Live data from Hacker News

Quora User Data Compromised

blog.quora.com

471–480 of 525 posts

Re: Quora User Data Compromised

#471

Earlier quoted context omitted.

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

Something about storing every password in a single cloud service to improve security sounds counterintuitive to me.

What do you do?

Re: Quora User Data Compromised

#472

Earlier quoted context omitted.

I have the same disappointing experience with LastPass and have grown tired of it. One of these days I will do something about it!

LastPass Mobile UI seems to be intentionally crippled ( https://vgy.me/9r29bm.jpg ) I assume because they want you to download the app, pushing you to purchase their license. If you load the same site using "load desktop site" the UI gets fixed.

Access through the apps has been free for a couple of years now.

Re: Quora User Data Compromised

#473

At this point I am operating on the assumption that ALL businesses that have my data are going to inadvertently leak it at some point, and thus I am attemtping to provide individual companies with as little information about me as possible. The toughest ones here are my online banking and my online health portal, but other than that, I have gotten pretty picky about what information I give any company.

The only way to independently verify a leak is to have a third party create a couple of user accounts with unique passwords and setup a corresponding gmail / facebook honeypot account which would alert them to logins. If my quoraAcct2 password ever gets hacked and used to login to my fake gmail or facebook account, I know that quora was compromised. Works with any site.

Re: Quora User Data Compromised

#475

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

physical mail is hardly more secured than email. 'literally anybody' could is in front of your house and fish all the mails straight from your mailbox while you are at work.

It's more secure in that stealing mail off endpoints requires the physical presence of, and personal risk to, the thief, and it's not scalable short of getting an army. By contrast, email can be stolen in bulk by one person anywhere in the world, from the comfort of their home or office.

Re: Quora User Data Compromised

#476

Earlier quoted context omitted.

Bitwarden doesn't seem to have any problem copying passwords using a new-style extension with no binary install.

I recall that the initial release of the Web Extension support was a bit threadbare, and/or that they had to change the extension ID or something of that sort, but it's also possible it was left out for existing design reasons/as a cudgel. In either case this whole thread has been useful for alerting me that I should re-evaluate if Lastpass is the optimal solution for me.

I switched to LastPass from 1Password because I hated their whole mobile sync thing where you had to be on the same wifi and start your Mac app to sync etc. I understand that it's more secure that way, but that trade-off was not worth for me. Has that changed in the meantime?

Re: Quora User Data Compromised

#477
post #91

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

Can you use this for one time purchases?

Re: Quora User Data Compromised

#478

I feel that this is becoming a standard narrative. SV company comes up with an idea, decides harvesting lots of user data is how they will monetize. VCs pump in a lot of money and expect their returns, so company is now forced to collect even more data aggressively (the sign-in wall that many others have pointed out is an example of this). VC pressure causes company to "innovate" fast, most likely trading off securit…

I think the success of Facebook and Google (being ad businesses) had a lot to do with this, i.e. "you are the product." If the trend to subscription businesses continues, do you think investors will approach how a company should scale differently?

Re: Quora User Data Compromised

#479

Earlier quoted context omitted.

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

I would like to recommend keepass. It's open source as well.

Agreed, a very functional manager for me, though I am using the KeePassXC [1] version on macOS (via brew cask) and Ubuntu (via snap).

1: https://keepassxc.org/

Re: Quora User Data Compromised

#480
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

Are you in paid bitwarden? For Premium and/or family?
Post reply on HN