Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

251–260 of 292 posts

Re: Notes on the Celebrity Data Theft

#251

Earlier quoted context omitted.

(disclaimer: not meaning to start any kind of flame-war) To be honest, the one I perceive (as a straight, white, middle-class, educated male) larger is the misandristic one. As a person who strives to be good and helpful to every human being equally, regardless of race, gender, orientation or whatever, I get everyday on the Internet and I get flooded by articles and comments saying that everything I do or think is mi…

> To be honest, the one I perceive (as a straight, white, middle-class, educated male) larger is the misandristic one. As a person who strives to be good and helpful to every human being equally, regardless of race, gender, orientation or whatever, I get everyday on the Internet and I get flooded by articles and comments saying that everything I do or think is misogynistic, wrong and overprivileged. This is just anot…

> Unless, of course, the things you are doing on the internet are wrong and misogynistic, in which case people are sending you articles and comments for a reason.

Fortunately no one sends me anything like that, they just end up in my news feed as I have many friends involved in feminism/minority movements, and because local media loves to spin everything as gender issues.

> Certainly if you are a man who doesn't do the things someone is complaining about, then you have nothing to worry about.

Well, even if one has nothing to worry about personally, it's just tiring and demotivating to see all those broad accusations all the time. sigh

Re: Notes on the Celebrity Data Theft

#252

Earlier quoted context omitted.

Looks like they still don't have a native Linux client though.

pass - http://www.passwordstore.org/

Well, my point was more that I do want a single password storage solution across the board. I use Linux, Windows, OSX, and Android regularly. I tried 1Password in the past but dropped it as it didn't have a Linux client. I now use KeePass as I can sync my DB across all my devices.

Re: Notes on the Celebrity Data Theft

#253
post #248
post #124

Earlier quoted context omitted.

That's more or less why I use LastPass. Same concept, only decrypts client-side, but is automatically preserved across machines and hardware failure.

I use Lastpass. I just logged in online and can see all my passwords so it doesn't seem terribly secure. I there was key-logging malware on my machine it could have got my master password and hence all my passwords off Lastpass. It seems handy for all the crap passwords but I would not want to rely on it for anything that lets people nick money. Unless I'm missing something...

LastPass uses your master password to decrypt your key store clientside. What's stored on their servers is an encrypted blob to which they don't have the key. It is an actual zero-knowledge system.

If there was key-logging software on your machine, you're pooched any way you slice it (since such malware can just snarf decrypted keystores out of memory anyhow). However, with LastPass you can use Google Authenticator or a Yubikey or similar to enforce second-factor logins, so that even if you have malware on your machine, there is a drastically-smaller window in which to attack you.

On the upside, you get phishing protection (LP won't fill passwords for sites that don't actually match the site that you've saved passwords against), password duplication detection and strength auditing, notifications of when your passwords may have been compromised by major breaches, secure transport of passwords to other people, and transparent synchronization across devices. It's quite good.

Re: Notes on the Celebrity Data Theft

#254
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

My problem is that 1Password et al are curing symptoms, not solving causes. Personal infosec hasn't evolved quick enough to match the technology it depends on. Sure we're comfortable with 12 character, 3 month rotation passwords, but the average 'civilian'? Probably doesn't even have a passcode on their phone despite the massive personal security risk they're carrying around with them. We need to educate and/or provi…

No, no I am not comfortable with 12 character, 3 month rotating passwords. 12 character, ok, but only if the damn thing isn't going to change all of the time. I have a hard enough time remembering my passwords for the computers at work that rotate every three months. You start making it necessary to do that for all of the sites I use on the Internet, and I'll lose access to pretty much every service. Not a workable solution! At least not without a password manager...

Re: Notes on the Celebrity Data Theft

#255
post #203

I'm wondering if simple GeoIP check can prevent lots of intrusion attempts - if the user consistently logs in from one location and then suddenly tries to log in with the wrong password from the distant one, that's the red flag that warrants temporary account lockout at least.

problem #1: GeoIP isn't accurate enough

problem #2: Travel becomes more of a pain because your apps/phone stop working.

Re: Notes on the Celebrity Data Theft

#256
post #80

Choice quote: To reiterate what the main bugs are that are being exploited here, roughly in order of popularity / effectiveness: Password reset (secret questions / answers) Phishing email Password recovery (email account hacked) Social engineering / RAT install / authentication keys Note: Not weak passwords.

Here's a question: How did the attacker get the usernames of the celebrities? Those aren't exactly public info (unless they used the same name as their Instagram account or something).

Re: Notes on the Celebrity Data Theft

#257

While I am complete appalled by the data breach and hope that similar things never happens to anyone again I would like to propose a purely thought experiment: The hacker reported sold the nude photos of Jennifer lawrence for a mere sum of $130 using bitcoin. If we apply game theory here, these kind of data is very difficult to monetize. If you sell one copy of the data, it is then immediately distributed online for…

While I don't actually have any solid grasp of the code that would be required, I imagine it would be possible to release 1 image to show that one does indeed have a collection of "valuable" photos. Once trust has been established that the person probably does indeed have additional photos, people will be more willing to submit bitcoin. You overwrite each pixel of each photo with black. You assign every photo a bitco…

That's an interesting twist on it; "unlocking" (unblocking) the pixel one at a time. Almost like a perverted Million Dollar Homepage of yesteryear.

Re: Notes on the Celebrity Data Theft

#258
post #195

Earlier quoted context omitted.

Turn of the DPI scaling in Windows. http://support.microsoft.com/kb/2900023 Google around for the actual steps.

I'd rather not do a fix like that; I want to notice if sites I code have the issue.

I agree, but until Google gets the fix in you can have no way of knowing what it will look like because it all depends on the hardware and how it has been scaled.

I only came across this because my daughter's new laptop with an HD screen made Chrome look awful and I didn't understand why since it looked good everywhere else.

Re: Notes on the Celebrity Data Theft

#259
post #230
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

Stupid question but what happens if you forget the master password or someone steals it?

>1Password creates your data file using the password you provided when you first launched the application. This password is not kept anywhere and it is never logged. Furthermore, there is no “back door” mechanism to recover your data or password. This approach is very important in order to be able to say that 1Password keeps your data safe and secure. However, because of it, once your password is forgotten, there is nothing we can do to help you recover it.

https://help.agilebits.com/1Password3/forgot_password.html

I have my master password written on a piece of paper that is stored in a safe location, mostly so my wife can access my information if anything ever happened to me, but it also works as a backup if I ever forget my master password for some reason.

Re: Notes on the Celebrity Data Theft

#260

While I am complete appalled by the data breach and hope that similar things never happens to anyone again I would like to propose a purely thought experiment: The hacker reported sold the nude photos of Jennifer lawrence for a mere sum of $130 using bitcoin. If we apply game theory here, these kind of data is very difficult to monetize. If you sell one copy of the data, it is then immediately distributed online for…

This is exactly what happened though. A BitCoin address was posted, and the leaker was taking "donations" with the promise of delivering more pictures, showing proof that he had more by showing partial screenshots of them.
Post reply on HN