Live data from Hacker News

Quora User Data Compromised

blog.quora.com

371–380 of 525 posts

Re: Quora User Data Compromised

#372

Earlier quoted context omitted.

Using a password manager (which I do) is a valid coping mechanism, but does not fix the root concern: for 90% of these cases, one shouldn't even need an account. I don't want personalization. I don't want some new identity to manage. I don't want a relationship with your service. I just want to browse the goddamned web! How did we get to this point where in order to use the Internet you have to sign up for all these…

How did we get to this point where in order to use the Internet you have to sign up for all these free accounts and generate all these ridiculous username/password combinations We stopped using sites built by amateurs in their spare time and demanded "beautiful user experiences" that we didn't pay anything for. That costs money, so people who wanted to solve that "pain" looked for business models that meant they coul…

The web started to decline when we moved away from JQuery, and personal homepages. And when Google started to use brand name as a ranking factor.

Re: Quora User Data Compromised

#373
post #362

This is all bullshit. My data is all over the place. At this point I expect none of my personal data to be private. This last few weeks alone my data was stolen from British Airways, Cathay Pacific, SPG/Mariott, Quora. As users we are completely powerless. Time for change. Time for intelligent heads to come together and think of how a better internet security architecture needs to look like.

I wonder how easy it would be to piece together all these breaches with any degree of accuracy to build a "complete picture" of an individual. Say your name, email address and social get leaked in one 500m user dump and your email passport number and actual address in another. I've never worked with datasets on this scale hence the ignorance. Maybe its possible for one person of interest but how complicated would it…

I’ve oftened wondered if I am helped by my practice of using [servicename]@[mydomain.com] for each service I sign up for. I used to do it to help control and track spam, then I stopped when spam stopped becoming an issue. But now I feel like no longer having a single unique key to correlate my data across different leaked data sets might also be a benefit.

Re: Quora User Data Compromised

#374

This is another reason why I don't like the "social logins". You give them so much data. They strongly encourage you to use the social login instead of using the regular email sign up.

At least your password won’t be exposed in that case.

It will be, once fb/google is breached (which will happen eventually). The consequences for you will be far more unpleasant.

Re: Quora User Data Compromised

#375
post #276

Earlier quoted context omitted.

Privacy.com allows you to create virtual credit cards once you connect a source of payment to your account. Can be bank or debit card. I personally create one credit card for every paid subscription I have with the limit set on the amount that's supposed to be debited (eg. Monthly limit on Tidal charging $20). Privacy is a game changer for online transaction security imo. An additional benefit is the ability to subsc…

Privacy.com is US only though.

Is it only for US persons or does it just require a US bank account?

Because then you can get one from transferwise.

Re: Quora User Data Compromised

#376
post #356

In 2013 a quora moderator contacted me and demanded that I provide my real name, and information that my name is real or they would ban my account. I tried reasoning with them, that I just wanted to view content and did not attend to write answers or interact etc, plus, they had a valid email address and facebook profile (also fake name on facebook). They fought back "we actually want proof of your real name like a s…

How did they know? Was your name obviously fake? My favorite feature of DuckDuckGo is that if you search "random name", it will actually generate a random name (e.g. "Marlon Lonzo"). So I use these random unique names on all websites that require one.

I've been known as John Smith, born 1/1/1970 for decades now

Re: Quora User Data Compromised

#377
That's lame, but there is to always remember that information leaks are happening in almost every company out there. The way we build and run systems is no adequate, unless very large efforts (like in the case of Google) are made in order to try to limit the attack exposure, but this is not for everybody cost-wise IMHO. Makes more sense for companies to limit the amount of data they ingest. In this regard it's very bad that Quora or Linked-In force you to login just to see content. As a user, if you want to live under correct expectations, assume that your real name and profile picture, and possibly an hashed password, are always automatically leaked.

Re: Quora User Data Compromised

#378

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

That's because a few years ago a website that let you login meant it was a "real" website. Look at phone systems. Every one you have to deal with says please listen carefully as our menu options have changed. Then they lead you through an audio menu with the same bullshit that turns a 15 second interaction into one that could last hours over multiple phone calls.

My point is people do cargo cult everything. Could the service be BETTER without forcing the user to sign up? Inconceivable! Everyone knows you should force users to sign up.

Re: Quora User Data Compromised

#379
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

I looked over privacy.com - specifically their security page[0] which reads impressively. As I looked at my "dashboard" I couldn't help but notice (according to uBlock Origin) that privacy.com , ironically, connects to facebook (.net) and google (fonts, apis, gstatic). I'm certain none of those 3rd-party connections are necessary and yet... like muscle-memory... devs continue to thoughtlessly invite tracking. [0] htt…

Haven't looked very closely, but how do you think they make money by offering virtual credit cards for free? I bet they will track all your purchases and resell them for marketing later.

Fonts and other stuff from google and facebook is just a small piece of the puzzle.

Re: Quora User Data Compromised

#380
post #364

Earlier quoted context omitted.

Its unfortunate that privacy.com is only for US residents. Does anyone know of a similar service that's available for Europeans as well? Specifically the virtual card feature. Most of the services that I've seen to offer something like this are for EEA residents only. This seems to be a new restriction imposed by Visa/MasterCard.

Not sure about EEA only, but Revolut might work for you and it has virtual cards. Would be nice to have privacy.com more widely available.

At Revolut you can only have one disposable virtual card active at any moment and they cannot be used for subscriptions/recurring payments.

You can have up to 5 non-disposable virtual cards.

Post reply on HN