At this point I am operating on the assumption that ALL businesses that have my data are going to inadvertently leak it at some point, and thus I am attemtping to provide individual companies with as little information about me as possible. The toughest ones here are my online banking and my online health portal, but other than that, I have gotten pretty picky about what information I give any company.
I have an email address that I've only ever used as my AWS account email since many years ago. Somehow I started getting spam on it last year. It is not an address anyone could guess or somehow generate based on other data points such as name or otherwise.
Quora User Data Compromised
31–40 of 525 posts
Re: Quora User Data Compromised
#32> encrypted password I hope they mean hashed, not encrypted.
Did a double take at this too, but they clarified that it means “hashed with a unique salt” later on. Not a good word choice for a summary though!
Re: Quora User Data Compromised
#33Re: Quora User Data Compromised
#34Wow. If this had happened a couple years ago, before they made all the anonymous entries truly anonymous, this would have been really ugly. It's a valuable lesson in "don't keep data you don't need". EDIT: A little backstory for non-Quorans. Until early 2017, anonymous Quora answers and comments were anonymous to the public but not actually anonymous in the database (they were still "your" entries). In early 2017 the…
No, the lesson is: "don't give companies data they don't need".
Both are valid lessons. One is from the businesses perspective and one is from the user's perspective.
Re: Quora User Data Compromised
#35Wow. If this had happened a couple years ago, before they made all the anonymous entries truly anonymous, this would have been really ugly. It's a valuable lesson in "don't keep data you don't need". EDIT: A little backstory for non-Quorans. Until early 2017, anonymous Quora answers and comments were anonymous to the public but not actually anonymous in the database (they were still "your" entries). In early 2017 the…
Their doc says: > Is content posted anonymously still secure? > Yes. Anonymous content cannot be connected to user accounts, so content posted anonymously is still secure. https://help.quora.com/hc/en-us/articles/360020212652
Re: Quora User Data Compromised
#36> encrypted password I hope they mean hashed, not encrypted.
Did a double take at this too, but they clarified that it means “hashed with a unique salt” later on. Not a good word choice for a summary though!
Re: Quora User Data Compromised
#371. Force everyone to register to get access to content. 2. Leak that data. 3. ... 4. Profit. Not sure how this part works though. I hope lesson should be learned: don't force users to register just because you can
Re: Quora User Data Compromised
#38So I'm not a security expert, so I ask this in real earnest to learn: what is it that these companies keep doing wrong, and/or why aren't they adjusting to the climate that these types of attacks are increasing over time? Or are they trying to adjust, and the attacks are getting so sophisticated that the pace of investment in counter-measures is below that of the pace of advancement in the complexity of attacks? Or s…
Re: Quora User Data Compromised
#39So I'm not a security expert, so I ask this in real earnest to learn: what is it that these companies keep doing wrong, and/or why aren't they adjusting to the climate that these types of attacks are increasing over time? Or are they trying to adjust, and the attacks are getting so sophisticated that the pace of investment in counter-measures is below that of the pace of advancement in the complexity of attacks? Or s…
Of course, this model assumes that as soon as you have penetrated the perimeter, the rest becomes easy. This is the more traditional model. People are increasingly adopting a you-are-already-hacked approach, which makes it harder to move laterally once someone gets in. However, the general challenge still applies.
Re: Quora User Data Compromised
#40At this point I am operating on the assumption that ALL businesses that have my data are going to inadvertently leak it at some point, and thus I am attemtping to provide individual companies with as little information about me as possible. The toughest ones here are my online banking and my online health portal, but other than that, I have gotten pretty picky about what information I give any company.