Live data from Hacker News

Quora User Data Compromised

blog.quora.com

401–410 of 525 posts

Re: Quora User Data Compromised

#401

Earlier quoted context omitted.

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

I use 1password regularly, tried bitwarden, found it lacking in various quality of life features & polish that 1p has, so I didn't migrate. This is kind of yikes for a password manager too: https://github.com/bitwarden/core/issues/399 But it's also pretty much the only polished open source password manager there is out there. For now I'll be sticking with 1password, but might check out bitwarden again once they have…

Just for the record, I don't believe that 1Password has unit tests either. I was unable to find evidence of unit tests, but I did find this: https://discussions.agilebits.com/discussion/comment/156429/...

We have a tendency to compare opaque with transparent and balk at what we find, but I question what you would feel if you could see through the opaque.

Re: Quora User Data Compromised

#402

Earlier quoted context omitted.

I use keepassx, a local password manager. I don't trust centralized online password managers with browser extensions. Huge attack surface. I copy and paste usernames and passwords.

I also do that (almost, keeweb + dropbox) and copy paste logins, but a serious problem is that you need to clear the clipboard after, otherwise any other site you visit can read it.

Dunno about Keeweb but KeePass automatically wipes the clipboard after a configurable number of seconds.

Re: Quora User Data Compromised

#403

Earlier quoted context omitted.

Check out Keepass! Rather than syncing directly into a Cloud, it allows you to store a database file into any location. It supports MFA (e.g. by combining a password with a secret file, or a Yubikey). And everything is open-source. I like the model a lot, because it solves the "database ownership" issue, where your Password provider (be it LastPass, 1Password, etc) becomes in itself a weak link.

I used to use KeePass but the lack of a proper crossplatform UI eventually broke it for me; KeePassX on linux looked and performed terribly, the Android app was just bad, etc etc etc. I switched to 1password which - at least at the time - offered a web-based fallback hosted from your own dropbox. Plus at the time you owned the data and were responsible for storing and syncing it. Dropbox support came out of the box b…

Yeah you're right, I believe it's based on .NET so on Linux you'll have to use Mono. For the plugin ecosystem, that's suboptimal because you'll have to rebuild a lot of plugins from scratch.

I used to be a 1password user, but they were pushing their premium, cloud-based offering a lot and lacked Yubikey support so I switched away.

Re: Quora User Data Compromised

#404

Earlier quoted context omitted.

Check out Keepass! Rather than syncing directly into a Cloud, it allows you to store a database file into any location. It supports MFA (e.g. by combining a password with a secret file, or a Yubikey). And everything is open-source. I like the model a lot, because it solves the "database ownership" issue, where your Password provider (be it LastPass, 1Password, etc) becomes in itself a weak link.

I used to use KeePass but the lack of a proper crossplatform UI eventually broke it for me; KeePassX on linux looked and performed terribly, the Android app was just bad, etc etc etc. I switched to 1password which - at least at the time - offered a web-based fallback hosted from your own dropbox. Plus at the time you owned the data and were responsible for storing and syncing it. Dropbox support came out of the box b…

Have another look at KeePass. They recently got a native Mac implementation, and I seem to recall seeing a new one for Linux at the time.

On the Mac, KeePass now feels like a better experience than having to pay a subscription for 1password.

Re: Quora User Data Compromised

#405

Earlier quoted context omitted.

I moved from LastPass to 1Password recently. Had been using LastPass for several years, but filling failures, the lack of copy password in FF (and no binary workaround for Linux), and generally unhelpful support when I contacted them prompted me to move. Very happy with 1PasswordX (the browser-only version) - filling is much better, copy is supported out of the box, support have been very helpful when I've reached ou…

I was a 1Password fan for many years, until the big push to go subscription. For now I'm just using Apple's keychain until I decide what tool to use next. If you're in Apple's ecosystem, keychain actually works pretty well.

Have a look at KeePass. There's a native OSX client now.

Re: Quora User Data Compromised

#406
post #396

Earlier quoted context omitted.

I have the same disappointing experience with LastPass and have grown tired of it. One of these days I will do something about it!

I'm in the same boat. The user experience on it is terrible now. The worse thing that happens to me is if I generate a password, and then Lastpass doesn't save it! It feels like a 50% shot it will actually save the generated password. I have nearly 1000 passwords stored in it now, so it's going to be a huge pain to migrate.

This is by far the worst. I have LP set up with a shortcut + fingerprint tap on my MBP, which works great until I'm generating a password, which never gets saved. I have to remember to get my vault page open ready to fill in before I generate the password, because if I generate one from the toolbar dropdown I'll never see it again. Ugh.

Re: Quora User Data Compromised

#407

In 2013 a quora moderator contacted me and demanded that I provide my real name, and information that my name is real or they would ban my account. I tried reasoning with them, that I just wanted to view content and did not attend to write answers or interact etc, plus, they had a valid email address and facebook profile (also fake name on facebook). They fought back "we actually want proof of your real name like a s…

> I tried reasoning with them, that I just wanted to view content and did not attend to write answers or interact etc, plus, they had a valid email address and facebook profile (also fake name on facebook). They fought back "we actually want proof of your real name like a scan of ID". I danced around and did not end up giving them a scan of my id, but I changed it to my real name.

I don't understand why you bothered arguing with them instead, I dunno, creating a new fake account?

Re: Quora User Data Compromised

#408
post #356

Earlier quoted context omitted.

How did they know? Was your name obviously fake? My favorite feature of DuckDuckGo is that if you search "random name", it will actually generate a random name (e.g. "Marlon Lonzo"). So I use these random unique names on all websites that require one.

I've been known as John Smith, born 1/1/1970 for decades now

Nice try, HAL9000 - you cant fool me

starts removing module cards

Re: Quora User Data Compromised

#409

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

> This is why I hate companies that force you to sign up to gain access to content I always found Quora's use of dark patterns and baiting you in from search engines then blocking the content particularly egregious. Always made me surprised anyone held that site to such a high standing and I can only imagine it's because the advocates never knew how awful the experience was without an account. I feel Pintrest is very…

And linkedin. But they get away because their founders are well connected or wellknown in SV.
Post reply on HN