Live data from Hacker News

Quora User Data Compromised

blog.quora.com

261–270 of 525 posts

Re: Quora User Data Compromised

#261

Earlier quoted context omitted.

What makes you trust LastPass that they won't sell/leak/expose your passwords from some backdoor or under the table deal? I'm asking because this is not a public company or an entity that can be held responsible in any way for such an act. It's just another startup obligated to make their investors 10X returns. I haven't read their agreements but I'm pretty sure any lawyers of such companies have enough clause to abs…

They don’t have your passwords

They do store your "vault" on their server. It's encrypted though using key that doesn't leave your computer. However I can easily imagine deliberate as well as innocent "mistakes" in browser plugins and other weak links in architecture that would expose the master key and hence your vault.

Re: Quora User Data Compromised

#262

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

Quora does not only want you to sign in, they want you to show your real identity instead of a handle or another pseudonym. For a simple online service, it should never be necessary to use your real identity, if only as a privacy-enhancing measure.

Re: Quora User Data Compromised

#263
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

I looked over privacy.com - specifically their security page[0] which reads impressively. As I looked at my "dashboard" I couldn't help but notice (according to uBlock Origin) that privacy.com , ironically, connects to facebook (.net) and google (fonts, apis, gstatic). I'm certain none of those 3rd-party connections are necessary and yet... like muscle-memory... devs continue to thoughtlessly invite tracking. [0] htt…

I've seen people include such tags on the logged in areas for cancer patients in medical websites without batting an eye and wondering why that's a bad thing.

Re: Quora User Data Compromised

#264

"encrypted (hashed) passwords" Was it hashed AND encrypted or another case of people not understanding the difference?

Seems like "encrypted" is in there for laymen and "hashed" being a clarification for more technical people. In the post they say: "... the passwords were encrypted (hashed with a salt that varies for each user) ..."

Re: Quora User Data Compromised

#265

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

Annoying as it is, it’s better than sensitive data in cleartext email attachments.

Email can be encrypted. Besides that most of the time these very same services have (broken) password reset processes that rely on that email address anyway so the security improvement is nil in practice.

Re: Quora User Data Compromised

#266
https://blog.quora.com/Quora-Security-Update seems to be misleading, especially the introduction. They start with 'some user data was compromised', however, it seems that for 'approximately 100 million Quora users' – that's basically all users! – all user data was compromised …

In addition, many questions remain open, for example: Which ' leading digital forensics and security firm' is working for Quora?

I hope for Quora that they met their 72-hour deadline according to the GDPR. Looking at https://www.quora.com/about/privacy, it does not look if Quora was / is GDPR-ready. They do not mention any legal basis for the processing (art. 13 GDPR) and they do not inform about their GDPR data representative in the EU (art. 27 GDPR).

Re: Quora User Data Compromised

#267

"encrypted (hashed) passwords" Was it hashed AND encrypted or another case of people not understanding the difference?

Seems like "encrypted" is in there for laymen and "hashed" being a clarification for more technical people. In the post they say: "... the passwords were encrypted (hashed with a salt that varies for each user) ..."

In that case how laymen are ever going to learn if we use incorrect words to make them feel safer?

"Ah, they were ENCRYPTED so I don't have to worry"

The thruth is they are most likely already reversed.

Re: Quora User Data Compromised

#268
What's bad about Quora website is that, whenever you see Answer notification, when you click on it, instead of a popup for quick review, the website will go to new url for the answers. That's why i don't use Quora much these days due to the stupid UX.

Re: Quora User Data Compromised

#269
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

I can’t trust privacy.com. I refuse to give some company direct access to pull money from my bank. Only a matter of time until they’re breached too.

What about using a completely segregated secondary account? I have a Simple account, and that's all I use it. I only ever have a couple hundred in there at any time.

Re: Quora User Data Compromised

#270
post #262

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

Quora does not only want you to sign in, they want you to show your real identity instead of a handle or another pseudonym. For a simple online service, it should never be necessary to use your real identity, if only as a privacy-enhancing measure.

As a reminder: Last year, Quora moved to 'new anonymity', i.e., no more anonymity. I had received the following message on 16 March 2017:

Hello! We will be moving to the new anonymity on Quora experience very soon. If you would like to edit or delete your existing anonymous content in the future, please provide your email here before March 20, 2017. You are receiving this message because we have not yet received an email from you. Please note that if you do not provide your email by March 20, 2017, you will need to contact us using our Contact Form and selecting “I need help with my account.”

Post reply on HN