Live data from Hacker News

Quora User Data Compromised

blog.quora.com

21–30 of 525 posts

Re: Quora User Data Compromised

#24
post #7

Interesting (to me, at least) that the regular Quora update emails land in my inbox (or in the Social tab in Gmail, anyway), but the security breach notification was spam filtered...

Well they probably sent a shit-ton of emails in a short timespan to notify most if not all users which could have triggered spam algorithms.

Re: Quora User Data Compromised

#25

At this point I am operating on the assumption that ALL businesses that have my data are going to inadvertently leak it at some point, and thus I am attemtping to provide individual companies with as little information about me as possible. The toughest ones here are my online banking and my online health portal, but other than that, I have gotten pretty picky about what information I give any company.

This mindset reminds me of the following "laws":

Anything that can go wrong, will go wrong [0]. Anything that's isn't disallowed by quantum mechanics, will eventually happen [1].

So, if businesses made it cryptographically impossible to leak data, maybe it wouldn't happen, assuming it is even possible to make it impossible...

[0] https://en.wikiquote.org/wiki/Murphy%27s_law

[1] https://en.wikipedia.org/wiki/Totalitarian_principle

Re: Quora User Data Compromised

#27

At this point I am operating on the assumption that ALL businesses that have my data are going to inadvertently leak it at some point, and thus I am attemtping to provide individual companies with as little information about me as possible. The toughest ones here are my online banking and my online health portal, but other than that, I have gotten pretty picky about what information I give any company.

This is a healthy mindset to have. I feel that for every company that self-reports a leak, there are multiple other companies that have leaked your data and either haven't discovered the breach, refuse to disclose it, or flat out sold your data to the highest bidder.

I’m even more worried about the ones that don’t have the facilities to even detect and know they’ve been breached.

Re: Quora User Data Compromised

#28

At this point I am operating on the assumption that ALL businesses that have my data are going to inadvertently leak it at some point, and thus I am attemtping to provide individual companies with as little information about me as possible. The toughest ones here are my online banking and my online health portal, but other than that, I have gotten pretty picky about what information I give any company.

This is a healthy mindset to have. I feel that for every company that self-reports a leak, there are multiple other companies that have leaked your data and either haven't discovered the breach, refuse to disclose it, or flat out sold your data to the highest bidder.

You would be correct. In the US, which I might remind you, does not have a national law on the books regarding data breach notification. Even at the state levels, it’s varies pretty wildly on top of, most notifications are only required if there is evidence. So here is the challenge: what if I keep no logs, and have terrible security monitoring capability? If I am notified or discover a critical vulnerability on my own, but have inadequate logs to show or detect if it was exploited... am I required to notify? I have been told no (I fervently disagreed; I think suspected breaches, or critical vulnerabilities which may lead to breaches but were inconclusive should still require notification).

Re: Quora User Data Compromised

#30
post #20

At this point I am operating on the assumption that ALL businesses that have my data are going to inadvertently leak it at some point, and thus I am attemtping to provide individual companies with as little information about me as possible. The toughest ones here are my online banking and my online health portal, but other than that, I have gotten pretty picky about what information I give any company.

I have an email address that I've only ever used as my AWS account email since many years ago. Somehow I started getting spam on it last year. It is not an address anyone could guess or somehow generate based on other data points such as name or otherwise.

I am using a separate email for each website, using the catch-all email feature.

It helped me find out a couple of local companies that are selling my data to spammers.

Post reply on HN