Live data from Hacker News

Quora User Data Compromised

blog.quora.com

71–80 of 525 posts

Re: Quora User Data Compromised

#71
post #31
post #20

Earlier quoted context omitted.

I have an email address that I've only ever used as my AWS account email since many years ago. Somehow I started getting spam on it last year. It is not an address anyone could guess or somehow generate based on other data points such as name or otherwise.

Many of us who operate our own mail services use a unique email address for every web service we use. You'd be surprised how many of these unique email addresses I've received spam at (and have subsequently blackholed). I would estimate less than 50% of the associated services ever report a data breach event. I figure either there has been an unreported breach or, possibly more likely, the service sold their userlist…

You can do this with a gmail account too. If your email address is johnsmith@gmail.com...the following addresses all fwd to your main address

John.smith@gmail.com

Johnsmith+quora@gmail.com

Johnsmith+equifax@gmail.com Etc...

Re: Quora User Data Compromised

#72

So I'm not a security expert, so I ask this in real earnest to learn: what is it that these companies keep doing wrong, and/or why aren't they adjusting to the climate that these types of attacks are increasing over time? Or are they trying to adjust, and the attacks are getting so sophisticated that the pace of investment in counter-measures is below that of the pace of advancement in the complexity of attacks? Or s…

In addition to what others mentioned, hackers usually got very high patience, it pays over time.

Re: Quora User Data Compromised

#73

Are there any details about how the passwords were stored? "Encrypted" is a bit questionable. I'd expect hashed.

They clarify that the passwords were indeed hashed and salted. "Encrypted" is just there to help the non-technical audience understand their passwords aren't exactly leaked in plaintext.

No details on the hashing scheme used though, so we don't really know how easy it'll be for the attacker to brute force the password hashes.

Re: Quora User Data Compromised

#74

Barely a month back in the facebook data breach thread in HN, I was downvoted and my comment removed when I said that it has become a fashion for the top 500 web/e-com companies to come one day and announce data breach and walk away. I said there that it all looks to me as part of a conspiracy theory where they hide behind a breach to sell data/ buy data en masse for marketing purposes.

Well yeah because that is stupid.

Re: Quora User Data Compromised

#75

At this point I am operating on the assumption that ALL businesses that have my data are going to inadvertently leak it at some point, and thus I am attemtping to provide individual companies with as little information about me as possible. The toughest ones here are my online banking and my online health portal, but other than that, I have gotten pretty picky about what information I give any company.

Yeah, I tag every email address I give to a vendor, and I have for years. It has helped me discover a number of breaches.

The address I gave Quora isn't in the hands of spammers yet, which is a mildly good sign. But normally it takes a while for an address to get out to the bottom-feeders, so we'll see.

Re: Quora User Data Compromised

#76
post #29

> encrypted password I hope they mean hashed, not encrypted.

Did a double take at this too, but they clarified that it means “hashed with a unique salt” later on. Not a good word choice for a summary though!

They don't mention the hash function anywhere so I'm assuming MD5.

Re: Quora User Data Compromised

#77
post #44
post #31

Earlier quoted context omitted.

Many of us who operate our own mail services use a unique email address for every web service we use. You'd be surprised how many of these unique email addresses I've received spam at (and have subsequently blackholed). I would estimate less than 50% of the associated services ever report a data breach event. I figure either there has been an unreported breach or, possibly more likely, the service sold their userlist…

Do you have any more info on running your own mail server? I looked at doing so but was promptly steered away because of blacklisting, servers that allow it and redundancy.

Can't recommend FastMail enough- it has aliases which automatically forward mail from xyz@alias.yourdomain.com to your alias@yourdomain.com - This is very similar in practice to the + trick with gmail[1] but with the benefit that your email addresses will pass all stupid Javascript email validation rules.

[1] https://www.thewindowsclub.com/gmail-address-tricks

Re: Quora User Data Compromised

#78
This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach.

One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via email. Then that disappeared and now you have to create an account on some portal so that you can download your invoice. So that's one userid/password combo per business relationship or service that you use privately. Healthcare, HOA, insurance, payroll etc., every bloody two bit player requires you to log-in to their oh-so-secure service rather than that they send you your stuff. Which requires a ton of overhead and - sure enough - sooner or later they get hacked because by then the amount of data they hold on to is more valuable than their security could reasonably be expected to defend.

Re: Quora User Data Compromised

#79
post #31
post #20

Earlier quoted context omitted.

I have an email address that I've only ever used as my AWS account email since many years ago. Somehow I started getting spam on it last year. It is not an address anyone could guess or somehow generate based on other data points such as name or otherwise.

Many of us who operate our own mail services use a unique email address for every web service we use. You'd be surprised how many of these unique email addresses I've received spam at (and have subsequently blackholed). I would estimate less than 50% of the associated services ever report a data breach event. I figure either there has been an unreported breach or, possibly more likely, the service sold their userlist…

As an anecdote to that:

I've received recruiter spam to "+fuckyouadobe@gmail.com". Turns out when I was forced to signed up for an Adobe account years ago I'd added "+fuckyouadobe" to my email and, of course, Adobe was inevitably hacked. The leaked database had somehow made its way into recruiter software. The recruiter told me their vendor and when I got in touch with them (Aevy.com) they, of course, had no idea how that email got there.

Sadly these days people are probably smart enough to strip out these additions to gmail addresses. I would guess that's what Aevy did after I reached out...

Re: Quora User Data Compromised

#80

At this point I am operating on the assumption that ALL businesses that have my data are going to inadvertently leak it at some point, and thus I am attemtping to provide individual companies with as little information about me as possible. The toughest ones here are my online banking and my online health portal, but other than that, I have gotten pretty picky about what information I give any company.

This is a healthy mindset to have. I feel that for every company that self-reports a leak, there are multiple other companies that have leaked your data and either haven't discovered the breach, refuse to disclose it, or flat out sold your data to the highest bidder.

[deleted]
Post reply on HN