Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

161–170 of 292 posts

Re: Notes on the Celebrity Data Theft

#161
I think the cloud has proven to be untrustable. One must assume that any data on any public cloud service (including email, photo libraries, documents, mobile device backups, etc.) will become public, and use the cloud with that mentality.

Re: Notes on the Celebrity Data Theft

#162
post #120

Earlier quoted context omitted.

Both groups certainly exist, but one is larger than the other by a few orders of magnitude.

(disclaimer: not meaning to start any kind of flame-war) To be honest, the one I perceive (as a straight, white, middle-class, educated male) larger is the misandristic one. As a person who strives to be good and helpful to every human being equally, regardless of race, gender, orientation or whatever, I get everyday on the Internet and I get flooded by articles and comments saying that everything I do or think is mi…

"the reason this leak contains only women celebrities has nothing to do with misogyny" ... "Not saying it's good or bad, it's just how the culture evolved"

I don't know what you've seen on your own facebook feed, but the articles I've seen are among other things pointing out that the leaks are part of a cultural trend in which women's bodies in particular are singled out for sexualization and commodification in a way that men's are not.

This is precisely misogyny.

Re: Notes on the Celebrity Data Theft

#163
post #74

Earlier quoted context omitted.

This is really easy. You have one good password for 1pass, and one good password for iCloud. If you can manage to memorize one, you can memorize two.

My real problem with this is writing the password with numbers, punctuation and stuff on a mobile keyboard. Feels like surgery even if I'd memorize it. I use 1P on my laptop most of the time so it's not a huge deal. Everything else on the iPhone just remembers credentials. I know I can force myself to use a great password for iCloud but my point is that most of the time, I'd go for an idiot password rather than forci…

that little voice in your head that is screaming "i hate this" is your problem. It really is not a big deal to type a password, and even to type it a few times, just try to have a more zen attitude about it. It's how passwords work, stop trying to figure out how to defeat your own password, it's doing what it's supposed to do.

Re: Notes on the Celebrity Data Theft

#164
post #97

Just to give OP a heads up: the article's font is rendering terribly in Windows Chrome.

I've noticed this with my own websites. Fonts consistently look great in FF and IE but terrible in Chrome. What can be done to fix this?

Turn of the DPI scaling in Windows.

http://support.microsoft.com/kb/2900023

Google around for the actual steps.

Re: Notes on the Celebrity Data Theft

#165
post #74

Earlier quoted context omitted.

This is really easy. You have one good password for 1pass, and one good password for iCloud. If you can manage to memorize one, you can memorize two.

My real problem with this is writing the password with numbers, punctuation and stuff on a mobile keyboard. Feels like surgery even if I'd memorize it. I use 1P on my laptop most of the time so it's not a huge deal. Everything else on the iPhone just remembers credentials. I know I can force myself to use a great password for iCloud but my point is that most of the time, I'd go for an idiot password rather than forci…

A good password doesn't need all that stuff. Just use something of sufficient length. A sentence, for example.

Re: Notes on the Celebrity Data Theft

#166
post #60

Earlier quoted context omitted.

Or a text file or spreadsheet containing passwords, in a TrueCrypt container (I still trust it).

Yep, I do the same. Master truecrypt container on a USB stick that just contains a text file with all my logons. Then whenever I change that file I backup the truecypt container to Spideroak so I'm not hosed if I my stick gets lost/broken/stolen.

That is completely unusable on mobile.

As someone who consistently needs my passwords on the go, a password manager is really the best way to go.

Re: Notes on the Celebrity Data Theft

#167

While I am complete appalled by the data breach and hope that similar things never happens to anyone again I would like to propose a purely thought experiment: The hacker reported sold the nude photos of Jennifer lawrence for a mere sum of $130 using bitcoin. If we apply game theory here, these kind of data is very difficult to monetize. If you sell one copy of the data, it is then immediately distributed online for…

https://en.wikipedia.org/wiki/Assassination_market

Probably this example is more accurately described as the 'ransom model'.

Re: Notes on the Celebrity Data Theft

#168
post #21

I use strong passwords generated by 1Password for everything.. except for iCloud. There I have an idiot password. Why? Because freaking iPhone asks for that when I want to download something from App Store. How do you guys handle that?

I've been using a scheme that involve easy to type password, like: qwertyuioplkjhgfdsa/ qazcdetgbmju / rtyujhgfvbnm (if you 're wondering how to memorize those password, looks at the QWERTY keyboard). Combining with number and capitalization, I feel pretty good about my odd of surviving the brute force/ dictionary attack. But I can't quite quality the exact amount of combinations for those schemes. Can anyone tell me why this would potentially be a bad idea?

Re: Notes on the Celebrity Data Theft

#169
post #79

Earlier quoted context omitted.

Nothing stops a threat from just lying and waiting for you to expose a large number of passwords. Having one stolen doesn't raise red flags in itself. I don't think signed addresses will be particularly effective. With the sort of key stores we have now, it seems pretty plausible that a bad actor to get a certificate that would pass on the Trezor device. It raises the barrier of entry a little though.

It should be just as effective as HTTPS is. Of course whether that's effective enough depends on who you ask. Yes, rogue/compromised CAs are occasionally a problem, but it generally works pretty well.

It doesn't hold up to SSL stripping very well. As we are working under the assumption of a compromised host, the absence of a signature on the Trezor when you don't expect one wouldn't raise any suspicion. The omnipotent host malware can remove all references to the payment request being signed from the payment gateway before the user sees it.

Re: Notes on the Celebrity Data Theft

#170
post #168
post #21

I use strong passwords generated by 1Password for everything.. except for iCloud. There I have an idiot password. Why? Because freaking iPhone asks for that when I want to download something from App Store. How do you guys handle that?

I've been using a scheme that involve easy to type password, like: qwertyuioplkjhgfdsa/ qazcdetgbmju / rtyujhgfvbnm (if you 're wondering how to memorize those password, looks at the QWERTY keyboard). Combining with number and capitalization, I feel pretty good about my odd of surviving the brute force/ dictionary attack. But I can't quite quality the exact amount of combinations for those schemes. Can anyone tell me…

I don't think it will necessarily work because some cracker has just probably added that to their personal dictionary(if they didn't before). It might work if you add 3.14159627 to it or a number/symbol set of your choice. I guess length is fairly key as well.
Post reply on HN