Quora User Data Compromised
51–60 of 525 posts
Re: Quora User Data Compromised
#521. Force everyone to register to get access to content. 2. Leak that data. 3. ... 4. Profit. Not sure how this part works though. I hope lesson should be learned: don't force users to register just because you can
I see no lesson to be learned from the business perspective. If equifax can recover from their data loss, any company can.
Re: Quora User Data Compromised
#53> encrypted password I hope they mean hashed, not encrypted.
Did a double take at this too, but they clarified that it means “hashed with a unique salt” later on. Not a good word choice for a summary though!
They can rightfully say "encrypted" to a lay audience because the definition of encrypted is not so strict as to require decryptability, but why would they say that the password might be exposed?
Re: Quora User Data Compromised
#54So I'm not a security expert, so I ask this in real earnest to learn: what is it that these companies keep doing wrong, and/or why aren't they adjusting to the climate that these types of attacks are increasing over time? Or are they trying to adjust, and the attacks are getting so sophisticated that the pace of investment in counter-measures is below that of the pace of advancement in the complexity of attacks? Or s…
Re: Quora User Data Compromised
#55Re: Quora User Data Compromised
#56Earlier quoted context omitted.
I have an email address that I've only ever used as my AWS account email since many years ago. Somehow I started getting spam on it last year. It is not an address anyone could guess or somehow generate based on other data points such as name or otherwise.
Many of us who operate our own mail services use a unique email address for every web service we use. You'd be surprised how many of these unique email addresses I've received spam at (and have subsequently blackholed). I would estimate less than 50% of the associated services ever report a data breach event. I figure either there has been an unreported breach or, possibly more likely, the service sold their userlist…
Although many services are getting wise to many of these services and not let you sign up with their domains.
Re: Quora User Data Compromised
#57Re: Quora User Data Compromised
#58They are hiring people based on leet code questions and school prestige and not based on real technical knowledge about systems. Their business people are top school MBA grads with no security domain expertise. They then proceed to build massive data collection programs using open source tooling that non of them fully understand. Their business model depends on that data and monetizing it in various ways. An so the complexity of their application goes through the roof with regards to user data. Their user facing web apps are the tip of the iceberg for a massive surveillance scheme.
Re: Quora User Data Compromised
#59Earlier quoted context omitted.
Many of us who operate our own mail services use a unique email address for every web service we use. You'd be surprised how many of these unique email addresses I've received spam at (and have subsequently blackholed). I would estimate less than 50% of the associated services ever report a data breach event. I figure either there has been an unreported breach or, possibly more likely, the service sold their userlist…
Do you have any more info on running your own mail server? I looked at doing so but was promptly steered away because of blacklisting, servers that allow it and redundancy.
Well, there's the obvious comfort of having all your mail in one place -- and all the obvious disadvantages that entails, I suppose.
Re: Quora User Data Compromised
#60> encrypted password I hope they mean hashed, not encrypted.
Did a double take at this too, but they clarified that it means “hashed with a unique salt” later on. Not a good word choice for a summary though!