Live data from Hacker News

Quora User Data Compromised

blog.quora.com

291–300 of 525 posts

Re: Quora User Data Compromised

#291

Earlier quoted context omitted.

Quora is all user-generated content that they monetize. They actually pay users to post questions (but not answers).

Is that why question quality is so low there?

Yes. The strategy is to generate SEO for every possible question someone could ask on Google and then link it to Quora.

It had amazing content in the early days and still has great answers but the sheer number of nonsensical or slightly tweaked but endlessly repeated question is driving away writers. Paying people to post these questions is just backwards.

Re: Quora User Data Compromised

#292
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

I use keepassx, a local password manager. I don't trust centralized online password managers with browser extensions. Huge attack surface. I copy and paste usernames and passwords.

Same. Where do you keep the db file? Mine's in the cloud and I can't help but think it reduces security, but then I need access to this data from various locations.

Re: Quora User Data Compromised

#293

Earlier quoted context omitted.

They don’t have your passwords

They do store your "vault" on their server. It's encrypted though using key that doesn't leave your computer. However I can easily imagine deliberate as well as innocent "mistakes" in browser plugins and other weak links in architecture that would expose the master key and hence your vault.

That can pretty much happen to any software provider you download software from.

You don't have the time to:

- audit the source code

- check every auto-update hash matches the main hash list "just in case" you get a special update just for you

If you turn off auto-update, you will eventually get hacked because of bitrot

Re: Quora User Data Compromised

#294
post #210

Earlier quoted context omitted.

Same. All my passwords are 100+ characters via LastPass. Except the ones the have to be only 12 :(

Nice. Hows that occasional instance where you need to type your 100 character password into Netflix on a Smart TV?

I use an apple tv, so I can paste it from the mobile app on my iPhone. iOS 12 password manager integration might work too!

Re: Quora User Data Compromised

#295
post #191

Earlier quoted context omitted.

Wouldn't the bank still know your full purchase history (since they know what numbers are tied to you)? So they'd in fact get a leg up on the competition, who get a more distorted view?

But they don’t get the invoices of what you bought, just the total payment amount.

Unless they work with an analytics system that mastercard, visa & amex participate in to link card numbers to invoices for better advertising & affiliate data.

I know FB & Google purchase something like that from one or two credit card companies, so I wouldn't be surprised if merchants were in to it too.

Re: Quora User Data Compromised

#296
post #240

Earlier quoted context omitted.

Nice. Hows that occasional instance where you need to type your 100 character password into Netflix on a Smart TV?

Given the shady things people have found their smart TVs doing, I'd feel about as safe typing a password into a smart TV as I would changing the password to "hunter2". The TV should display (or maybe email) a link that I would visit with my primary web browser and grant it permissions - or ask for a password as a very last resort for users who have no computer/phone but somehow have Netflix.

The bbc iPlayer does essentially this now. It creates a short one time code and you type it into a logged in account to activate the smart device.

Of course, when you only have one logged in device and it's tied to a different room, it's mildly irritating, but you only do it once.

Re: Quora User Data Compromised

#297

Earlier quoted context omitted.

Retroactively, right?

I worked at Quora, but left before this change was made, but I believe it was totally retroactive, mainly because I got emails with information about my previous anonymous answers and a deadline to get the one-time link. Now... if the emails were logged and in the exploited database, then all bets are off, but there's no indication that happened at all. There are about a hundred other things about this that give me a…

>given Quora's tenure (almost nine years!) that this is the first breach is pretty amazing

I am sorry but this is #ShitHackerNewsSays worthy. Let me fix it for you

>given Equifax's tenure (almost 119 years! Since 1899) that this is the first breach is pretty amazing

Better now? Downvote me if you want, but there are no pats in the back for having PII leaks, no matter the years.

Re: Quora User Data Compromised

#298
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

I would like to recommend keepass. It's open source as well.

Re: Quora User Data Compromised

#299

In 2013 a quora moderator contacted me and demanded that I provide my real name, and information that my name is real or they would ban my account. I tried reasoning with them, that I just wanted to view content and did not attend to write answers or interact etc, plus, they had a valid email address and facebook profile (also fake name on facebook). They fought back "we actually want proof of your real name like a s…

Haha I never give it to them as well. Never put your real name, no matter what. They are ridiculous with these requirements. I'm waiting until the day they'll make a credit check to open an account
Post reply on HN