Live data from Hacker News

Quora User Data Compromised

blog.quora.com

271–280 of 525 posts

Re: Quora User Data Compromised

#271
How were the passwords hashed? Wait. You know what? At this point it doesn’t matter. Using the same password everywhere is a broken concept and password managers are still unadopted. At this point the only solution is either SSO from a few point of trust (facebook, google, twitter, etc.) or/and password managing+generation by default (safari, iOS)

Re: Quora User Data Compromised

#272
post #91

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

[deleted]

Re: Quora User Data Compromised

#273
I think at this point it should be standard practice to say what hashing algorithm is used in passwords when disclosing a breach.

The email I got from quota just says “encrypted” passwords, and while the blog post says “hashed”, it doesn’t say what algorithm. For all we know it could be something useless like MD5

Re: Quora User Data Compromised

#274

How were the passwords hashed? Wait. You know what? At this point it doesn’t matter. Using the same password everywhere is a broken concept and password managers are still unadopted. At this point the only solution is either SSO from a few point of trust (facebook, google, twitter, etc.) or/and password managing+generation by default (safari, iOS)

> At this point the only solution is either SSO from a few point of trust (facebook, google, twitter, etc.)

No, that's what made OpenID awful. Your accounts all go down if one those "points of trust" get taken down for whatever (or no) reason.

Re: Quora User Data Compromised

#275

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

Use a social login. If you for example use gmail for email, then it makes no sense to create a password as opposed to just logging in with your google account instead.

Re: Quora User Data Compromised

#276
post #239

Earlier quoted context omitted.

What bank/card allows you to create unique credit cards with separate limits? The one I was using (Swedbank/visa/mastercard) stopped providing this service last year.

Privacy.com allows you to create virtual credit cards once you connect a source of payment to your account. Can be bank or debit card. I personally create one credit card for every paid subscription I have with the limit set on the amount that's supposed to be debited (eg. Monthly limit on Tidal charging $20). Privacy is a game changer for online transaction security imo. An additional benefit is the ability to subsc…

Privacy.com is US only though.

Re: Quora User Data Compromised

#277
post #148

Earlier quoted context omitted.

Companies hate users who don't want to sign up. They do not want that relationship. So it's a win-win if you dont' sign up. Why would companies feel obligated to generate content for free? If their systems get hacked and they have your snail mail address, they get your snail mail address as well. Email doesn't change that story.

Quora is all user-generated content that they monetize. They actually pay users to post questions (but not answers).

Is that why question quality is so low there?

Re: Quora User Data Compromised

#278

Earlier quoted context omitted.

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

Hmmm, I have been using the Keepass + Dropbox combo. Wanted to change to a more streamlined experience. The current choices of 1Password, LastPass and Dashlane didn't seem to attract me. I will give Bitwarden a try.

This is what I do too. Biggest complaint is the lack of official apps for mobile devices. I’ve used MiniKeePass in the past but am hesitant because there doesn’t seem to be much active development and I don’t see the source code anywhere.

Do you access kbdx files on mobile devices? If so, what do you use?

Re: Quora User Data Compromised

#279

Earlier quoted context omitted.

Annoying as it is, it’s better than sensitive data in cleartext email attachments.

Email can be encrypted. Besides that most of the time these very same services have (broken) password reset processes that rely on that email address anyway so the security improvement is nil in practice.

No medical practice, HOA, etc. is ever going to ask its patrons to fiddle around with PGP. The receptionist is not going to ask my grandmother for her public key before her hip replacement. Email functionally cannot be encrypted unless all parties to the conversation are in a tiny cohort of computer enthusiasts.

Password reset is a noisy, active attack compared to eavesdropping somewhere in the path of an email.

Re: Quora User Data Compromised

#280
post #31

Earlier quoted context omitted.

Many of us who operate our own mail services use a unique email address for every web service we use. You'd be surprised how many of these unique email addresses I've received spam at (and have subsequently blackholed). I would estimate less than 50% of the associated services ever report a data breach event. I figure either there has been an unreported breach or, possibly more likely, the service sold their userlist…

You can do this with a gmail account too. If your email address is johnsmith@gmail.com...the following addresses all fwd to your main address John.smith@gmail.com Johnsmith+quora@gmail.com Johnsmith+equifax@gmail.com Etc...

I use domain.tld@subdomain.domain.tld combined with a catch-all address for that sub-domain. It gets around various email validation regexes that won't accept +.
Post reply on HN