Live data from Hacker News

Quora User Data Compromised

blog.quora.com

171–180 of 525 posts

Re: Quora User Data Compromised

#171
The folks asking for snail mail are joking right? Snail mail is an obsolete relic of a time gone by, and belongs in the dust-bin of history alongside buggy whips, wood fired steam engines, betamax, etc.

Personally I'd pay to be able to stop getting snail mail. If it weren't for the one or two rare pieces of semi-important crap that show up, sent by dinosaurs that don't realize we aren't living in the 20th century anymore, I'd quit checking my physical mailbox once and for all. I mean, it's not like 99/100'ths of what comes in there isn't junk catalogs, fundraising letters from politicians I hate, sales flyers from stores I hate, bills that I pay online already, mail meant for the previous residents, etc. But unlike email spam, it actually costs me effort to scrape that garbage out of the box and haul it to the dumpster.

Blech. Personally, I want no part of it.

Re: Quora User Data Compromised

#172
post #67

I'm experiencing a sense of schadenfruede because I'm embittered by Quora's arrogant "real names" policy. They won't "let me" contribute. Nothing insightful. I'm just here to kick them while they're down.

It's not that hard to be as anonymous as you like on Quora. It's been a while since I contributed, because I got tired of their schizophrenic moderation, but I don't recall that mobile text authentication was necessary. Unlike say, Twitter. And even that isn't all that hard to get around, using hosted SIMs.

Re: Quora User Data Compromised

#173
Is it really that hard to keep a database secure?

Genuine question - not sarcasm. I would love to know how the attackers got in in the first place.

Usually when I hear about a breach, my first reaction is “yeah, I would have covered that from the start,” but if there’s something to be learned here, I’m all for it...

Re: Quora User Data Compromised

#174
post #143
post #67

I'm experiencing a sense of schadenfruede because I'm embittered by Quora's arrogant "real names" policy. They won't "let me" contribute. Nothing insightful. I'm just here to kick them while they're down.

Are names validated?

Not in my experience.

Re: Quora User Data Compromised

#177
post #91

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

I’m happy with privacy.com

I’m using two personal domains fo host my own email. One domain is purely for registration/junk purposes and it forwards *@junkemail.com —> junk@myemail.com.

The same server uses nextcloud for calendar/contacts/webdav

I use the password manager Enpass which can sync via webdav across my devices.

Everything selfhosted and emails/credit cards disposable

Re: Quora User Data Compromised

#178

Earlier quoted context omitted.

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

Install the LastPass binary, and you get copy password back in Firefox.

Ah good to know. Does anyone know the reason they removed it from the Firefox addon?

Re: Quora User Data Compromised

#179

Wow. If this had happened a couple years ago, before they made all the anonymous entries truly anonymous, this would have been really ugly. It's a valuable lesson in "don't keep data you don't need". EDIT: A little backstory for non-Quorans. Until early 2017, anonymous Quora answers and comments were anonymous to the public but not actually anonymous in the database (they were still "your" entries). In early 2017 the…

Retroactively, right?

I worked at Quora, but left before this change was made, but I believe it was totally retroactive, mainly because I got emails with information about my previous anonymous answers and a deadline to get the one-time link.

Now... if the emails were logged and in the exploited database, then all bets are off, but there's no indication that happened at all.

There are about a hundred other things about this that give me anxiety, but Quora is run by extremely competent people (engineering and otherwise), so I am pretty confident about their ability to be transparent and to know the extent of any issue.

This entire thing is really shitty for everyone involved, but given Quora's tenure (almost nine years!) that this is the first breach is pretty amazing, and that they've done so much work to make it less of a problem is great.

None of the above is meant to diminish the general dissatisfaction others are expressing here.

Re: Quora User Data Compromised

#180
post #155

The Quora link to more details is a masterpiece of corporate obfuscation. Posing as a FAQ, it presents questions, then proceeds to not answer them (at least, as of a few minutes ago). https://help.quora.com/hc/en-us/articles/360020212652 What happened? - not answered in any detail What kind of user data was affected? - answered! How do I know if I was affected? - not answered How was it brought to your attention? - n…

All of these appear filled out now.

Quora is good about responding quickly, which should be appreciated. That the FAQ wasn't fully filled out was just because it was being filled out. I know this can be an awkward experience for someone who immediately sees and responds to the tech news, but a bulk of their users won't be that profile. They got the framework for response laid out immediately, and are working on the responses. This seems pretty solid.

Post reply on HN