Live data from Hacker News

Quora User Data Compromised

blog.quora.com

351–360 of 525 posts

Re: Quora User Data Compromised

#351

Earlier quoted context omitted.

LastPass is one of my least liked most used tools. Everything about the implentation feels second rate; slow, unreliable login capture, unreliable form fill, occasional inability to edit records, buried password copy, clunky UI, inappropriate modal nagging in browser and app... Most times I use it I am cursing it. I tried to switch to pass, and I'm not sure if it was something to do with how I imported but it didn't…

I have the same disappointing experience with LastPass and have grown tired of it. One of these days I will do something about it!

Check out Keepass! Rather than syncing directly into a Cloud, it allows you to store a database file into any location. It supports MFA (e.g. by combining a password with a secret file, or a Yubikey). And everything is open-source.

I like the model a lot, because it solves the "database ownership" issue, where your Password provider (be it LastPass, 1Password, etc) becomes in itself a weak link.

Re: Quora User Data Compromised

#352

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

Annoying as it is, it’s better than sensitive data in cleartext email attachments.

No, it is not. My email account is - obviously to say 'secure' as a binary proposition is inappropriate, but about as secure as anything on the Internet ever gets for most people. Training people to click an email link and type their password into the resulting page, by contrast, basically throws the entire concept of security out the window.

Re: Quora User Data Compromised

#353
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

I migrated over from Lastpass to Dashlane a few years ago. Couldn't be happier. It integrates with everything and as far as I understand their encryption is better than Lastpass, although I couldn't say how.

Re: Quora User Data Compromised

#354

Earlier quoted context omitted.

I worked at Quora, but left before this change was made, but I believe it was totally retroactive, mainly because I got emails with information about my previous anonymous answers and a deadline to get the one-time link. Now... if the emails were logged and in the exploited database, then all bets are off, but there's no indication that happened at all. There are about a hundred other things about this that give me a…

>given Quora's tenure (almost nine years!) that this is the first breach is pretty amazing I am sorry but this is #ShitHackerNewsSays worthy. Let me fix it for you >given Equifax's tenure (almost 119 years! Since 1899) that this is the first breach is pretty amazing Better now? Downvote me if you want, but there are no pats in the back for having PII leaks, no matter the years.

There have been at least 5 different breaches (of varying impact) at Equifax in the recent past several years. (https://en.wikipedia.org/wiki/Equifax)

Another set of 5 data breaches at Equifax dating back to 2013 (some but not all of these overlap with the Wikipedia reference) (https://www.forbes.com/sites/thomasbrewster/2017/09/08/equif...)

I would not be surprised if Equifax has been "breached" more than a hundred times over its history. Do your research.

Re: Quora User Data Compromised

#355

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

Just last week I wanted to look up how much I bought some appliance for, five years ago. In the e-mail I see a link that is supposed to let me download the invoice... which of course no longer works because they have updated their ordering/billing system.

Re: Quora User Data Compromised

#356

In 2013 a quora moderator contacted me and demanded that I provide my real name, and information that my name is real or they would ban my account. I tried reasoning with them, that I just wanted to view content and did not attend to write answers or interact etc, plus, they had a valid email address and facebook profile (also fake name on facebook). They fought back "we actually want proof of your real name like a s…

How did they know? Was your name obviously fake? My favorite feature of DuckDuckGo is that if you search "random name", it will actually generate a random name (e.g. "Marlon Lonzo"). So I use these random unique names on all websites that require one.

Re: Quora User Data Compromised

#357
The game of large numbers: so hackers obtain a million passwords. How with they decide to waste their time on any of them? In Quora's case that requires real identities and institutional affiliations will they go after the cream of the crop then?

Re: Quora User Data Compromised

#358
post #266

https://blog.quora.com/Quora-Security-Update seems to be misleading, especially the introduction. They start with 'some user data was compromised', however, it seems that for 'approximately 100 million Quora users' – that's basically all users! – all user data was compromised … In addition, many questions remain open, for example: Which ' leading digital forensics and security firm' is working for Quora? I hope for Q…

There can only be one digital forensics and security firm in the lead, right? All of the other firms are trailing...

Re: Quora User Data Compromised

#360

Earlier quoted context omitted.

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

I would like to recommend keepass. It's open source as well.

Yep, I use KeePass synced over my selfhosted nginx server. But you can use Dropbox/Google Drive/etc. just as easily.

I would like to also recommend the Firefox extension 'Kee' for autofill. On Android there is the 'Keepass2Android' app. Both are open source and work well.

I also recommend the KeePass plugin 'Yet Another Favicon Downloader'. It downloads favicons from websites for your password entries.

Also 'Keebuntu' is a plugin that makes 'minimize to tray icon' work for me on Linux.

Post reply on HN