Live data from Hacker News

Quora User Data Compromised

blog.quora.com

281–290 of 525 posts

Re: Quora User Data Compromised

#282

How were the passwords hashed? Wait. You know what? At this point it doesn’t matter. Using the same password everywhere is a broken concept and password managers are still unadopted. At this point the only solution is either SSO from a few point of trust (facebook, google, twitter, etc.) or/and password managing+generation by default (safari, iOS)

> At this point the only solution is either SSO from a few point of trust (facebook, google, twitter, etc.) No, that's what made OpenID awful. Your accounts all go down if one those "points of trust" get taken down for whatever (or no) reason.

It does suck. What I’m saying is that security for the people is not getting much better than that atm.

Re: Quora User Data Compromised

#283
post #149

Earlier quoted context omitted.

Was the water company thankful enough to compensate you for the $X,000 consulting services you provided because they didn't set up their own security monitoring?

Given their lack of security, I’m guessing they have no idea of the value that I provided. It’s all good though. Knowing I helped thousands of my neighbors is compensation enough. Besides, if they gave me a credit, they’d have to hike everyone’s bill to compensate!

Or give a smaller bonus to their head of security.

I know I'm a cynic, but it takes all sorts of people.

Re: Quora User Data Compromised

#284

At this point I am operating on the assumption that ALL businesses that have my data are going to inadvertently leak it at some point, and thus I am attemtping to provide individual companies with as little information about me as possible. The toughest ones here are my online banking and my online health portal, but other than that, I have gotten pretty picky about what information I give any company.

This mindset reminds me of the following "laws": Anything that can go wrong, will go wrong [0]. Anything that's isn't disallowed by quantum mechanics, will eventually happen [1]. So, if businesses made it cryptographically impossible to leak data, maybe it wouldn't happen, assuming it is even possible to make it impossible... [0] https://en.wikiquote.org/wiki/Murphy%27s_law [1] https://en.wikipedia.org/wiki/Totalitar…

Anything can go wrong, will go wrong in the worst possible moment (Sod's law).

Re: Quora User Data Compromised

#285
post #210

Earlier quoted context omitted.

Same. All my passwords are 100+ characters via LastPass. Except the ones the have to be only 12 :(

Nice. Hows that occasional instance where you need to type your 100 character password into Netflix on a Smart TV?

Haven't had to do that yet. My uh-oh case is VR. I just typed 5 chars at a time in the headset and then looked at my phone. The occasional cost is worth it though, only adding ~30 seconds

Re: Quora User Data Compromised

#286

> ...there’s little hope of sharing and growing the world’s knowledge if those doing so ... cannot trust that their information will remain private. Here's a crazy idea, circa 1990's: don't store their personal information! Allow people to browse Quora without using their real names. I'm very happy I deleted my Quora account when I did.

So you're under the impression Quota actually deletes all information related to your account when you click on delete? I'd be surprised.

Re: Quora User Data Compromised

#287
In 2013 a quora moderator contacted me and demanded that I provide my real name, and information that my name is real or they would ban my account. I tried reasoning with them, that I just wanted to view content and did not attend to write answers or interact etc, plus, they had a valid email address and facebook profile (also fake name on facebook). They fought back "we actually want proof of your real name like a scan of ID". I danced around and did not end up giving them a scan of my id, but I changed it to my real name.

Today my information is probably leaked. Information I didn't want to give and that they threatened me for it.

Where is the apology Quora? From all the recent leaks this is the one that pisses me off the most, because it's the one that was forced unto me.

Re: Quora User Data Compromised

#289
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

I use 1password regularly, tried bitwarden, found it lacking in various quality of life features & polish that 1p has, so I didn't migrate.

This is kind of yikes for a password manager too: https://github.com/bitwarden/core/issues/399

But it's also pretty much the only polished open source password manager there is out there.

For now I'll be sticking with 1password, but might check out bitwarden again once they have tests and more maturity as a password manager.

Re: Quora User Data Compromised

#290
post #245

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

I got an email that included “personalization data” in the list of data types that were stolen. The help page also says that information on “actions” was stolen. Does this mean that every question or answer I’ve viewed is now in the hands of the attacker?

Very likely. They had really poor privacy practices. At one point, a 'feature' was displaying in a sidebar who all were looking at a given question. Great for people looking for resources on gay rights, domestic violence etc. /s
Post reply on HN