TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Disqus Demonstrates How to Do Breach Disclosure Right

176 pointsby Artemis2over 7 years ago

9 comments

notzorbo3over 7 years ago
&gt; They provided details - the passwords were salted SHA1 hashes which is not a pretty story to tell in this day and age, but they told it truthfully regardless<p>The leak is from 2012, which might explain SHA1 usage. It should still have been something beter, even for that time, but still.<p>Anyway, I think it&#x27;s pretty hilarious that we&#x27;re now patting companies on the back after leaking 17.5 million user details. Not that Disqus&#x27; disclosure wasn&#x27;t text book. Just that it&#x27;s now so normal for companies to leak things all over the place that we actually have Best Practices for what to do when (not if ;-) that happens.<p>Personally, I don&#x27;t register with my real name and email anymore, anywhere. It&#x27;s a bit of a pain in the ass sometimes, but worth it.
评论 #15436320 未加载
评论 #15433565 未加载
StavrosKover 7 years ago
While we&#x27;re on the subject, is there an alternative to Disqus that doesn&#x27;t load three terabytes of stuff and have all the social-engagey functionality? I just want something that does comments.
评论 #15433162 未加载
评论 #15434163 未加载
评论 #15434154 未加载
评论 #15436885 未加载
评论 #15433248 未加载
评论 #15434111 未加载
feelin_googleyover 7 years ago
&quot;Less than a day earlier, they had absolutely no idea what was coming yet they managed to pull all this together in record time.&quot;<p>How is he sure that they had no knowledge?<p>What if they knew but were just waiting for someone with a blog or a Twitter account to make the &quot;discovery&quot;?<p>In any event, none of this would have happened if email addresses had not been collected.<p>There is no need to collect email addresses in order to allow internet users to post comments. <i>Requiring</i> email addresses serves no benefit to the user. It is just more gratuitous data collection. Data which eventually becomes the subject of yet another &quot;data breach blog&quot; entry.
评论 #15435403 未加载
评论 #15436130 未加载
jlgaddisover 7 years ago
In a previous discussion here on HN, there were several folks who claimed that they were (or should have been) affected that did not receive an notification from Disqus but did receive a notification from HIBP.
评论 #15432825 未加载
评论 #15432846 未加载
ComodoHackerover 7 years ago
Would their reaction be so swift and competent if it wasn&#x27;t Troy but someone with no name?
评论 #15433231 未加载
aidosover 7 years ago
Is this correct though? I had the email from Troy saying my email was in the breach but I haven&#x27;t heard anything at all from Disqus...
评论 #15432766 未加载
DougWebbover 7 years ago
I got an email, despite never having set up an account. I was able to reset my password and delete the account though. Before I did that I looked through the profile and settings, and it was completely blank aside from my email address.<p>I&#x27;m assuming one of the many people who use my gmail address by mistake tried to sign up with it.
评论 #15433221 未加载
RachelFover 7 years ago
Perhaps it is co-incidental, but disclosing the results at 4pm EST on a Friday afternoon helps &quot;bury the bad news&quot;.<p>This ensures it falls outside the news cycle for most journalists and gets the minimum of coverage.
megousover 7 years ago
I have my mail in the breach, yet I don&#x27;t have an account.<p>Perhaps I&#x27;ve deleted my account after 2012, but don&#x27;t remember it.<p>Will be interesting to see if I receive email from them, despite not being a user anymore.