Live data from Hacker News

Quora User Data Compromised

blog.quora.com

181–190 of 525 posts

Re: Quora User Data Compromised

#181

Is it really that hard to keep a database secure? Genuine question - not sarcasm. I would love to know how the attackers got in in the first place. Usually when I hear about a breach, my first reaction is “yeah, I would have covered that from the start,” but if there’s something to be learned here, I’m all for it...

Yes it is, when you have the surface area of a company like Quora, or even a much smaller company.

I worked at Quora, and totally unrelated, at my current company, had the opportunity to source and be point on multiple penetration tests. At my current company, I work with some people I consider extremely competent at SQL, and in particular PostgreSQL, but that didn't stop the pentesters from finding SQLi in our code. It sneaks in, and all it takes is one fuck up for a hacker to go to town.

I think that most startups don't understand the value of dropping 20-30k on an engagement with a competent pentest company, and this can propagate even longer into an org to the point that they never bother to get outside testing. Don't fall into that trap. Having a third-party with eyes on your org is worth every cent. If you run a startup or aspire to, I highly recommend you consider getting a pentest when you have ~5M ARR, and continue to do a yearly engagement to make sure your shit is covered until you can afford a full time security staff.

Re: Quora User Data Compromised

#182
post #52

Earlier quoted context omitted.

I see no lesson to be learned from the business perspective. If equifax can recover from their data loss, any company can.

Well equifax didn’t harm any of their customers so their bounce back should be no surprise.

I'll bite. How did they not harm their users?

Re: Quora User Data Compromised

#183
post #67

I'm experiencing a sense of schadenfruede because I'm embittered by Quora's arrogant "real names" policy. They won't "let me" contribute. Nothing insightful. I'm just here to kick them while they're down.

It's not that hard to be as anonymous as you like on Quora. It's been a while since I contributed, because I got tired of their schizophrenic moderation, but I don't recall that mobile text authentication was necessary. Unlike say, Twitter. And even that isn't all that hard to get around, using hosted SIMs.

Can you elaborate on the hosted SIMs thing? More and more websites are starting to ask for SMS verification and blocking VOIP numbers like google voice and it is getting really annoying.

Re: Quora User Data Compromised

#184
post #45

Earlier quoted context omitted.

Still, I would have thought it is good practice to notify your users if you leak their data to thieves. Quora did the right thing and should be applauded. As a counterexample, it seems that Newegg had a massive breach (thieves installed JavaScript that skimmed credit card numbers for weeks) in August, and even though my credit card was likely stolen, I hever heard about it from Newegg.

Not sure why you didn't hear from Newegg, but they did send out a mass email notification with details of the breach.

I somehow got their email a week or so after the event, and after my card's fraud prevention called for suspicious activity, reverted the transactions and cancelled my card. The bank official was not aware of the leak.

Re: Quora User Data Compromised

#185
post #65

Earlier quoted context omitted.

It’s a whole lot of things, but first and foremost and probably the simplest explanation, security is hard. Incredibly hard. Once you understand how difficult attack mitigation is, then you can pick and choose from a variety of factors: - executives may not have a realistic understanding of how difficult attack mitigation is so they don’t allocate the resources for hiring - incompetent admins overestimating their abi…

An organization running original software on the internet first needs to be preventing vulnerabilities in its own codebase. Nothing “admins” do is going to help much if the application itself is full of SQL injection and direct object reference. You can have impeccable configuration, firewalls, etc. and not even be playing the game.

Absolutely. Apologies if I indicated my list were the only possible issues at play.

Re: Quora User Data Compromised

#187
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

LastPass is not helping you with privacy here. From their tos tos: > You may use our Services only as permitted in these Terms, and you consent to our Privacy Policy at https://www.logmeininc.com/legal/privacy , which is incorporated by reference. pp: > When you use our Services, we receive information generated through the use of the Service, either entered by you or others who use the Services with you (for example…

Yow, that is precisely the last thing you want from a company whose job it is to store passwords. Thanks for the heads up.

Re: Quora User Data Compromised

#188
post #152
post #132

Earlier quoted context omitted.

It hasn't changed for either one, sadly. [1] [2] [1]: https://www.bankofamerica.com/privacy/accounts-cards/shopsaf... [2]: http://www.citibank.com/transactionservices/home/card_soluti...

virtual card #s is a great system, why did it rot? I assume it's because the whole industry prefers data-brokering your purchase history, joined on credit-card # to establish identity.

That's one good reason, another is probably pushback from merchants. Having these virtual cards completely shuts down the "free-trial-we-hope-you'll-forget-and-let-us-ding-you-for-a-month-or-two" business model that's so popular for online services.

Re: Quora User Data Compromised

#189
post #65

Earlier quoted context omitted.

It’s a whole lot of things, but first and foremost and probably the simplest explanation, security is hard. Incredibly hard. Once you understand how difficult attack mitigation is, then you can pick and choose from a variety of factors: - executives may not have a realistic understanding of how difficult attack mitigation is so they don’t allocate the resources for hiring - incompetent admins overestimating their abi…

An organization running original software on the internet first needs to be preventing vulnerabilities in its own codebase. Nothing “admins” do is going to help much if the application itself is full of SQL injection and direct object reference. You can have impeccable configuration, firewalls, etc. and not even be playing the game.

WAF

Re: Quora User Data Compromised

#190
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

+1 for bitwarden. Not a security professional, but it seems to be a good tradeoff between security and usability. Definitely better than lastpass on both counts.
Post reply on HN