the merchant still gets to see my credit card numbers (both sides) With chip and pin? I don't think they do.

In the UK the numbers are printed on the receipt - part obfuscated on the customers copy, fully shown on retailer copy. So whilst the retailer may not touch the card they still get everything except the magic 3 digits.

Where I work you need the 3 digit security code and some address numbers (which you can make up) to properly process a transaction without the card.

Post reply on HN