Live data from Hacker News

Quora User Data Compromised

blog.quora.com

481–490 of 525 posts

Re: Quora User Data Compromised

#481

Wow. If this had happened a couple years ago, before they made all the anonymous entries truly anonymous, this would have been really ugly. It's a valuable lesson in "don't keep data you don't need". EDIT: A little backstory for non-Quorans. Until early 2017, anonymous Quora answers and comments were anonymous to the public but not actually anonymous in the database (they were still "your" entries). In early 2017 the…

Weren't there some cases where people had made anonymous answers but there was a way to find out that they had written such an answer?

Re: Quora User Data Compromised

#482

Earlier quoted context omitted.

I worked at Quora, but left before this change was made, but I believe it was totally retroactive, mainly because I got emails with information about my previous anonymous answers and a deadline to get the one-time link. Now... if the emails were logged and in the exploited database, then all bets are off, but there's no indication that happened at all. There are about a hundred other things about this that give me a…

This is the one which came to light.

Which is all that is worth speculating about and discussing in this thread, or are you suggesting otherwise?

Re: Quora User Data Compromised

#483

Earlier quoted context omitted.

I have the same disappointing experience with LastPass and have grown tired of it. One of these days I will do something about it!

Check out Keepass! Rather than syncing directly into a Cloud, it allows you to store a database file into any location. It supports MFA (e.g. by combining a password with a secret file, or a Yubikey). And everything is open-source. I like the model a lot, because it solves the "database ownership" issue, where your Password provider (be it LastPass, 1Password, etc) becomes in itself a weak link.

I have used Keypass for years. It is not as convenient as some of the alternatives, but I trust it more.

Re: Quora User Data Compromised

#484

Earlier quoted context omitted.

My experience with Quora answers has been that they are blatant ads from people working on different companies. Just search for anything like "what is an open source alternative to X" and the results will be a lot of people trying to justify why their Y paid option is a good solution for your problem.

I quickly stopped using Quora after finding the answers consisted solely of scam software (just didn't work), adware or stolen & rebranded software. It seems to be popular with scammers and they have taken over.

In other areas it seems like it's people working on their craft of writing fiction, notably erotic fiction. Questions like "What's the naughtiest thing you've done at work?" generate those kind of responses. Which is fine, just don't expect me to believe it really went down like that.

Re: Quora User Data Compromised

#485

Earlier quoted context omitted.

I use 1password regularly, tried bitwarden, found it lacking in various quality of life features & polish that 1p has, so I didn't migrate. This is kind of yikes for a password manager too: https://github.com/bitwarden/core/issues/399 But it's also pretty much the only polished open source password manager there is out there. For now I'll be sticking with 1password, but might check out bitwarden again once they have…

Just for the record, I don't believe that 1Password has unit tests either. I was unable to find evidence of unit tests, but I did find this: https://discussions.agilebits.com/discussion/comment/156429/... We have a tendency to compare opaque with transparent and balk at what we find, but I question what you would feel if you could see through the opaque.

That is true, but at least they have code review and multiple people ;) I'm just estimating from my experience that after a certain point, most companies start writing automated tests.

And if you look at their jobs page, one of the job description points is "Create unit tests for existing code to run faster and more reliably.": https://1password.com/jobs/droid-builder/

They might even have a few QA people AFAIK!

I understand why the single founder / engineer of bitwarden doesn't have tests. When you're a startup not writing tests can speed you up significantly. But after a certain point they are going to need automated testing, especially for something as vital as this.

For me, the lack of open source in 1p has been a sticking point, and I was planning to migrate after the audit. But seeing no tests, 1p documenting their security model and bitwarden not being good enough compared to 1p in UI has me sticking to 1p for now. I have high hopes that bitwarden will get to that maturity point one day.

Re: Quora User Data Compromised

#486
post #91

Earlier quoted context omitted.

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

Can you use this for one time purchases?

Yep! You can create "burner" cards that become invalid after one use. I actually never use that feature, because sometimes vendors screw up and have to put the charge through a second time or whatever. Instead I set a lifetime spending limit $1 higher than the purchase I'm making.

Re: Quora User Data Compromised

#487

Clearly this is well orchestrated and professional. I'm wondering what could be the motivation for such an attack. There is no monetary benefit whatsoever. Perhaps some AI company wanting to acquire solid data to train their models?

Rumors are that it was a disgruntled ex-employee.

Really? Do tell

Re: Quora User Data Compromised

#488

In 2013 a quora moderator contacted me and demanded that I provide my real name, and information that my name is real or they would ban my account. I tried reasoning with them, that I just wanted to view content and did not attend to write answers or interact etc, plus, they had a valid email address and facebook profile (also fake name on facebook). They fought back "we actually want proof of your real name like a s…

Can I ask why you wanted to view Quora's content so much? They flood Google search results but I've never seen a single substantial answer on there - it's like an off-brand Stack Overflow with an even worse "I know programming so I'm smart about every subject" problem.

They have a lot of great anwesers, especially by experts in the field. In the early days around 2011, I would spend hours just reading everything I could on the site.

These days the growth has masked all the good stuff with a layer of spam and general crap that’s hard to get past. Inevitable consequence of growing users but it has been managed poorly.

Re: Quora User Data Compromised

#489
post #395
post #332

Earlier quoted context omitted.

+2, keepass and plain google drive / dropbox / icloud file sync to have it available in several machines.

+3 Though I sync it on my synology instead of teh cloud.

I've thought about setting up a personal NAS for this purpose. But I'm concerned about having a single point of failure/loss in the event of a house fire or burglary. Any chance you've addressed this risk in your implementation?

Re: Quora User Data Compromised

#490

Earlier quoted context omitted.

1000x this. Nextdoor did this to my parents. It's fairly ridiculous. The state of personal data regulation in the US is abysmal. Unfortunately, if Cambridge Analytica wasn't enough to spur new regulation, I fear nothing will.

I can understand NextDoor at least. It’s very neighborhood based, and they need some way to verify that you live where you say you live. If people keep seeing membership in their neighborhood has included those who don’t love in their area, the main attraction of NextDoor will disappear.

I think you're trying to start a different conversation than what I had intended to point out by adding another anecdote to the original comment I was responding to.

Right now there is relatively little liability in gathering personal data about customers but huge benefits to doing so. I believe that there should be regulation governing punishments and protections for consumers whose data may be compromised or mishandled by corporate entities.

As it stands right now a company can leak personal data from their customers and face very few consequences. Rather, the negative consequences of customer data leaks are felt by the customer rather than the corporation that mishandles their data. This is a similar externality-effect as pollution, where a bad actor's malfeasance generates a larger negative impact than what is directly born by the bad actor itself.

We could discuss whether or not NextDoor has a legitimate use for personal identification data, but that's a tangential discussion. My point was supposed to be that any firm that gathers personal data should be assuming a greater amount of liability than they currently are.

Post reply on HN