Live data from Hacker News

Quora User Data Compromised

blog.quora.com

411–420 of 525 posts

Re: Quora User Data Compromised

#411
post #178

Earlier quoted context omitted.

Install the LastPass binary, and you get copy password back in Firefox.

Ah good to know. Does anyone know the reason they removed it from the Firefox addon?

I believe it had to do with the change from the old addon format to the new one in Firefox.

Re: Quora User Data Compromised

#412

Earlier quoted context omitted.

I have the same disappointing experience with LastPass and have grown tired of it. One of these days I will do something about it!

Check out Keepass! Rather than syncing directly into a Cloud, it allows you to store a database file into any location. It supports MFA (e.g. by combining a password with a secret file, or a Yubikey). And everything is open-source. I like the model a lot, because it solves the "database ownership" issue, where your Password provider (be it LastPass, 1Password, etc) becomes in itself a weak link.

Keepass is great, but it is somewhat slower and more clicks to get passwords into forms as opposed to 1Password or LastPass.

Re: Quora User Data Compromised

#413
post #153
post #148

Earlier quoted context omitted.

Companies hate users who don't want to sign up. They do not want that relationship. So it's a win-win if you dont' sign up. Why would companies feel obligated to generate content for free? If their systems get hacked and they have your snail mail address, they get your snail mail address as well. Email doesn't change that story.

They (Quora) don't hate you if get to their site via a Google referer. That's really shameful.

How do you know?

Re: Quora User Data Compromised

#414
post #342

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

> This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. I felt validated when I received the email from Quora about the hack to a fake email address and addressing me by a fake name.

This should be a service by password managera. Not just password generation but fake emails and details too.

Re: Quora User Data Compromised

#415

I didn't even know I had a quora account. Never continuously registered one. Got the e-mail though. Tried to log in, had to "complete my account" before I could go on.....wtf.... I deleted my account now, tho.

I knew I had an account but it was via oauth and I had to create a "real" quora account in order to delete it. The notice that they were storing contacts from other social networks was the part that pushed me over the top towards deletion.

This must have been it. Still not sure at which point I've ever logged in to quora, but I can't think of any other explanation

Re: Quora User Data Compromised

#417
post #362

This is all bullshit. My data is all over the place. At this point I expect none of my personal data to be private. This last few weeks alone my data was stolen from British Airways, Cathay Pacific, SPG/Mariott, Quora. As users we are completely powerless. Time for change. Time for intelligent heads to come together and think of how a better internet security architecture needs to look like.

I'm half afraid that some sort of Cambridge Analytica type firm is buying these on the dark-net and merging all the data-sets together trying to put together even more accurate psychological profiles.

Re: Quora User Data Compromised

#418
post #149
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

Was the water company thankful enough to compensate you for the $X,000 consulting services you provided because they didn't set up their own security monitoring?

Right, it’s a nice story and all, but... why is the customer the one informing these companies of the problem? That’s backwards.

Re: Quora User Data Compromised

#419

I really started hating Quora a while back, probably 3 years ago and stopped collaborating. Most because "people" were spamming answers with marketing bs... So many answers start with "I'm Bob, CEO of MyCompany.com, I am an expert in this and that" Most Quora users are hungry for answers and flood-request you to answer their question just because the system recommends them to do so. No matter how many times you pass,…

A lot of the quora answers on topics outside of computer science and math are just plain wrong, especially in history, philosophy, and economics.

Re: Quora User Data Compromised

#420

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

This is exactly what has me excited about the new content model for the web Eich proposes. I just commented in another thread [1] but essentially: 1. enable donations / tips / subscriptions to sites using a browser-native crypto wallet 2. use ZKP anonymity This enables a publisher / subscriber business model of 'dollars without data'. Which should really be the Minimum Viable Product for a publisher. PII data for mar…

I'm very excited about Sovrin and other Self-Sovereign Identity solutions. As one of the engineers at Mainframe (we're building decentralized, unstoppable apps that keep data and relationships in control of the user) I think what you're talking about is one of the top two value-adds for decentralization for western societies.

Brave and BAT are attempting the same thing from a slightly different direction than we are--they are attempting to bring privacy to partially-decentralized apps; however, I don't think this will ultimately succeed--privacy is broken by the weakest link. As soon as you allow some connection to some server somewhere that's exfiltrating your interests, you now have advertisers lining up to buy that data and exfiltrate more. As far as I understand the "hybrid decentralized app" model, where DNS and web2.0 are allowed, you permit these weak links to exist.

Post reply on HN