Live data from Hacker News

Quora User Data Compromised

blog.quora.com

41–50 of 525 posts

Re: Quora User Data Compromised

#41

Wow. If this had happened a couple years ago, before they made all the anonymous entries truly anonymous, this would have been really ugly. It's a valuable lesson in "don't keep data you don't need". EDIT: A little backstory for non-Quorans. Until early 2017, anonymous Quora answers and comments were anonymous to the public but not actually anonymous in the database (they were still "your" entries). In early 2017 the…

> It's a valuable lesson in "don't keep data you don't need".

Unfortunately, though, most companies operate under the "keep data you might eventually need" principle.

Re: Quora User Data Compromised

#44
post #31
post #20

Earlier quoted context omitted.

I have an email address that I've only ever used as my AWS account email since many years ago. Somehow I started getting spam on it last year. It is not an address anyone could guess or somehow generate based on other data points such as name or otherwise.

Many of us who operate our own mail services use a unique email address for every web service we use. You'd be surprised how many of these unique email addresses I've received spam at (and have subsequently blackholed). I would estimate less than 50% of the associated services ever report a data breach event. I figure either there has been an unreported breach or, possibly more likely, the service sold their userlist…

Do you have any more info on running your own mail server? I looked at doing so but was promptly steered away because of blacklisting, servers that allow it and redundancy.

Re: Quora User Data Compromised

#45
post #28

Earlier quoted context omitted.

This is a healthy mindset to have. I feel that for every company that self-reports a leak, there are multiple other companies that have leaked your data and either haven't discovered the breach, refuse to disclose it, or flat out sold your data to the highest bidder.

You would be correct. In the US, which I might remind you, does not have a national law on the books regarding data breach notification. Even at the state levels, it’s varies pretty wildly on top of, most notifications are only required if there is evidence. So here is the challenge: what if I keep no logs, and have terrible security monitoring capability? If I am notified or discover a critical vulnerability on my o…

Still, I would have thought it is good practice to notify your users if you leak their data to thieves. Quora did the right thing and should be applauded.

As a counterexample, it seems that Newegg had a massive breach (thieves installed JavaScript that skimmed credit card numbers for weeks) in August, and even though my credit card was likely stolen, I hever heard about it from Newegg.

Re: Quora User Data Compromised

#46

Quora would not allow you to read multiple answers by clicking on "similar questions" (on the side) without creating an account. And then this happens!

Valid point. If you're aggressively farming data, so much so that you log them in automatically if they are logged into the google account then you better be careful with data too

Re: Quora User Data Compromised

#47

Wow. If this had happened a couple years ago, before they made all the anonymous entries truly anonymous, this would have been really ugly. It's a valuable lesson in "don't keep data you don't need". EDIT: A little backstory for non-Quorans. Until early 2017, anonymous Quora answers and comments were anonymous to the public but not actually anonymous in the database (they were still "your" entries). In early 2017 the…

> It's a valuable lesson in "don't keep data you don't need". Unfortunately, though, most companies operate under the "keep data you might eventually need" principle.

Not anymore, at least in Europe. The GDPR began to move things in the right direction.

Re: Quora User Data Compromised

#48
>I didn’t know I had a Quora account. How is it that my email or information was exposed? You may have signed up for Quora some time ago. While you might not have regularly visited or used Quora, your account remained, and this breach may have exposed some of your information, such as the email address you signed up with, the password you used, or actions you took on Quora.

Would be nice if websites measured user activity and could 'lock out' or otherwise release their data if they never use the site; at least, confirm with said user via email if the account is needed.

But in this era, I'm sure companies would prefer to keep whatever data they can get.

Re: Quora User Data Compromised

#49

So I'm not a security expert, so I ask this in real earnest to learn: what is it that these companies keep doing wrong, and/or why aren't they adjusting to the climate that these types of attacks are increasing over time? Or are they trying to adjust, and the attacks are getting so sophisticated that the pace of investment in counter-measures is below that of the pace of advancement in the complexity of attacks? Or s…

[deleted]

Re: Quora User Data Compromised

#50

So I'm not a security expert, so I ask this in real earnest to learn: what is it that these companies keep doing wrong, and/or why aren't they adjusting to the climate that these types of attacks are increasing over time? Or are they trying to adjust, and the attacks are getting so sophisticated that the pace of investment in counter-measures is below that of the pace of advancement in the complexity of attacks? Or s…

No harm comes to the company after a breach so from their perspective there is no risk. Since there is no risk there is no need to improve security or reduce retained data.

It’s not really a security issue as much as an incentive issue.

Post reply on HN