TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Quora User Data Compromised

1254 点作者 joebeetee超过 6 年前

83 条评论

dang超过 6 年前
<a href="https:&#x2F;&#x2F;help.quora.com&#x2F;hc&#x2F;en-us&#x2F;articles&#x2F;360020212652" rel="nofollow">https:&#x2F;&#x2F;help.quora.com&#x2F;hc&#x2F;en-us&#x2F;articles&#x2F;360020212652</a> contains more detail.
jacquesm超过 6 年前
This is why I hate companies that force you to sign up to gain access to content. I do not <i>want</i> that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach.<p>One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via email. Then <i>that</i> disappeared and now you have to create an account on some portal so that you can download your invoice. So that&#x27;s one userid&#x2F;password combo per business relationship or service that you use privately. Healthcare, HOA, insurance, payroll etc., every bloody two bit player requires you to log-in to their oh-so-secure service rather than that they send you your stuff. Which requires a ton of overhead and - sure enough - sooner or later they get hacked because by then the amount of data they hold on to is more valuable than their security could reasonably be expected to defend.
评论 #18595495 未加载
评论 #18598575 未加载
评论 #18595974 未加载
评论 #18596045 未加载
评论 #18595465 未加载
评论 #18598154 未加载
评论 #18597192 未加载
评论 #18598247 未加载
评论 #18598288 未加载
评论 #18595821 未加载
评论 #18596991 未加载
评论 #18598752 未加载
评论 #18597307 未加载
评论 #18596025 未加载
评论 #18606445 未加载
评论 #18596705 未加载
评论 #18595960 未加载
评论 #18597921 未加载
评论 #18596181 未加载
throwaway66666超过 6 年前
In 2013 a quora moderator contacted me and demanded that I provide my real name, and information that my name is real or they would ban my account. I tried reasoning with them, that I just wanted to view content and did not attend to write answers or interact etc, plus, they had a valid email address and facebook profile (also fake name on facebook). They fought back &quot;we actually want proof of your real name like a scan of ID&quot;. I danced around and did not end up giving them a scan of my id, but I changed it to my real name.<p>Today my information is probably leaked. Information I didn&#x27;t want to give and that they threatened me for it.<p>Where is the apology Quora? From all the recent leaks this is the one that pisses me off the most, because it&#x27;s the one that was forced unto me.
评论 #18599545 未加载
评论 #18600589 未加载
评论 #18598291 未加载
评论 #18597669 未加载
评论 #18597749 未加载
评论 #18598147 未加载
评论 #18597951 未加载
评论 #18600700 未加载
评论 #18598248 未加载
评论 #18598185 未加载
评论 #18597635 未加载
评论 #18600935 未加载
评论 #18600670 未加载
评论 #18597870 未加载
orliesaurus超过 6 年前
I really started hating Quora a while back, probably 3 years ago and stopped collaborating. Most because &quot;people&quot; were spamming answers with marketing bs... So many answers start with &quot;I&#x27;m Bob, CEO of MyCompany.com, I am an expert in this and that&quot;<p>Most Quora users are hungry for answers and flood-request you to answer their question just because the system recommends them to do so. No matter how many times you pass, the system still keeps notifying you that &quot;you are needed&quot;. Quora doesn&#x27;t understand a no is a no.<p>IMHO -&gt; There truly isn&#x27;t any benefit on providing good answers on Quora, other than stroking your ego, might as well become a micro-influencer on Instagram.<p>Even worse most questions seem truly 1-Google search away and the answers are low-effort. Sure you do have some rare gems, and those are truly amazing to read. Alas, that&#x27;s not often and spamming answers just for the sake of answering has become a reality.
评论 #18599018 未加载
评论 #18598258 未加载
评论 #18600037 未加载
评论 #18599289 未加载
stickfigure超过 6 年前
Wow. If this had happened a couple years ago, before they made all the anonymous entries truly anonymous, this would have been <i>really</i> ugly.<p>It&#x27;s a valuable lesson in &quot;don&#x27;t keep data you don&#x27;t need&quot;.<p>EDIT: A little backstory for non-Quorans. Until early 2017, anonymous Quora answers and comments were anonymous to the public but not actually anonymous in the database (they were still &quot;your&quot; entries). In early 2017 they (presciently) made all this content fully anonymous, even in the database.
