Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

81–90 of 292 posts

Re: Notes on the Celebrity Data Theft

#81
post #4
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

>Dude. 1Password. Password managers only protect against certain kinds of attack. Many cloud services do not or can not properly encrypt their users' data, so having a strong password won't help in the event that your cloud provider's datacenter gets rooted.

Sure, but it'll stop rayiner from gmailing passwords to himself.

Re: Notes on the Celebrity Data Theft

#82
post #67

While I am complete appalled by the data breach and hope that similar things never happens to anyone again I would like to propose a purely thought experiment: The hacker reported sold the nude photos of Jennifer lawrence for a mere sum of $130 using bitcoin. If we apply game theory here, these kind of data is very difficult to monetize. If you sell one copy of the data, it is then immediately distributed online for…

[deleted]

> Preventing the oracles from colluding to prematurely release the keys, or not release the keys at all, is a harder problem.

No, the harder problem is knowing the "encrypted" data is something other than a directory of the sellers favorite goat-porn. A cut and choose proof could be used, but non-interactive ones require a lot of samples to have good security... and revealing a lot of sample images is something the seller doesn't want to do here.

To put that in concrete terms: Say I claim have a million nudes of Elmo which you'd like to purchase. I give you an encrypted copy of them. You pick some number at random, and I reveal the keys. You decrypt and get find all of them to be fine examples of the promised images of Elmo in all Elmo's glory. You are now convinced that it is likely that the rest of the images are similar— since your selection was uniform you can use simple combinitorics to how likely I would have been to get away with various levels of fraud. "That tickles"

To make this protocol non-interactive with a fiat-shamir transform— I hash the encrypted pictures and use the hash to select which ones I reveal. This requires many more examples to achieve security because I could have been secretly grinding one of the images until the hash picked the few passing examples I had. (There are, however, ways too boost the security by inserting an expensive process— like giving away Bitcoins— into the inner loop).

It's likely not reasonable for a collection of just a few dozen images, even with strengthening, however.

For machine decidable things— say a DRM master key— other approaches are possible (https://en.bitcoin.it/wiki/Zero_Knowledge_Contingent_Payment) but since no one is likely to turn up a program that decides nudes of one celebrity vs another, about the best you could do is a non-interactive cut and choose selective reveal over _pixels_, and use compressed sensing techniques to build low res images to decide if the rest of the pixels are worth paying for. If you're happy with that, then at least theoretically, the ZKCP approach lets you pay for the keys for the rest of the pixels with no risk of being stood up and no third parties.

Re: Notes on the Celebrity Data Theft

#83
post #28

Earlier quoted context omitted.

Are we still unable to move past this pedantic hosting-vs-linking nitpicking? It's like you willfully ignore how content discovery works on the Internet.

Just to be pedantic: By the same logic, Google is also grossly hosting tonnes of illegal material.

The differentiation is knowledge & intent. Nobody types in random photo GUIDs after the imgur url to find content, just like nobody generates SHA-1 hashes hoping to find valid magnet links. Users follow a route of links through search engines and content aggregators to find what they're looking for. Look, I know it's easy to take this whole issue to ridiculous logical extremes[0], but the argument that you don't have culpability by hosting links is really, really weak.

To head off the probable route this discussion will take, linking to Google or Reddit as a whole does not incur the same culpability as those sites do by linking directly to the material, as finding the offending link requires additional knowledge. If you linked to Reddit along with instructions like "go to and click the third-highest link for the week" then it would incur culpability as it's functionally identical to linking to the content directly.

[0] http://en.wikipedia.org/wiki/Illegal_number

Re: Notes on the Celebrity Data Theft

#84
post #21

I use strong passwords generated by 1Password for everything.. except for iCloud. There I have an idiot password. Why? Because freaking iPhone asks for that when I want to download something from App Store. How do you guys handle that?

Check out PasswordPilot on jailbroken devices :)

Re: Notes on the Celebrity Data Theft

#85
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

I'm sure it is useful, except for when 1Password attacks take place.

1Password is not a cloud service.

Re: Notes on the Celebrity Data Theft

#86
post #3
post #2

I wrote this in the other thread on the leak before it died: > Even if the leaks result from one at a time social engineering, it still really calls into question the practical security of the cloud. I doubt it's much harder to steal, e.g. confidential business documents from executives' cloud accounts than it is to steal pictures from celebrities' cloud accounts. > If I were a big organization with confidential info…

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

I got screwed by a password manager that got deleted during upgrading a hard drive. Never again

Re: Notes on the Celebrity Data Theft

#87
So if I'm understanding this from a technical perspective, the real story is that this is/has been going on for quite some time, and there's an entire ecosystem devoted to it. The general public rarely ever sees behind the curtain, but somebody got greedy in this case and we ended up in a race to the bottom.

If true, interesting that such a layered economic structure can exist without much press or public comment -- until something like this happens.

Fascinating. Makes you wonder what percent of the total activity these 100+ celebrity invasions represent.

Re: Notes on the Celebrity Data Theft

#88
post #78

> Password reset is answering the date of birth and security question challenges (often easy to break using publicly available data – birthdays and favorite sports teams, etc. are often not secrets) I really dislike this trend of "personal questions" to reset your password. The first car I owned or where I'd like to retire is easily obtained information. When are websites going to stop doing this? I answer these ques…

What about just using a basic cipher for your questions? It is what I do. So if the question is "What was your first car?"

Answer could be: Ford

Instead it is Enqc or droF or Gpse

Re: Notes on the Celebrity Data Theft

#89
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

aka 1PointOfFailure. Having spent several years maintaining and repairing computer systems for corporate and professional clients, I can tell you from experience that it is trivially easy to social engineer someone's credentials out of them.

AKA 1FailureToUnderstandTheThreatVector, the common antisecurity argument of lazy or pedantic people. A password manager is not defending against a social engineering attack (how could it?), it's defending against Joe's Blog getting knocked over and your re-used password on Wells Fargo being disclosed.

Your comment is a really lame excuse for not using a password manager and is quite a bit of FUD; there is no technical solution to a social engineering attack, so it's a clever way out as an excuse to avoid doing something difficult. You are not the first person to try it on me. You also sound like you're making the case for social engineering control of their machine, at which point what does the password manager matter? You have physical. Game over.

I have this conversation regarding self-signed certificates and MD5 hashing as well. "But they don't authenticate," or "but MD5 is insecure!" Yep, I know. Do you understand the threat vector for my usage of either? You sure?

Just use one. Seriously.

Re: Notes on the Celebrity Data Theft

#90
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

While I think using password managers with random passwords is far better than sharing the same password between every account, I've never really gotten comfortable with storing passwords in a file on my computer. What I'd really like is a password manager hardware dongle of some kind, like the Bitcoin Trezor wallet.

I find myself suggesting this to people often, but I'm excited about the Mooltipass[0], an offline password keeper crowd developed on Hackaday. Hope to get one when they've ironed out the bugs and finally move to random passwords.

[0] http://hackaday.io/project/86-Mooltipass

Post reply on HN