Live data from Hacker News

Quora User Data Compromised

blog.quora.com

221–230 of 525 posts

Re: Quora User Data Compromised

#221
post #65

So I'm not a security expert, so I ask this in real earnest to learn: what is it that these companies keep doing wrong, and/or why aren't they adjusting to the climate that these types of attacks are increasing over time? Or are they trying to adjust, and the attacks are getting so sophisticated that the pace of investment in counter-measures is below that of the pace of advancement in the complexity of attacks? Or s…

It’s a whole lot of things, but first and foremost and probably the simplest explanation, security is hard. Incredibly hard. Once you understand how difficult attack mitigation is, then you can pick and choose from a variety of factors: - executives may not have a realistic understanding of how difficult attack mitigation is so they don’t allocate the resources for hiring - incompetent admins overestimating their abi…

Security is not too difficult on a decent network. There are several that meet Federal requirements. The problem is that the Web design was leaky in the first place. The companies that specified it wanted free flowing data above all else with authenication behind the firewall. But the W3c browser is not secure. Tim's comments notwithstanding, this occurred on his watch. We're due for a serious network, not another toy.

Re: Quora User Data Compromised

#222

Barely a month back in the facebook data breach thread in HN, I was downvoted and my comment removed when I said that it has become a fashion for the top 500 web/e-com companies to come one day and announce data breach and walk away. I said there that it all looks to me as part of a conspiracy theory where they hide behind a breach to sell data/ buy data en masse for marketing purposes.

Selling the data outright is not worth anything. Public identities can be scrapped and bought very easily already. Most companies with personal and contextual data like this sell access to it, usually in the form of ads.

Re: Quora User Data Compromised

#224

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

This is an example where they decided their business model trumped user security. It’s hard to monetize an easy to access collection of free data. I hope we can find better ways to fund internet services than by consuming data from the users.

Re: Quora User Data Compromised

#225
Is there an email notifying all users of the incident and a separate email notifying those affected, or just one?

Many companies seem to use intentionally vague wording to suggest you might not have to worry.

Re: Quora User Data Compromised

#226
Quora is an absolute shit show. It won't allow you to read content on mobile web EVEN WHEN YOU ARE SIGNED IN! To top it they disallow any screenshots of the same! Check here https://pbs.twimg.com/media/Dc-9ldcU8AUr23v.jpg https://pbs.twimg.com/media/Dc-9ldbVAAALJfX.jpg

Even though I have been a heavy quora user (reader and contributor), I would be really happy if it died a really painful and stupid death

Re: Quora User Data Compromised

#227
post #226

Quora is an absolute shit show. It won't allow you to read content on mobile web EVEN WHEN YOU ARE SIGNED IN! To top it they disallow any screenshots of the same! Check here https://pbs.twimg.com/media/Dc-9ldcU8AUr23v.jpg https://pbs.twimg.com/media/Dc-9ldbVAAALJfX.jpg Even though I have been a heavy quora user (reader and contributor), I would be really happy if it died a really painful and stupid death

Zhihu (Chinese offshoot of Quora) does the exact same shit on mobile as a way to force users to download their app (which pushes a ton of ads plus other frills). Looks like they got their full playbook from Quora.

Re: Quora User Data Compromised

#228
post #225

Is there an email notifying all users of the incident and a separate email notifying those affected, or just one? Many companies seem to use intentionally vague wording to suggest you might not have to worry.

I too got one email and I'm not sure now if I'm affected (I got the same content as on the website in this email)

Re: Quora User Data Compromised

#229

Earlier quoted context omitted.

I moved from LastPass to 1Password recently. Had been using LastPass for several years, but filling failures, the lack of copy password in FF (and no binary workaround for Linux), and generally unhelpful support when I contacted them prompted me to move. Very happy with 1PasswordX (the browser-only version) - filling is much better, copy is supported out of the box, support have been very helpful when I've reached ou…

Do they support automatically adding/updating sites yet?

It will prompt you to do so.

Re: Quora User Data Compromised

#230
post #191
post #152

Earlier quoted context omitted.

virtual card #s is a great system, why did it rot? I assume it's because the whole industry prefers data-brokering your purchase history, joined on credit-card # to establish identity.

Wouldn't the bank still know your full purchase history (since they know what numbers are tied to you)? So they'd in fact get a leg up on the competition, who get a more distorted view?

But they don’t get the invoices of what you bought, just the total payment amount.
Post reply on HN