评论 #18594967 未加载
评论 #18595123 未加载
评论 #18602724 未加载
评论 #18603532 未加载
评论 #18594955 未加载
评论 #18595497 未加载
throwaway292939超过 6 年前
I feel that this is becoming a standard narrative. SV company comes up with an idea, decides harvesting lots of user data is how they will monetize. VCs pump in a lot of money and expect their returns, so company is now forced to collect even more data aggressively (the sign-in wall that many others have pointed out is an example of this). VC pressure causes company to &quot;innovate&quot; fast, most likely trading off security for new features in the meantime. As this progresses and they become more valuable, they are then targeted by hackers, which causes some type of compromise of users&#x27; data.<p>Quora is an intimate medium — tied to real names, real and often deep interests. It&#x27;s especially bad that this happened.<p>There needs to be a better way to realign incentives in this ecosystem, otherwise this story will repeat.
评论 #18596434 未加载
评论 #18602515 未加载
sharkweek超过 6 年前
At this point I am operating on the assumption that ALL businesses that have my data are going to inadvertently leak it at some point, and thus I am attemtping to provide individual companies with as little information about me as possible.<p>The toughest ones here are my online banking and my online health portal, but other than that, I have gotten pretty picky about what information I give any company.
评论 #18594962 未加载
评论 #18595407 未加载
评论 #18602040 未加载
评论 #18595509 未加载
评论 #18595097 未加载
评论 #18594901 未加载
评论 #18597871 未加载
评论 #18594989 未加载
评论 #18595383 未加载
评论 #18595331 未加载
评论 #18595011 未加载
chmars超过 6 年前
<a href="https:&#x2F;&#x2F;blog.quora.com&#x2F;Quora-Security-Update" rel="nofollow">https:&#x2F;&#x2F;blog.quora.com&#x2F;Quora-Security-Update</a> seems to be misleading, especially the introduction. They start with &#x27;some user data was compromised&#x27;, however, it seems that for &#x27;approximately 100 million Quora users&#x27; – that&#x27;s basically all users! – all user data was compromised …<p>In addition, many questions remain open, for example: Which &#x27; leading digital forensics and security firm&#x27; is working for Quora?<p>I hope for Quora that they met their 72-hour deadline according to the GDPR. Looking at <a href="https:&#x2F;&#x2F;www.quora.com&#x2F;about&#x2F;privacy" rel="nofollow">https:&#x2F;&#x2F;www.quora.com&#x2F;about&#x2F;privacy</a>, it does not look if Quora was &#x2F; is GDPR-ready. They do not mention any legal basis for the processing (art. 13 GDPR) and they do not inform about their GDPR data representative in the EU (art. 27 GDPR).
评论 #18597661 未加载
评论 #18598333 未加载
MattBearman超过 6 年前
I think at this point it should be standard practice to say <i>what</i> hashing algorithm is used in passwords when disclosing a breach.<p>The email I got from quota just says “encrypted” passwords, and while the blog post says “hashed”, it doesn’t say what algorithm. For all we know it could be something useless like MD5
评论 #18599267 未加载
评论 #18603869 未加载
s3r3nity超过 6 年前
So I&#x27;m not a security expert, so I ask this in real earnest to learn: what is it that these companies keep doing wrong, and&#x2F;or why aren&#x27;t they adjusting to the climate that these types of attacks are increasing over time?<p>Or are they trying to adjust, and the attacks are getting so sophisticated that the pace of investment in counter-measures is below that of the pace of advancement in the complexity of attacks?<p>Or something in the middle?
