Live data from Hacker News

Quora User Data Compromised

blog.quora.com

141–150 of 525 posts

Re: Quora User Data Compromised

#141
post #73

Are there any details about how the passwords were stored? "Encrypted" is a bit questionable. I'd expect hashed.

They clarify that the passwords were indeed hashed and salted. "Encrypted" is just there to help the non-technical audience understand their passwords aren't exactly leaked in plaintext. No details on the hashing scheme used though, so we don't really know how easy it'll be for the attacker to brute force the password hashes.

Because they didn't mention it, and the age of the site makes me think it isn't something we'd consider secure.

Re: Quora User Data Compromised

#142
It's genuinely hard to imagine a second-rate question and answer site could have any credentials, or indeed any non-public content, that anyone else could be interested in. From the list of what's been taken, it sounds like it's mostly email and hashed passwords, though I suspect Quora's user base is not entirely populated by people committed to a strict one-off password policy.

Happily I get to once again bemoan the disappearance of JCSV, who was astounded that Quora was still a thing five years ago: http://jesuschristsiliconvalley-blog.tumblr.com/post/4896203...

Re: Quora User Data Compromised

#144
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

Install the LastPass binary, and you get copy password back in Firefox.

Re: Quora User Data Compromised

#145

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

> One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via email. Then that disappeared and now you have to create an account on some portal so that you can download your invoice. So that's one userid/password combo per business relationship or service that you use privately.

It's annoying being on the other end of this: management deciding, for cost reasons, that snail mail is out and email is in.

Somebody else then worries about the risks of emailing documents that contain private information.

I think a case can be made that some kind of email token login is the simplest solution here: passwords only introduce another attack vector since you can usually reset them by email.

Are there more elegant solutions to this problem?

Re: Quora User Data Compromised

#147
post #65

So I'm not a security expert, so I ask this in real earnest to learn: what is it that these companies keep doing wrong, and/or why aren't they adjusting to the climate that these types of attacks are increasing over time? Or are they trying to adjust, and the attacks are getting so sophisticated that the pace of investment in counter-measures is below that of the pace of advancement in the complexity of attacks? Or s…

It’s a whole lot of things, but first and foremost and probably the simplest explanation, security is hard. Incredibly hard. Once you understand how difficult attack mitigation is, then you can pick and choose from a variety of factors: - executives may not have a realistic understanding of how difficult attack mitigation is so they don’t allocate the resources for hiring - incompetent admins overestimating their abi…

An organization running original software on the internet first needs to be preventing vulnerabilities in its own codebase. Nothing “admins” do is going to help much if the application itself is full of SQL injection and direct object reference. You can have impeccable configuration, firewalls, etc. and not even be playing the game.

Re: Quora User Data Compromised

#148

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

Companies hate users who don't want to sign up. They do not want that relationship. So it's a win-win if you dont' sign up. Why would companies feel obligated to generate content for free?

If their systems get hacked and they have your snail mail address, they get your snail mail address as well. Email doesn't change that story.

Re: Quora User Data Compromised

#149
post #91

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

Was the water company thankful enough to compensate you for the $X,000 consulting services you provided because they didn't set up their own security monitoring?

Re: Quora User Data Compromised

#150

Earlier quoted context omitted.

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

Install the LastPass binary, and you get copy password back in Firefox.

Not on Linux, and we've waited too long. 1Password supports it direct from the extension.
Post reply on HN