Live data from Hacker News

Quora User Data Compromised

blog.quora.com

81–90 of 525 posts

Re: Quora User Data Compromised

#82
post #31

Earlier quoted context omitted.

Many of us who operate our own mail services use a unique email address for every web service we use. You'd be surprised how many of these unique email addresses I've received spam at (and have subsequently blackholed). I would estimate less than 50% of the associated services ever report a data breach event. I figure either there has been an unreported breach or, possibly more likely, the service sold their userlist…

You can do this with a gmail account too. If your email address is johnsmith@gmail.com...the following addresses all fwd to your main address John.smith@gmail.com Johnsmith+quora@gmail.com Johnsmith+equifax@gmail.com Etc...

Can't the spammer just s/'\+.*@'/'@'/ or something and throw away the + sign and all that follows? Or the company could do this if they were selling your email address.

Re: Quora User Data Compromised

#83
post #29

Earlier quoted context omitted.

Did a double take at this too, but they clarified that it means “hashed with a unique salt” later on. Not a good word choice for a summary though!

They don't mention the hash function anywhere so I'm assuming MD5.

If they don't mention it you could assume any one of the commonly used hash functions.

Re: Quora User Data Compromised

#84
post #31

Earlier quoted context omitted.

Many of us who operate our own mail services use a unique email address for every web service we use. You'd be surprised how many of these unique email addresses I've received spam at (and have subsequently blackholed). I would estimate less than 50% of the associated services ever report a data breach event. I figure either there has been an unreported breach or, possibly more likely, the service sold their userlist…

You can do this with a gmail account too. If your email address is johnsmith@gmail.com...the following addresses all fwd to your main address John.smith@gmail.com Johnsmith+quora@gmail.com Johnsmith+equifax@gmail.com Etc...

I used to use this technique for many years, but occasionally ran into issues with form validators rejecting the email address. I finally stopped because I never got spam from those email addresses (even in spam folder). I figured it's trivial for spammers to strip out the extra text, any half-decent spammer should know this trick. Also, I suspected they might change the +text to put the blame on someone else.

Re: Quora User Data Compromised

#85

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

If your main concern is the sheer number of username/unique password combos, pick a good password manager that works well across the devices you use. I’ve literally stopped caring about this aspect of my family’s online life thanks to 1Password. That iOS 12 added OS level integration for the service was the icing on the cake for me.

Re: Quora User Data Compromised

#86

Barely a month back in the facebook data breach thread in HN, I was downvoted and my comment removed when I said that it has become a fashion for the top 500 web/e-com companies to come one day and announce data breach and walk away. I said there that it all looks to me as part of a conspiracy theory where they hide behind a breach to sell data/ buy data en masse for marketing purposes.

The conspiracy is mostly in your head. No sane company would do this.

Re: Quora User Data Compromised

#87
post #44

Earlier quoted context omitted.

Do you have any more info on running your own mail server? I looked at doing so but was promptly steered away because of blacklisting, servers that allow it and redundancy.

Can't recommend FastMail enough- it has aliases which automatically forward mail from xyz@alias.yourdomain.com to your alias@yourdomain.com - This is very similar in practice to the + trick with gmail[1] but with the benefit that your email addresses will pass all stupid Javascript email validation rules. [1] https://www.thewindowsclub.com/gmail-address-tricks

You can also set up wildcard aliases, e.g. I have the equivalent of *@example.com, leading to addresses like hackernews@example.com.

Re: Quora User Data Compromised

#89
post #85

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

If your main concern is the sheer number of username/unique password combos, pick a good password manager that works well across the devices you use. I’ve literally stopped caring about this aspect of my family’s online life thanks to 1Password. That iOS 12 added OS level integration for the service was the icing on the cake for me.

Agreed. I never would have thought that the problem that motivated Persona would have been solved this way... but the combination of TouchID/Face ID and 1Password has made account setup/maintenance sufficiently frictionless.

Re: Quora User Data Compromised

#90
post #85

This is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via emai…

If your main concern is the sheer number of username/unique password combos, pick a good password manager that works well across the devices you use. I’ve literally stopped caring about this aspect of my family’s online life thanks to 1Password. That iOS 12 added OS level integration for the service was the icing on the cake for me.

That's only part of it. The other part is that - invariably - they get hacked.
Post reply on HN