评论 #18595096 未加载
评论 #18595375 未加载
评论 #18596866 未加载
评论 #18595200 未加载
评论 #18595090 未加载
评论 #18595234 未加载
评论 #18595393 未加载
评论 #18595544 未加载
评论 #18600252 未加载
评论 #18595750 未加载
评论 #18596662 未加载
评论 #18595197 未加载
评论 #18595398 未加载
Jedd超过 6 年前
It&#x27;s genuinely hard to imagine a second-rate question and answer site could have any credentials, or indeed any non-public content, that anyone else could be interested in. From the list of what&#x27;s been taken, it sounds like it&#x27;s mostly email and hashed passwords, though I suspect Quora&#x27;s user base is not entirely populated by people committed to a strict one-off password policy.<p>Happily I get to once again bemoan the disappearance of JCSV, who was astounded that Quora was still a thing five years ago: <a href="http:&#x2F;&#x2F;jesuschristsiliconvalley-blog.tumblr.com&#x2F;post&#x2F;48962035819&#x2F;quoraquoraquora" rel="nofollow">http:&#x2F;&#x2F;jesuschristsiliconvalley-blog.tumblr.com&#x2F;post&#x2F;4896203...</a>
abraae超过 6 年前
The Quora link to more details is a masterpiece of corporate obfuscation. Posing as a FAQ, it presents questions, then proceeds to not answer them (at least, as of a few minutes ago).<p><a href="https:&#x2F;&#x2F;help.quora.com&#x2F;hc&#x2F;en-us&#x2F;articles&#x2F;360020212652" rel="nofollow">https:&#x2F;&#x2F;help.quora.com&#x2F;hc&#x2F;en-us&#x2F;articles&#x2F;360020212652</a><p>What happened? - not answered in any detail<p>What kind of user data was affected? - answered!<p>How do I know if I was affected? - not answered<p>How was it brought to your attention? - not answered<p>How many Quora users are affected? - not answered
评论 #18596322 未加载
manigandham超过 6 年前
Seems like a complete database exfiltration. Quora advertisers also had info compromised from a separate email notice:<p><pre><code> - Account information available on the Ads Manager account settings page. - The email address provided for notifications about your ad campaigns. - Campaign structure and setup, including information like budgets, schedule, bids, targeting, and ad information. - Notifications that were in your Ads Manager, such as ad paused, logo approved, and ad ready. - Audience setup information available on the Ads Manager audience page such as types and creation date. - Partial credit card information, including name, expiration date, and the last four digits of the credit card.</code></pre>
niuzeta超过 6 年前
No system is breach-proof; security breaches happen. We as engineers should strive to reduce the break-ins and diligently push for high standards nevertheless.<p>Having said that, this is pretty much a perfect response to the situation.<p>1. Quick turnaround from the breach to the announcement 2. Concise description of what happened 3. Owning the mistake 4. Update of their mitigation 5. Promise to follow up &amp; actionable items. 6. Additional technical detail for more interested: <a href="https:&#x2F;&#x2F;help.quora.com&#x2F;hc&#x2F;en-us&#x2F;articles&#x2F;360020212652" rel="nofollow">https:&#x2F;&#x2F;help.quora.com&#x2F;hc&#x2F;en-us&#x2F;articles&#x2F;360020212652</a><p>It sucks that this happened, but for that alone I&#x27;d like to applaud Quora team. Yes, it would&#x27;ve been <i>great</i> if they didn&#x27;t have to force me to sign up from the first place. It would&#x27;ve been great if this breach has never happened. But for the context, they&#x27;re handling the issue as well as possible.
ulfw超过 6 年前
This is all bullshit. My data is all over the place. At this point I expect none of my personal data to be private. This last few weeks alone my data was stolen from British Airways, Cathay Pacific, SPG&#x2F;Mariott, Quora. As users we are completely powerless.<p>Time for change. Time for intelligent heads to come together and think of how a better internet security architecture needs to look like.
评论 #18600011 未加载
评论 #18598550 未加载
brad0超过 6 年前
Exposed Data:<p>---<p>Based on what we have learned, some of our users’ information has been exposed, including:<p>- Account information (e.g. name, email address, encrypted password, data imported from linked networks when authorized by users)<p>- Public content and actions (e.g. questions, answers, comments, upvotes)<p>- Non-public content and actions (e.g. answer requests, downvotes, direct messages)<p>Questions and answers that were written anonymously are not affected by this breach as we do not store the identities of people who post anonymous content.
评论 #18594845 未加载
EamonnMR超过 6 年前
I always found Quora&#x27;s demand that I make an account merely to read, like Pinterest, extremely rude. I don&#x27;t think I ever gave in and made an account but I suppose I can find out now.
bigiain超过 6 年前
Interesting (to me, at least) that the regular Quora update emails land in my inbox (or in the Social tab in Gmail, anyway), but the security breach notification was spam filtered...
