Live data from Hacker News

Quora User Data Compromised

blog.quora.com

421–430 of 525 posts

Re: Quora User Data Compromised

#421

Earlier quoted context omitted.

Let me write an apology for them: "the security and privacy of your information is our utmost priority" Feel better, don't you?

And it must end with "-The Quora Team" Because we will leak your data, but we won't bother designating a responsible spokeperson be it security officer, cto, vp of engineering or principal architect. It will be the all nebulous quora team.

I feel like you're criticising just for the sake of it.

Firstly, this post is signed by Adam D'Angelo, the CEO and co-founder. If you had opened the link you wouldn't even have had to scroll down, it's literally on the second line, right after the headline. So clearly Quora doesn't do what you've accused them of doing.

Secondly, what good does crucifying one person do? I'm sure if they had written it such that one person was responsible for everything, a similar comment would have been written - "why make one person the scapegoat? The entire team should take responsibility!!"

I don't know anything about your experience working in software, but when there's a fuck up like this, it doesn't do any good to pin the blame on one person. You figure out where your systems failed, and fix the system after conducting a blame free review. If you start pointing fingers within the team, you'll never get anything fixed.

Re: Quora User Data Compromised

#422
post #75

At this point I am operating on the assumption that ALL businesses that have my data are going to inadvertently leak it at some point, and thus I am attemtping to provide individual companies with as little information about me as possible. The toughest ones here are my online banking and my online health portal, but other than that, I have gotten pretty picky about what information I give any company.

Yeah, I tag every email address I give to a vendor, and I have for years. It has helped me discover a number of breaches. The address I gave Quora isn't in the hands of spammers yet, which is a mildly good sign. But normally it takes a while for an address to get out to the bottom-feeders, so we'll see.

> Yeah, I tag every email address I give to a vendor, and I have for years. It has helped me discover a number of breaches.

Can you go into detail on this? What exactly do you mean by tagging? Just wondering in case I want to do the same.

Re: Quora User Data Compromised

#423
post #75

Earlier quoted context omitted.

Yeah, I tag every email address I give to a vendor, and I have for years. It has helped me discover a number of breaches. The address I gave Quora isn't in the hands of spammers yet, which is a mildly good sign. But normally it takes a while for an address to get out to the bottom-feeders, so we'll see.

> Yeah, I tag every email address I give to a vendor, and I have for years. It has helped me discover a number of breaches. Can you go into detail on this? What exactly do you mean by tagging? Just wondering in case I want to do the same.

There are a few ways to do it, but I use what is known as subaddressing: https://tools.ietf.org/html/rfc5233

Re: Quora User Data Compromised

#424

Earlier quoted context omitted.

I haven't even tried to use these services, can someone please explain why centralizing all your online activity helps with privacy?

The traditional pitch from security experts is "Using a password manager is better than reusing the same password on lots of sites, or using low entropy passwords, or saving your passwords in an excel spreadsheet, which is what you were probably doing before"

Apart from shoulder-surfing wouldn't an encrypted spreadsheet be equivalent (not Excel, as I imagine MS might randomly send that data home, eg of there's a crash)?

In both cases once there's physical compromise, if they have the "master" password you're screwed?

I presume they use clipboards for the pasting, or do typing that could be captured bya keylogger.

Re: Quora User Data Compromised

#425

Earlier quoted context omitted.

I worked at Quora, but left before this change was made, but I believe it was totally retroactive, mainly because I got emails with information about my previous anonymous answers and a deadline to get the one-time link. Now... if the emails were logged and in the exploited database, then all bets are off, but there's no indication that happened at all. There are about a hundred other things about this that give me a…

>given Quora's tenure (almost nine years!) that this is the first breach is pretty amazing I am sorry but this is #ShitHackerNewsSays worthy. Let me fix it for you >given Equifax's tenure (almost 119 years! Since 1899) that this is the first breach is pretty amazing Better now? Downvote me if you want, but there are no pats in the back for having PII leaks, no matter the years.

I don't know why you need to be so aggressive. You've made multiple comments on this thread, all in this vein.

Flagged.

Re: Quora User Data Compromised

#426
post #91

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

Does the bank not hold the liability if a credit card is used fraudulently? (I'm sure the process is a pain.)

Re: Quora User Data Compromised

#427

Earlier quoted context omitted.

Check out Keepass! Rather than syncing directly into a Cloud, it allows you to store a database file into any location. It supports MFA (e.g. by combining a password with a secret file, or a Yubikey). And everything is open-source. I like the model a lot, because it solves the "database ownership" issue, where your Password provider (be it LastPass, 1Password, etc) becomes in itself a weak link.

I used to use KeePass but the lack of a proper crossplatform UI eventually broke it for me; KeePassX on linux looked and performed terribly, the Android app was just bad, etc etc etc. I switched to 1password which - at least at the time - offered a web-based fallback hosted from your own dropbox. Plus at the time you owned the data and were responsible for storing and syncing it. Dropbox support came out of the box b…

KeePassXC works great for me on Linux, Windows, Mac, and Android.

Re: Quora User Data Compromised

#428
post #240

Earlier quoted context omitted.

Nice. Hows that occasional instance where you need to type your 100 character password into Netflix on a Smart TV?

Given the shady things people have found their smart TVs doing, I'd feel about as safe typing a password into a smart TV as I would changing the password to "hunter2". The TV should display (or maybe email) a link that I would visit with my primary web browser and grant it permissions - or ask for a password as a very last resort for users who have no computer/phone but somehow have Netflix.

Plex and Roku do this. They give you a simple one time URL like plex.tv\U23SL That URL asks you to log in (on your computer) and once it's authorized, the Roku or Plex on your TV gets the signal and continues. Easier than typing on a TV device.

Re: Quora User Data Compromised

#430
post #152

Earlier quoted context omitted.

virtual card #s is a great system, why did it rot? I assume it's because the whole industry prefers data-brokering your purchase history, joined on credit-card # to establish identity.

That's one good reason, another is probably pushback from merchants. Having these virtual cards completely shuts down the "free-trial-we-hope-you'll-forget-and-let-us-ding-you-for-a-month-or-two" business model that's so popular for online services.

Not sure you need merchant pushback there - if it leads to unexpected charges then it's more likely to lead to inability to pay, or short payment, which gives the credit card companies their chance to feed off the client.
Post reply on HN