Live data from Hacker News

Quora User Data Compromised

blog.quora.com

331–340 of 525 posts

Re: Quora User Data Compromised

#331

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

Use a social login. If you for example use gmail for email, then it makes no sense to create a password as opposed to just logging in with your google account instead.

I always do that when possible because I am lazy and it works too damn fine, but it is a nightmare from a privacy point of view.

Re: Quora User Data Compromised

#333

Earlier quoted context omitted.

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

LastPass is one of my least liked most used tools. Everything about the implentation feels second rate; slow, unreliable login capture, unreliable form fill, occasional inability to edit records, buried password copy, clunky UI, inappropriate modal nagging in browser and app... Most times I use it I am cursing it. I tried to switch to pass, and I'm not sure if it was something to do with how I imported but it didn't…

I have the same disappointing experience with LastPass and have grown tired of it. One of these days I will do something about it!

Re: Quora User Data Compromised

#334

Earlier quoted context omitted.

LastPass is not helping you with privacy here. From their tos tos: > You may use our Services only as permitted in these Terms, and you consent to our Privacy Policy at https://www.logmeininc.com/legal/privacy , which is incorporated by reference. pp: > When you use our Services, we receive information generated through the use of the Service, either entered by you or others who use the Services with you (for example…

I haven't even tried to use these services, can someone please explain why centralizing all your online activity helps with privacy?

The traditional pitch from security experts is "Using a password manager is better than reusing the same password on lots of sites, or using low entropy passwords, or saving your passwords in an excel spreadsheet, which is what you were probably doing before"

Re: Quora User Data Compromised

#335
post #210
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

Same. All my passwords are 100+ characters via LastPass. Except the ones the have to be only 12 :(

That's excessive. Around 80 bits of entropy (16 alphanumericals) is sufficient, especially when using unique passwords for each service. See https://security.stackexchange.com/questions/6095/xkcd-936-s...

Re: Quora User Data Compromised

#336

Earlier quoted context omitted.

Do they support automatically adding/updating sites yet?

Not on page submit, but you can do it when the form is still visible before you submit.

My 1Password always prompts me after I submit a form if I want to save the credentials used in that form.

Re: Quora User Data Compromised

#337

Earlier quoted context omitted.

The sad things is that even if you received and apology, it would mean nothing, empty words repeated over and over and over.

Companies are not people and cannot have human attributes

Well, according to the US government, companies are in fact people for a wide variety of important purposes.

Re: Quora User Data Compromised

#338
post #292

Earlier quoted context omitted.

I use keepassx, a local password manager. I don't trust centralized online password managers with browser extensions. Huge attack surface. I copy and paste usernames and passwords.

Same. Where do you keep the db file? Mine's in the cloud and I can't help but think it reduces security, but then I need access to this data from various locations.

I worry about this too. I store the database itself in Dropbox, and I also use a keyfile alongside the password to open it. I can easily recreate the keyfile on any computer, but it never goes anywhere near the internet.

In addition to that, for my really critical "gatekeeper" accounts, I don't put the full password in the database. Just a reminder that this is a "special" password, which needs to be combined with another bit of info in order to work.

I just live with the fact that I can't use this system on my phone, and for my usage patterns, that's fine. There's nothing I need to do that's so urgent that it can't wait until I'm back in front of my computer.

Re: Quora User Data Compromised

#339
It's quite obvious that Quora doesn't care a lot about user data. Just for looking at the website, you need to login with Facebook and in fact other users could at some point even see which parts of the site you browse to without informing you. Kind of sucks, luckily deleted my account half a year ago.

Re: Quora User Data Compromised

#340

In 2013 a quora moderator contacted me and demanded that I provide my real name, and information that my name is real or they would ban my account. I tried reasoning with them, that I just wanted to view content and did not attend to write answers or interact etc, plus, they had a valid email address and facebook profile (also fake name on facebook). They fought back "we actually want proof of your real name like a s…

I got the same. And when I looked into it and found out the company was founded by former Facebook guys, I knew they couldn't be trusted and knew enough to jump ship.
Post reply on HN