评论 #18595004 未加载
gwbas1c超过 6 年前
I recently got an email from Quora, &quot;you read XXX, did you find what you&#x27;re looking for?&quot;<p>I don&#x27;t want every site that I visit sending me an email every time I click on a Google result.<p>I hit that SPAM button as fast as I could.
antirez超过 6 年前
That&#x27;s lame, but there is to always remember that information leaks are happening in almost every company out there. The way we build and run systems is no adequate, unless very large efforts (like in the case of Google) are made in order to try to limit the attack exposure, but this is not for everybody cost-wise IMHO. Makes more sense for companies to limit the amount of data they ingest. In this regard it&#x27;s very bad that Quora or Linked-In force you to login just to see content. As a user, if you want to live under correct expectations, assume that your real name and profile picture, and possibly an hashed password, are always automatically leaked.
breckuh超过 6 年前
&gt; ...there’s little hope of sharing and growing the world’s knowledge if those doing so ... cannot trust that their information will remain private.<p>Here&#x27;s a crazy idea, circa 1990&#x27;s: don&#x27;t store their personal information! Allow people to browse Quora without using their real names. I&#x27;m very happy I deleted my Quora account when I did.
评论 #18597443 未加载
thwy12321超过 6 年前
My take on Quora and business like them:<p>They are hiring people based on leet code questions and school prestige and not based on real technical knowledge about systems. Their business people are top school MBA grads with no security domain expertise. They then proceed to build massive data collection programs using open source tooling that non of them fully understand. Their business model depends on that data and monetizing it in various ways. An so the complexity of their application goes through the roof with regards to user data. Their user facing web apps are the tip of the iceberg for a massive surveillance scheme.
评论 #18596595 未加载
Bucephalus355超过 6 年前
One thing I would like to do is have various US Senators send letters to the major corporations, and perhaps even large open source groups (like npm), and ask them, proactively, what they are doing to secure citizens around the world&#x27;s data.<p>There is something called the Cybersecurity Bipartisan Caucus in the US Senate.<p>I have found calling these senators (which I have never done before for any politician about anything) extraordinarily helpful and gratifying. I have even explained that I don&#x27;t live in their state, and yet they still listen and clearly need the advice from good security&#x2F;sysadmin people (like asking them why Facebook still doesn&#x27;t have a CSP Security Header).<p>It was only 6 days ago that the &quot;International Committee on Privacy&quot;, made up of Senators from countries around the globe, met in London to question Richard Allan, VP of Privacy at Facebook. Mark Zuckerberg rejected the request for his attendance.<p>[1] <a href="https:&#x2F;&#x2F;www.warner.senate.gov&#x2F;public&#x2F;index.cfm&#x2F;cybersecurity" rel="nofollow">https:&#x2F;&#x2F;www.warner.senate.gov&#x2F;public&#x2F;index.cfm&#x2F;cybersecurity</a><p>[2] <a href="https:&#x2F;&#x2F;www.parliament.uk&#x2F;business&#x2F;committees&#x2F;committees-a-z&#x2F;commons-select&#x2F;digital-culture-media-and-sport-committee&#x2F;news&#x2F;grand-committee-evidence-17-19&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.parliament.uk&#x2F;business&#x2F;committees&#x2F;committees-a-z...</a><p>[3] <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=1P97ubLDbJI" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=1P97ubLDbJI</a>
rahimnathwani超过 6 年前
It&#x27;s strange that:<p>- the linked article says the breach included hashed passwords, but makes no mention of salt<p>- the help page says they&#x27;re forcing affected users to change their passwords<p>If the passwords were salted before being hashed and stored, then:<p>- Why not mention it, so users (especially those who don&#x27;t use unique passwords on every site) know that it&#x27;s not trivial for their password to be found?<p>- Why force people to change their passwords?
评论 #18603960 未加载
mindcrime超过 6 年前
The folks asking for snail mail are joking right? Snail mail is an obsolete relic of a time gone by, and belongs in the dust-bin of history alongside buggy whips, wood fired steam engines, betamax, etc.<p>Personally I&#x27;d pay to be able to <i>stop</i> getting snail mail. If it weren&#x27;t for the one or two rare pieces of semi-important crap that show up, sent by dinosaurs that don&#x27;t realize we aren&#x27;t living in the 20th century anymore, I&#x27;d quit checking my physical mailbox once and for all. I mean, it&#x27;s not like 99&#x2F;100&#x27;ths of what comes in there isn&#x27;t junk catalogs, fundraising letters from politicians I hate, sales flyers from stores I hate, bills that I pay online already, mail meant for the previous residents, etc. But unlike email spam, it actually costs me effort to scrape that garbage out of the box and haul it to the dumpster.<p>Blech. Personally, I want no part of it.
cornstalks超过 6 年前
&gt; encrypted password<p>I hope they mean hashed, not encrypted.
