Live data from Hacker News

The Dropbox hack is real

troyhunt.com

321–330 of 557 posts

Re: The Dropbox hack is real

#321
post #246
post #40

Earlier quoted context omitted.

I cannot agree more, I do the same, and invite everyone else to do so. - Useful as a canary of which website has been breached - Useful as a canary of which website sold your details - and if your details are in the wild, you can stop the spam by deleting the address Credit cards should work the same way: a unique authorization code specific to this vendor or this transaction and useless to any other actor.

"a unique authorization code specific to this vendor or this transaction and useless to any other actor" Sounds a lot like a bitcoin address.

...except not traceable, works with people's payment systems, sends actual US dollars, and doesn't have a 5% chance of getting stolen.

Re: The Dropbox hack is real

#322
post #280
post #274

Earlier quoted context omitted.

Indeed. I would really love to recommend Keepass, but their website is really ugly and makes the impression of a non-polished software - even though Keepass is absolute mature and fine. On the other hand, the PuTTY website is also everything but polished, but people have always been using it. Also, I suspect that most people will get it through the third-party site "www.putty.org" instead of the real PuTTY website, w…

> their website is really ugly I don't think it's ugly -- just dated. Isn't it weird that mentally we trust software less if they have a dated website? Shouldn't it be the opposite? (As in: a dated website means this software is mature and tested?)

It could also mean the software is abandoned and hasn't received security updates in a long time.

Re: The Dropbox hack is real

#323
post #309

Earlier quoted context omitted.

1Password is well worth the money. It is well designed for both desktop and mobile and I am happy to pay for software that I use every day.

It absolutely blows my mind that people are okay with giving their passwords (encrypted or not, see this very breach for why that's not always enough) to a 3rd party, but are not okay reusing a password somewhere. If 1Password ever got owned, the Internet would be severely fucked. And to stem the potential flood a bit, I realize there are plenty of good counterargument built up over the years to try and combat this g…

Using a strong key and cipher, you should feel safe giving anyone your information.

Re: The Dropbox hack is real

#324
It never ceases to amaze me how people have bought into "cloud" computing. Its hard enough to protect your own data, on your own secure machine. Once you entrust your data to a third party you should have absolutely no doubt that it is at risk. The larger the organization that that third party is, the more inherently insecure it is. In the cloud, it only takes one careless, stupid, or inept person to expose the data of thousands (or millions). And you can't fix stupid.

No thanks, I'll keep control over my own data.

Re: The Dropbox hack is real

#325
post #274

Earlier quoted context omitted.

the website is so poorly designed, it leads to consumer-non-adoptability.

Indeed. I would really love to recommend Keepass, but their website is really ugly and makes the impression of a non-polished software - even though Keepass is absolute mature and fine. On the other hand, the PuTTY website is also everything but polished, but people have always been using it. Also, I suspect that most people will get it through the third-party site "www.putty.org" instead of the real PuTTY website, w…

Heh, it doesn't even look half bad if you drop the bettermotherfuckingwebsite css on it.

Re: The Dropbox hack is real

#326
post #263
post #76

Earlier quoted context omitted.

For credit cards, check out privacy.com I recently started using it, works great.

Wondering how this works. If one is using different number per transaction where they are getting so many free numbers?

Reading their footer, it says: "The Privacy Visa Card is issued by Customers Bank pursuant to a license from Visa U.S.A. Inc."

So, it seems they have some kind of partnership with a bank, which is able to generate unlimited card numbers for them.

Re: The Dropbox hack is real

#327
post #26

It was pretty obvious the dropbox hack was real several years ago, because lots of spam mail started arriving at my dropbox-unique email almost immediately after the breach. I changed my email to another unique address quickly back then. Unique-per-service email addresses work pretty well as a canary for breaches. Just make sure there is more uniqueness than just the service name to such addresses, or someone could s…

> On a side note, don't forget the time dropbox accepted ANY password during logins - http://www.cnet.com/news/dropbox-confirms-security-glitch-no...

I've not forgotten, and this glitch has kept me from ever considering opening a Dropbox account.

I'm surprised everyone else seems so forgiving of this massive screw up.

Re: The Dropbox hack is real

#328

Earlier quoted context omitted.

Is there a service (email host) that can give you "infinite email aliases"? (Yes, I know about the '+' in gmail, but I suspect the word is out on it)

I use Google Apps for Work on my domain, which lets me forward all email to any address on that domain to my inbox. That way I can use adobe@ryanplant.net, github@ryanplant.net, fitbit@ryanplant.net, etc.

I do this exact same trick and have been using it for years. It led to a couple of brief and somewhat awkward phone calls with local business owners when I asked them rather pointedly about them sharing my information with third parties.

I also take this one step further and have inbox rules to automatically send all promotional email (from sites I'm interested in) to the trash folder. If I want a coupon for a website I frequent, I'll just search my trash for the latest offers from that company. Google conveniently purges messages from the trash folder every 30 days or so, and I don't have to worry about a massive backlog of promos.

Re: The Dropbox hack is real

#329
post #310

Great read. He goes on to say that 1Password has a subscription now and that you should signup for it. No. I will never, ever put all my passwords into a cloud based password store. I simply do not trust them to not fuck it up at one point in time. Am I alone with this view?

1Password is not cloud based...

https://1password.com/privacy/

For some products, they are.

"Your vaults, items, and documents are fully encrypted in your 1Password Families and 1Password Teams and stored on our servers."

Re: The Dropbox hack is real

#330
post #76

Earlier quoted context omitted.

For credit cards, check out privacy.com I recently started using it, works great.

This looks pretty cool, but seems like they are invite-only for now... Any chance you can drop an invite for a fellow HNer? :)

I found an early access code on their twitter: "NETTED". They posted that 1st August, so I'm not sure if it still works, but give it a shot!
Post reply on HN