Live data from Hacker News

Quora User Data Compromised

blog.quora.com

431–440 of 525 posts

Re: Quora User Data Compromised

#431

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

This is exactly what has me excited about the new content model for the web Eich proposes. I just commented in another thread [1] but essentially: 1. enable donations / tips / subscriptions to sites using a browser-native crypto wallet 2. use ZKP anonymity This enables a publisher / subscriber business model of 'dollars without data'. Which should really be the Minimum Viable Product for a publisher. PII data for mar…

A better solution to this is incorporating https://universallogin.io/ imo.

Re: Quora User Data Compromised

#432

So I'm not a security expert, so I ask this in real earnest to learn: what is it that these companies keep doing wrong, and/or why aren't they adjusting to the climate that these types of attacks are increasing over time? Or are they trying to adjust, and the attacks are getting so sophisticated that the pace of investment in counter-measures is below that of the pace of advancement in the complexity of attacks? Or s…

It's not the companies, it's the internet itself. The internet is only composed of communication protocols, with security as an after-thought. The solution to this is incorporating security at the protocol layer, which is the end game of crypto platforms like Ethereum.

Re: Quora User Data Compromised

#433

Earlier quoted context omitted.

>given Quora's tenure (almost nine years!) that this is the first breach is pretty amazing I am sorry but this is #ShitHackerNewsSays worthy. Let me fix it for you >given Equifax's tenure (almost 119 years! Since 1899) that this is the first breach is pretty amazing Better now? Downvote me if you want, but there are no pats in the back for having PII leaks, no matter the years.

I don't know why you need to be so aggressive. You've made multiple comments on this thread, all in this vein. Flagged.

He is not aggressive at all. Upset? Maybe. Aggressive? No.

Re: Quora User Data Compromised

#434
post #149

Earlier quoted context omitted.

Was the water company thankful enough to compensate you for the $X,000 consulting services you provided because they didn't set up their own security monitoring?

Given their lack of security, I’m guessing they have no idea of the value that I provided. It’s all good though. Knowing I helped thousands of my neighbors is compensation enough. Besides, if they gave me a credit, they’d have to hike everyone’s bill to compensate!

I guess the money diesn't matter to you personally at all, but they could pay a bonus from profits, or by cutting executives wages (if they're a non-profit). It's not like the only means of paying is gouging customers.

Re: Quora User Data Compromised

#435
It's strange that:

- the linked article says the breach included hashed passwords, but makes no mention of salt

- the help page says they're forcing affected users to change their passwords

If the passwords were salted before being hashed and stored, then:

- Why not mention it, so users (especially those who don't use unique passwords on every site) know that it's not trivial for their password to be found?

- Why force people to change their passwords?

Re: Quora User Data Compromised

#436

So I'm not a security expert, so I ask this in real earnest to learn: what is it that these companies keep doing wrong, and/or why aren't they adjusting to the climate that these types of attacks are increasing over time? Or are they trying to adjust, and the attacks are getting so sophisticated that the pace of investment in counter-measures is below that of the pace of advancement in the complexity of attacks? Or s…

It's not the companies, it's the internet itself. The internet is only composed of communication protocols, with security as an after-thought. The solution to this is incorporating security at the protocol layer, which is the end game of crypto platforms like Ethereum.

I am not convinced by this narrative. I would rather assume that like any ordinary project, Quora also was developed with zero security in mind. I would bet in a huge amount that noone has ever said during any project meeting that `BTW. I think we should spend 2 more months implementing every detail securely`. Probably security was an afterthought.

Re: Quora User Data Compromised

#437
post #44

Earlier quoted context omitted.

Do you have any more info on running your own mail server? I looked at doing so but was promptly steered away because of blacklisting, servers that allow it and redundancy.

Can't recommend FastMail enough- it has aliases which automatically forward mail from xyz@alias.yourdomain.com to your alias@yourdomain.com - This is very similar in practice to the + trick with gmail[1] but with the benefit that your email addresses will pass all stupid Javascript email validation rules. [1] https://www.thewindowsclub.com/gmail-address-tricks

Been using Fastmail for ages... great provider.

Re: Quora User Data Compromised

#438
post #239

Earlier quoted context omitted.

What bank/card allows you to create unique credit cards with separate limits? The one I was using (Swedbank/visa/mastercard) stopped providing this service last year.

Citibank offers virtual credit cards. Once they are used by one merchant, they can not be used by any other merchant. On top of that, you can optionally give them money and time limits.

I rather like this feature from CitiBank. I hate the interface, but the feature is great. I can use it to sign up for monthly services that I'm unsure about. If I don't want to go through the hassle of canceling the service, I just don't renew the cards.

I also use it with sites I don't necessarily trust, like a random auto parts store. If it were a tad easier to use, I'd use it for nearly everything.

Re: Quora User Data Compromised

#439

Earlier quoted context omitted.

And it must end with "-The Quora Team" Because we will leak your data, but we won't bother designating a responsible spokeperson be it security officer, cto, vp of engineering or principal architect. It will be the all nebulous quora team.

I feel like you're criticising just for the sake of it. Firstly, this post is signed by Adam D'Angelo, the CEO and co-founder. If you had opened the link you wouldn't even have had to scroll down, it's literally on the second line, right after the headline. So clearly Quora doesn't do what you've accused them of doing. Secondly, what good does crucifying one person do? I'm sure if they had written it such that one pe…

The email they sent out to actual users was signed "The Quora Team"

Re: Quora User Data Compromised

#440
post #356

Earlier quoted context omitted.

How did they know? Was your name obviously fake? My favorite feature of DuckDuckGo is that if you search "random name", it will actually generate a random name (e.g. "Marlon Lonzo"). So I use these random unique names on all websites that require one.

I've been known as John Smith, born 1/1/1970 for decades now

I'm starting to get lots of end of life planning service targeted ads as a result of using 01/23/45 as a birth date since forever ago.
Post reply on HN