Live data from Hacker News

Quora User Data Compromised

blog.quora.com

211–220 of 525 posts

Re: Quora User Data Compromised

#211

Earlier quoted context omitted.

Using a password manager (which I do) is a valid coping mechanism, but does not fix the root concern: for 90% of these cases, one shouldn't even need an account. I don't want personalization. I don't want some new identity to manage. I don't want a relationship with your service. I just want to browse the goddamned web! How did we get to this point where in order to use the Internet you have to sign up for all these…

How did we get to this point where in order to use the Internet you have to sign up for all these free accounts and generate all these ridiculous username/password combinations We stopped using sites built by amateurs in their spare time and demanded "beautiful user experiences" that we didn't pay anything for. That costs money, so people who wanted to solve that "pain" looked for business models that meant they coul…

https://www.quora.com/How-does-DuckDuckGo-show-me-the-ads-th...

This model doesn't seem bad, advertising without tracking.

Re: Quora User Data Compromised

#212

Earlier quoted context omitted.

It's not that hard to be as anonymous as you like on Quora. It's been a while since I contributed, because I got tired of their schizophrenic moderation, but I don't recall that mobile text authentication was necessary. Unlike say, Twitter. And even that isn't all that hard to get around, using hosted SIMs.

It's impossible for me to be as anonymous as I like on Quora, because they require a government ID with the name I want to use. Which isn't even that weird! It's my legal last name, plus my childhood nickname for a first name. Your name just didn't provoke their Real Name Gestapo.

Huh. Good to know, thanks.

Re: Quora User Data Compromised

#213
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

LastPass is not helping you with privacy here. From their tos tos: > You may use our Services only as permitted in these Terms, and you consent to our Privacy Policy at https://www.logmeininc.com/legal/privacy , which is incorporated by reference. pp: > When you use our Services, we receive information generated through the use of the Service, either entered by you or others who use the Services with you (for example…

That's so awful. Which password managers are not like that? I assume KeepassXC is good since its open source

Re: Quora User Data Compromised

#214

Earlier quoted context omitted.

It's not that hard to be as anonymous as you like on Quora. It's been a while since I contributed, because I got tired of their schizophrenic moderation, but I don't recall that mobile text authentication was necessary. Unlike say, Twitter. And even that isn't all that hard to get around, using hosted SIMs.

Can you elaborate on the hosted SIMs thing? More and more websites are starting to ask for SMS verification and blocking VOIP numbers like google voice and it is getting really annoying.

See https://www.wilderssecurity.com/threads/hosted-sims-for-priv...

Edit: I don't have any affiliate etc association with them.

Re: Quora User Data Compromised

#215
Seems like a complete database exfiltration. Quora advertisers also had info compromised from a separate email notice:

  - Account information available on the Ads Manager account settings page.
  - The email address provided for notifications about your ad campaigns.
  - Campaign structure and setup, including information like budgets, schedule, bids, targeting, and ad information.
  - Notifications that were in your Ads Manager, such as ad paused, logo approved, and ad ready.
  - Audience setup information available on the Ads Manager audience page such as types and creation date.
  - Partial credit card information, including name, expiration date, and the last four digits of the credit card.

Re: Quora User Data Compromised

#216
post #148

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

Companies hate users who don't want to sign up. They do not want that relationship. So it's a win-win if you dont' sign up. Why would companies feel obligated to generate content for free? If their systems get hacked and they have your snail mail address, they get your snail mail address as well. Email doesn't change that story.

Quora is all user-generated content that they monetize. They actually pay users to post questions (but not answers).

Re: Quora User Data Compromised

#217

So I'm not a security expert, so I ask this in real earnest to learn: what is it that these companies keep doing wrong, and/or why aren't they adjusting to the climate that these types of attacks are increasing over time? Or are they trying to adjust, and the attacks are getting so sophisticated that the pace of investment in counter-measures is below that of the pace of advancement in the complexity of attacks? Or s…

They aren't being incentiviced hard enough. Security costs money and can be inconvenient both for you and the users, which is not good for startups.

In addition to that, attackers only have to get lucky once, the defenders have to check every entryway.

Re: Quora User Data Compromised

#218
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

I have been using Pass [0] with passff [1] and been pretty happy about it. Simple and offline password management where passwords live in gpg encrypted files. Additional features I like are tracking changes with git, bash completion and copying passwords to clipboard for few seconds temporarily, and a few very useful extensions.

[0] https://www.passwordstore.org/ [1] https://github.com/passff/passff#readme

Re: Quora User Data Compromised

#219

Earlier quoted context omitted.

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

I moved from LastPass to 1Password recently. Had been using LastPass for several years, but filling failures, the lack of copy password in FF (and no binary workaround for Linux), and generally unhelpful support when I contacted them prompted me to move. Very happy with 1PasswordX (the browser-only version) - filling is much better, copy is supported out of the box, support have been very helpful when I've reached ou…

Do they support automatically adding/updating sites yet?
Post reply on HN