Live data from Hacker News

Quora User Data Compromised

blog.quora.com

451–460 of 525 posts

Re: Quora User Data Compromised

#451

Earlier quoted context omitted.

I moved from LastPass to 1Password recently. Had been using LastPass for several years, but filling failures, the lack of copy password in FF (and no binary workaround for Linux), and generally unhelpful support when I contacted them prompted me to move. Very happy with 1PasswordX (the browser-only version) - filling is much better, copy is supported out of the box, support have been very helpful when I've reached ou…

I was a 1Password fan for many years, until the big push to go subscription. For now I'm just using Apple's keychain until I decide what tool to use next. If you're in Apple's ecosystem, keychain actually works pretty well.

Loving Safari / iOS 12's improved integration with Keychain.

However. Still can't uninstall 1Password. Haven't figured out where to store notes (meta) in Keychain. Stuff like "Name of your first pet?".

Re: Quora User Data Compromised

#452

Earlier quoted context omitted.

I have the same disappointing experience with LastPass and have grown tired of it. One of these days I will do something about it!

LastPass Mobile UI seems to be intentionally crippled ( https://vgy.me/9r29bm.jpg ) I assume because they want you to download the app, pushing you to purchase their license. If you load the same site using "load desktop site" the UI gets fixed.

The Android app is still very frustrating to use.

Re: Quora User Data Compromised

#453

In 2013 a quora moderator contacted me and demanded that I provide my real name, and information that my name is real or they would ban my account. I tried reasoning with them, that I just wanted to view content and did not attend to write answers or interact etc, plus, they had a valid email address and facebook profile (also fake name on facebook). They fought back "we actually want proof of your real name like a s…

Really? Are you sure this was actually Quora and not a scammer?

Edit: Sorry if stupid question, but that would be throwing major red flags if I got such an email.

Re: Quora User Data Compromised

#454

Earlier quoted context omitted.

I worked at Quora, but left before this change was made, but I believe it was totally retroactive, mainly because I got emails with information about my previous anonymous answers and a deadline to get the one-time link. Now... if the emails were logged and in the exploited database, then all bets are off, but there's no indication that happened at all. There are about a hundred other things about this that give me a…

>given Quora's tenure (almost nine years!) that this is the first breach is pretty amazing I am sorry but this is #ShitHackerNewsSays worthy. Let me fix it for you >given Equifax's tenure (almost 119 years! Since 1899) that this is the first breach is pretty amazing Better now? Downvote me if you want, but there are no pats in the back for having PII leaks, no matter the years.

This is an understandable counter point. I don’t really agree but I appreciate it.

Re: Quora User Data Compromised

#455

Earlier quoted context omitted.

I don't know why you need to be so aggressive. You've made multiple comments on this thread, all in this vein. Flagged.

He is not aggressive at all. Upset? Maybe. Aggressive? No.

As a meta point, the word "aggressive" has undergone significant scope creep in tech lately. It's worrisome that lots of people with influence have started to punish messages that, while polite, express explicit, forceful, and direct disagreement. The only remaining option is an indirect approach laden with false pleasantries and ambiguous language that leaves the reader confused about the actual state of agreement. We need to push back against false claims of aggressiveness.

Re: Quora User Data Compromised

#456

Earlier quoted context omitted.

Can I ask why you wanted to view Quora's content so much? They flood Google search results but I've never seen a single substantial answer on there - it's like an off-brand Stack Overflow with an even worse "I know programming so I'm smart about every subject" problem.

My experience with Quora answers has been that they are blatant ads from people working on different companies. Just search for anything like "what is an open source alternative to X" and the results will be a lot of people trying to justify why their Y paid option is a good solution for your problem.

I quickly stopped using Quora after finding the answers consisted solely of scam software (just didn't work), adware or stolen & rebranded software.

It seems to be popular with scammers and they have taken over.

Re: Quora User Data Compromised

#457
From now on, I will assume all my user-data will be compromised, we need a new way to store the user-data, it will be a balance of convenience and security, but more importantly, it needs to be temporal, i.e. the use-data shall not be static anymore, something like a virtual and temporarily generated password for each session?

Re: Quora User Data Compromised

#458
post #178

Earlier quoted context omitted.

Ah good to know. Does anyone know the reason they removed it from the Firefox addon?

I believe it had to do with the change from the old addon format to the new one in Firefox.

Bitwarden doesn't seem to have any problem copying passwords using a new-style extension with no binary install.

Re: Quora User Data Compromised

#459

Earlier quoted context omitted.

I believe it had to do with the change from the old addon format to the new one in Firefox.

Bitwarden doesn't seem to have any problem copying passwords using a new-style extension with no binary install.

I recall that the initial release of the Web Extension support was a bit threadbare, and/or that they had to change the extension ID or something of that sort, but it's also possible it was left out for existing design reasons/as a cudgel. In either case this whole thread has been useful for alerting me that I should re-evaluate if Lastpass is the optimal solution for me.

Re: Quora User Data Compromised

#460

Earlier quoted context omitted.

Install the LastPass binary, and you get copy password back in Firefox.

Not on Linux, and we've waited too long. 1Password supports it direct from the extension.

Weirdly, I have been using Lastpass in Firefox on Linux and seem to have copy/paste.

(Not that this whole thread hasn't had me re-evaluating whether there's a better solution for me now.)

Post reply on HN