Earlier quoted context omitted.
If your main concern is the sheer number of username/unique password combos, pick a good password manager that works well across the devices you use. I’ve literally stopped caring about this aspect of my family’s online life thanks to 1Password. That iOS 12 added OS level integration for the service was the icing on the cake for me.
That's only part of it. The other part is that - invariably - they get hacked.
Quora User Data Compromised
491–500 of 525 posts
Re: Quora User Data Compromised
#492Earlier quoted context omitted.
And it must end with "-The Quora Team" Because we will leak your data, but we won't bother designating a responsible spokeperson be it security officer, cto, vp of engineering or principal architect. It will be the all nebulous quora team.
I feel like you're criticising just for the sake of it. Firstly, this post is signed by Adam D'Angelo, the CEO and co-founder. If you had opened the link you wouldn't even have had to scroll down, it's literally on the second line, right after the headline. So clearly Quora doesn't do what you've accused them of doing. Secondly, what good does crucifying one person do? I'm sure if they had written it such that one pe…
But still, it is not about finger pointing and blaming one individual. It is about a spokeperson for the public.
The guarantee that things will improve. Someone who will handle announcements and communications with the public and will vouch using their real name and reputation that things will improve. Someone who will explain what went wrong and what actions are taken to ensure this does not happen again. Employee training in place? Tier'ed access of data and information to employees. Stricter policies, eg you can't take a database backup home? etc etc.
Again, no crucifixation required, but pinning an identity can be good, because you know that there is someone and who that someone is that puts all their energy into fixing this mess.
Think of someone like Stamos at facebook. I don't know if his contribution in the end was a net positive or not, but it is good to know that there is someone that is focused on the issue.
Re: Quora User Data Compromised
#493Earlier quoted context omitted.
I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…
Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…
Re: Quora User Data Compromised
#494Wow. If this had happened a couple years ago, before they made all the anonymous entries truly anonymous, this would have been really ugly. It's a valuable lesson in "don't keep data you don't need". EDIT: A little backstory for non-Quorans. Until early 2017, anonymous Quora answers and comments were anonymous to the public but not actually anonymous in the database (they were still "your" entries). In early 2017 the…
Re: Quora User Data Compromised
#495https://blog.quora.com/Quora-Security-Update seems to be misleading, especially the introduction. They start with 'some user data was compromised', however, it seems that for 'approximately 100 million Quora users' – that's basically all users! – all user data was compromised … In addition, many questions remain open, for example: Which ' leading digital forensics and security firm' is working for Quora? I hope for Q…
There can only be one digital forensics and security firm in the lead, right? All of the other firms are trailing...
Re: Quora User Data Compromised
#496Re: Quora User Data Compromised
#497Earlier quoted context omitted.
Still, I would have thought it is good practice to notify your users if you leak their data to thieves. Quora did the right thing and should be applauded. As a counterexample, it seems that Newegg had a massive breach (thieves installed JavaScript that skimmed credit card numbers for weeks) in August, and even though my credit card was likely stolen, I hever heard about it from Newegg.
How did you find out they did that? Just following tech news?
Re: Quora User Data Compromised
#498Earlier quoted context omitted.
Still, I would have thought it is good practice to notify your users if you leak their data to thieves. Quora did the right thing and should be applauded. As a counterexample, it seems that Newegg had a massive breach (thieves installed JavaScript that skimmed credit card numbers for weeks) in August, and even though my credit card was likely stolen, I hever heard about it from Newegg.
Not sure why you didn't hear from Newegg, but they did send out a mass email notification with details of the breach.
Re: Quora User Data Compromised
#499I think at this point it should be standard practice to say what hashing algorithm is used in passwords when disclosing a breach. The email I got from quota just says “encrypted” passwords, and while the blog post says “hashed”, it doesn’t say what algorithm. For all we know it could be something useless like MD5
Re: Quora User Data Compromised
#500It's strange that: - the linked article says the breach included hashed passwords, but makes no mention of salt - the help page says they're forcing affected users to change their passwords If the passwords were salted before being hashed and stored, then: - Why not mention it, so users (especially those who don't use unique passwords on every site) know that it's not trivial for their password to be found? - Why for…
> the passwords were encrypted (hashed with a salt that varies for each user)
Looks like the article says the same thing.