Live data from Hacker News

Quora User Data Compromised

blog.quora.com

501–510 of 525 posts

Re: Quora User Data Compromised

#501

Earlier quoted context omitted.

I used to use KeePass but the lack of a proper crossplatform UI eventually broke it for me; KeePassX on linux looked and performed terribly, the Android app was just bad, etc etc etc. I switched to 1password which - at least at the time - offered a web-based fallback hosted from your own dropbox. Plus at the time you owned the data and were responsible for storing and syncing it. Dropbox support came out of the box b…

Have another look at KeePass. They recently got a native Mac implementation, and I seem to recall seeing a new one for Linux at the time. On the Mac, KeePass now feels like a better experience than having to pay a subscription for 1password.

Or MacPass for macOS, which was a very slick alternative to the KeePass application at the time.

Re: Quora User Data Compromised

#502
post #292

Earlier quoted context omitted.

Same. Where do you keep the db file? Mine's in the cloud and I can't help but think it reduces security, but then I need access to this data from various locations.

I worry about this too. I store the database itself in Dropbox, and I also use a keyfile alongside the password to open it. I can easily recreate the keyfile on any computer, but it never goes anywhere near the internet. In addition to that, for my really critical "gatekeeper" accounts, I don't put the full password in the database. Just a reminder that this is a "special" password, which needs to be combined with an…

Why can't you use it on your phone? There are various apps for Keepass available.

Re: Quora User Data Compromised

#503

Earlier quoted context omitted.

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

Something about storing every password in a single cloud service to improve security sounds counterintuitive to me.

The passwords are all encrypted with the master password and ideally an additional salt such as in the case of 1password.

Re: Quora User Data Compromised

#504

Earlier quoted context omitted.

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

LastPass is one of my least liked most used tools. Everything about the implentation feels second rate; slow, unreliable login capture, unreliable form fill, occasional inability to edit records, buried password copy, clunky UI, inappropriate modal nagging in browser and app... Most times I use it I am cursing it. I tried to switch to pass, and I'm not sure if it was something to do with how I imported but it didn't…

LastPass has corporate mismanagement written all over it. It's ridiculous how bad their product is considering how big they were.

Re: Quora User Data Compromised

#505
post #148

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

Companies hate users who don't want to sign up. They do not want that relationship. So it's a win-win if you dont' sign up. Why would companies feel obligated to generate content for free? If their systems get hacked and they have your snail mail address, they get your snail mail address as well. Email doesn't change that story.

Snail mail is already gotten. I get junk mail from 8 different past tenants at my unit, and I'm sure I'm still getting junk mail at all my old addresses. Google your name right now, and I guarantee you will find your address and other personal info on one of those dime a dozen background check sites, because companies have operated under the philosophy that your phone numbers and physical addresses are public facing information that you could find in a phone book, and are free to sell or pass along.

Re: Quora User Data Compromised

#506
I hate Quora for the dark pattern practices of forcing you to login before you can see anything.

In a way this is a great example of why you shouldn’t collect data Willy nilly.

I really really really hope we get some sort of a law where companies are seriously liable for data breaches.

US has a ton of tech companies but very little regulation that protects the customer.

Re: Quora User Data Compromised

#507
post #47

Earlier quoted context omitted.

> It's a valuable lesson in "don't keep data you don't need". Unfortunately, though, most companies operate under the "keep data you might eventually need" principle.

Not anymore, at least in Europe. The GDPR began to move things in the right direction.

And based on the bellyaching from tech companies from that piece of legislation, it will remain in Europe.

Re: Quora User Data Compromised

#508
post #91

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

I use privacy.com and Lastpass to help with this problem. Any time there is a service I have to have a business relationship with that I don't trust to keep my info secure, I use a unique password and a unique credit card number with a tight limit. What's nice is that they tie the card to a single vendor too. For example, the water company. I know the water bill is usually $50 or less, so I set the limit to $60/mo. A…

Interesting. I literally don't care if my CC information is stolen from a merchant -- I have zero liability for fraudulent use on all of my cards. Why do I want the friction of privacy.com?

The one thing that is cool, for items that don't have to ship in the mail, is the ability to use any name and address whatsoever with the merchant.

Re: Quora User Data Compromised

#509
post #353

Earlier quoted context omitted.

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

I migrated over from Lastpass to Dashlane a few years ago. Couldn't be happier. It integrates with everything and as far as I understand their encryption is better than Lastpass, although I couldn't say how.

Another vote for Dashlane. The password management is stellar, it even alerts you about breaches and prompts you to change compromised passwords.

I run a unique password for every site so it doesn't matter if a provider gets rumbled, and I don't reuse passwords or have to remember multiple ones.

The form autofill is pretty awful compared to Lastpass, but I can live with that.

Re: Quora User Data Compromised

#510

Earlier quoted context omitted.

Lastpass has been going downhill with every acquisition and had gotten to the point where autofill failed on the majority of sites and the "copy password" menu item disappeared, bringing clicks-to-login from 1 to ~10. A few weeks ago I saw bitwarden finish their third party security audit and took the opportunity to jump. Couldn't be happier. Autofill fails less, the "copy password" menu works, the mobile experience…

I have been using Pass [0] with passff [1] and been pretty happy about it. Simple and offline password management where passwords live in gpg encrypted files. Additional features I like are tracking changes with git, bash completion and copying passwords to clipboard for few seconds temporarily, and a few very useful extensions. [0] https://www.passwordstore.org/ [1] https://github.com/passff/passff#readme

Pass is awesome. I use it in combination with a YubiKey to store the pgp key. Because every password is stored in an independent encrypted file and every decryption needs a press on the YubiKey even a stolen database and keylogger does not provide access to all passwords.
Post reply on HN