Live data from Hacker News

Quora User Data Compromised

blog.quora.com

461–470 of 525 posts

Re: Quora User Data Compromised

#461

Earlier quoted context omitted.

He is not aggressive at all. Upset? Maybe. Aggressive? No.

As a meta point, the word "aggressive" has undergone significant scope creep in tech lately. It's worrisome that lots of people with influence have started to punish messages that, while polite, express explicit, forceful, and direct disagreement. The only remaining option is an indirect approach laden with false pleasantries and ambiguous language that leaves the reader confused about the actual state of agreement.…

Really? If I dismissed your comment with #ShitHackerNewsSays, you'd say that was a "forceful, direct disagreement"? Maybe you think this is great because "false" pleasantries are cut off, but for me that's aggressive.

Re: Quora User Data Compromised

#462
No system is breach-proof; security breaches happen. We as engineers should strive to reduce the break-ins and diligently push for high standards nevertheless.

Having said that, this is pretty much a perfect response to the situation.

1. Quick turnaround from the breach to the announcement 2. Concise description of what happened 3. Owning the mistake 4. Update of their mitigation 5. Promise to follow up & actionable items. 6. Additional technical detail for more interested: https://help.quora.com/hc/en-us/articles/360020212652

It sucks that this happened, but for that alone I'd like to applaud Quora team. Yes, it would've been great if they didn't have to force me to sign up from the first place. It would've been great if this breach has never happened. But for the context, they're handling the issue as well as possible.

Re: Quora User Data Compromised

#463

Earlier quoted context omitted.

I moved from LastPass to 1Password recently. Had been using LastPass for several years, but filling failures, the lack of copy password in FF (and no binary workaround for Linux), and generally unhelpful support when I contacted them prompted me to move. Very happy with 1PasswordX (the browser-only version) - filling is much better, copy is supported out of the box, support have been very helpful when I've reached ou…

I was a 1Password fan for many years, until the big push to go subscription. For now I'm just using Apple's keychain until I decide what tool to use next. If you're in Apple's ecosystem, keychain actually works pretty well.

You can still purchase a standalone license, even for v7. Sure they want you to rent access to your data, but that's not the only path. I also recently taught KeePassXC to read the 1P on-disk vault format, so you can continue to use 1P even in Linux, and even if AgileBits goes under.

Re: Quora User Data Compromised

#464
post #249

Earlier quoted context omitted.

I can’t trust privacy.com. I refuse to give some company direct access to pull money from my bank. Only a matter of time until they’re breached too.

How do you buy online?

With a credit card... I have protection against fraud on those.

Re: Quora User Data Compromised

#465

Earlier quoted context omitted.

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

I have been using Pass [0] with passff [1] and been pretty happy about it. Simple and offline password management where passwords live in gpg encrypted files. Additional features I like are tracking changes with git, bash completion and copying passwords to clipboard for few seconds temporarily, and a few very useful extensions. [0] https://www.passwordstore.org/ [1] https://github.com/passff/passff#readme

Pass ist definitely not as polished, but it's so dead simple, just a thin wrapper over gpg and git.

Re: Quora User Data Compromised

#466
post #246

Earlier quoted context omitted.

Yes, heavily regulated banks and medical providers have wonderful security. You can see that they do whenever they require punctuation (but not spaces or $) in the password, and demand an 8 character password (but reject anything over 16 or 24 characters). /sarcasm I especially like financial companies that have you login by using symantec VIP[1] which you append to your password. There's no way anyone thought that w…

Symantec's system does suck but there's actually a way to use it with Google Authenticator: https://www.cyrozap.com/2014/09/29/reversing-the-symantec-vi...

Interesting. So it's just a bunch of obfuscation and 3rd party api crap around a core of TOTP shared secrets between the app and symantec? Why don't they implement it that way, and make it transparent, so that their app can add multiple VIP credentials, rather than obfuscating everything, locking it down to a single shared credential for all sites?

Re: Quora User Data Compromised

#467
post #116

Earlier quoted context omitted.

You could just use a normal Citi or BoA or any other card that generates virtual card numbers and that'll also lock it to that vendor after the first charge. So that they couldn't even hit it for $0.80 if they wanted to.

Last time I checked, both Citi and BofA give me virtual card numbers via a Flash plugin. I really have no desire to run Flash any more. Has that changed?

Capital One gives virtual card numbers via a Firefox or Chrome extension, which you use on the check out page of the site where you want to use the virtual card. It is quite convenient.

The virtual cards don't have separate spending limits, though, so it is not quite as good as BofA or Citi for use with questionable sites.

Re: Quora User Data Compromised

#468

Earlier quoted context omitted.

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

I do love lastpass but since switching to Firefox 100% away from Chrome, the lack of copying a password to the clipboard without seeing it first really stings. What if someone is sitting next to me, or someone is grabbing screenshots or streaming my screen? It's like having this super secure electrified iron door installed but neglecting to lock it. Is anyone aware of a technical reason that copy to clipboard is abse…

The clipboard can be accessed by any other application.

Re: Quora User Data Compromised

#469
post #91

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

I have a hard time trusting _any_ of the password services that host my passwords.

Single point of failure. Even if they claim they're "encrypted so that even THEY can see them", it's so easy to mess up encryption, it makes it a single point of failure.

I still share passwords between my devices though, but instead I use KeePass along with the Android app. For less critical passwords I let Chrome keep them; I _mostly_ trust Google, and non-critical passwords are exactly my level of trust of Google.

And I also trust Google to share my (encrypted) KeePass file with my devices. But now it's two points of failure: Someone would have to break into a private Google Drive, get my KeePass file, and break the KeePass encryption.

And I trust _both_ KeePass _and_ Google more than I trust Lasspass to get security right.

Post reply on HN