Earlier quoted context omitted.
> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…
How do you guys do this? IS there a service? Do you add na.melast@gmail Or do you create them on your own domain through the hosting company?
The Dropbox hack is real
301–310 of 557 posts
Re: The Dropbox hack is real
#302Earlier quoted context omitted.
Doesn't that defeat the purpose? Surely anyone savvy enough to be dealing in black-market e-mail address lists is savvy enough to just remove everything after the + sign?
You never use the bare address. If it gets stripped then it gets binned.
Re: The Dropbox hack is real
#303Earlier quoted context omitted.
How do you guys do this? IS there a service? Do you add na.melast@gmail Or do you create them on your own domain through the hosting company?
I have a wildcard redirect so that @mydomain.com is forwarded to me. That way whenever I sign up for a service I just use, e.g., dropbox@mydomain.com.
Re: The Dropbox hack is real
#304Earlier quoted context omitted.
> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…
How do you guys do this? IS there a service? Do you add na.melast@gmail Or do you create them on your own domain through the hosting company?
Re: The Dropbox hack is real
#305Earlier quoted context omitted.
How do you guys do this? IS there a service? Do you add na.melast@gmail Or do you create them on your own domain through the hosting company?
You can use anything after a + character with Gmail. E.g. myaddress+service1@gmail.com will go to your inbox and you can filter on it.
"I can't log in and to boot your site says there is no account matching first.last@gmail.com. What kind of Mickey Mouse operation are you running here?"
"Sir, you are an idiot."
Re: The Dropbox hack is real
#306It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could s…
> Unique-per-service email addresses work pretty well as a canary for breaches I do this too, but it taught me everything is breached - the local ambulance service, the local computer store, the local car share, small businesses overseas that I've placed orders with. Some of the big names don't seem to be, which is lucky because otherwise I'd be wondering if it was the ISPs that had been breached. Either large chunks…
I also have expiring subdomains. So I'm not using domain.com, but something like b2.domain.com. The rationale is that if I start receiving a lot of spam, I go through all the accounts I have, change all emails to use another subdomain like b3.domain.com, and then invalidate the old subdomain entirely. I haven't had to do that yet and my domain is several years old.
With two big exceptions: the email address I leave on my website and the email address I publish on my GitHub profile. These 2 have dedicated throwaway domains like throwaway283728@domain.com. Because you wouldn't believe how much spam I get from that GitHub profile, not just recruiters, but also get rich offers from princes in Nigeria and Viagra pills.
Re: The Dropbox hack is real
#307> As for Dropbox, they seem to have handled this really well. I'm biased, but I can't agree with this. From what I can tell, there are two communications from Dropbox -- one in 2012 [1] and one last week [2]. In 2012 they did not disclose that hashes were stolen, so I don't see how it's really relevant. In the latest communication, they don't actually explain the risk to the user. They say it is "purely as a preventa…
"We’re reaching out to let you know that if you haven’t updated your Dropbox password since mid-2012, you’ll be prompted to update it the next time you sign in. This is purely a preventative measure, and we’re sorry for the inconvenience.
To learn more about why we’re taking this precaution, please visit this page on our Help Center. If you have any questions, feel free to contact us at password-reset-help@dropbox.com"
Re: The Dropbox hack is real
#308Make sure you sign yourself up for something like https://haveibeenpwned.com if you haven't already. Sometimes being timely in responding to leaks can make a big difference on any further leaks.
Re: The Dropbox hack is real
#309> 1Password now has a subscription service for $3 a month and you get the first 6 months for free. Don't pay for this people. Use the open source password manager Keepass http://keepass.info/
1Password is well worth the money. It is well designed for both desktop and mobile and I am happy to pay for software that I use every day.
If 1Password ever got owned, the Internet would be severely fucked.
And to stem the potential flood a bit, I realize there are plenty of good counterargument built up over the years to try and combat this general idea, but fundamentally the concept of giving your password to someone else to manage is still a confounding idea, regardless of whatever points those arguments make.
Re: The Dropbox hack is real
#310Great read. He goes on to say that 1Password has a subscription now and that you should signup for it. No. I will never, ever put all my passwords into a cloud based password store. I simply do not trust them to not fuck it up at one point in time. Am I alone with this view?