评论 #18595032 未加载
评论 #18598585 未加载
spike021超过 6 年前
&gt;I didn’t know I had a Quora account. How is it that my email or information was exposed? You may have signed up for Quora some time ago. While you might not have regularly visited or used Quora, your account remained, and this breach may have exposed some of your information, such as the email address you signed up with, the password you used, or actions you took on Quora.<p>Would be nice if websites measured user activity and could &#x27;lock out&#x27; or otherwise release their data if they never use the site; at least, confirm with said user via email if the account is needed.<p>But in this era, I&#x27;m sure companies would prefer to keep whatever data they can get.
评论 #18595798 未加载
MagicPropmaker超过 6 年前
In other cases customers have had trouble filing individual lawsuits for damage because the companies successfully argue that the information--usually credit information--doesn&#x27;t belong to them, it belongs to the credit card companies.<p>However, in this case, there is no credit card information to muddle up or confuse a case. It&#x27;s only a users personal information--private messages, moderator requests, reports against other users--that has been compromised because they didn&#x27;t collect credit card info. And there&#x27;s an enforced &quot;real names&quot; policy that makes it identifiable.
xiphias2超过 6 年前
From reading the details it looks like almost all user data (and every user&#x27;s data) is compromised. Using the word ,,some&#x27;&#x27; should be illegal in this instance.
sn41超过 6 年前
Is Quora legally liable for compromised data? Making companies legally liable for compromised data might be one way for them to be scrupulous about minimal data retention.
skilled超过 6 年前
Actually, I was looking at an answer last night and couldn&#x27;t see it because my account was logged out. This happens on Chrome from time to time, so I didn&#x27;t think much of it. But, when trying to log back in it said my password was incorrect. This was before the announcement.<p>I wonder if some had their details reset altogether? Either way, this looks like a major breach considering the value of people who have signed up with Quora.
productdev超过 6 年前
Quora would not allow you to read multiple answers by clicking on &quot;similar questions&quot; (on the side) without creating an account.<p>And then this happens!
评论 #18595184 未加载
bogomipz超过 6 年前
The post states:<p>&gt;&quot;We recently discovered that some user data was compromised as a result of unauthorized access to one of our systems by a malicious third party.&quot;<p>&quot;Some user data&quot;<p>Then goes on to say:<p>&gt;&quot;For approximately 100 million Quora users, the following information may have been compromised:<p>Account information, e.g. name, email address, encrypted (hashed) password, data imported from linked networks when authorized by users Public content and actions, e.g. questions, answers, comments, upvotes Non-public content and actions, e.g. answer requests, downvotes, direct messages (note that a low percentage of Quora users have sent or received such messages)&quot;<p>Wouldn&#x27;t this be closer to &quot;all user data was compromised&quot;?<p>It seems absurd for them to state &quot;some user data was compromised.&quot; That&#x27;s seems like a pretty comprehensive list of user data. What else would there be?<p>This is a company that for years forced account sign up and obscured user generated content even for users who just wanted to browse unless you created an account. Seriously fuck Quora.
pandler超过 6 年前
I&#x27;ve started keeping a log of all information I provide to a company: addresses, phone numbers, names, social security number, etc... I started doing it just to keep track of everywhere I need to update next time I change address, phone, cards, and emails at the same time[1], but it&#x27;s been eye opening to watch the list grow.<p>I think of it as something like a reverse password manager; instead of &quot;here&#x27;s a website, what&#x27;s my data&quot;, it&#x27;s &quot;here&#x27;s a bit of information about myself, who has it?&quot;<p>It&#x27;s a pain keeping that list updated but at this point I&#x27;m so hooked on being able to see my personal info leak out into the world bit by bit that the friction is worth it.<p>I&#x27;m still trying to figure out what I should do with the data I have on myself, if anyone has any suggestions.<p>[1] That situation seems sketchy seeing it written down like that, so just want to explain that it&#x27;s because I moved to a different country (address, phone, credit cards) and away from gmail at the same time.
the_clarence超过 6 年前
How were the passwords hashed? Wait. You know what? At this point it doesn’t matter. Using the same password everywhere is a broken concept and password managers are still unadopted. At this point the only solution is either SSO from a few point of trust (facebook, google, twitter, etc.) or&#x2F;and password managing+generation by default (safari, iOS)
评论 #18597302 未加载
throwawayquora超过 6 年前
Are there any details about how the passwords were stored? &quot;Encrypted&quot; is a bit questionable. I&#x27;d expect hashed.
评论 #18595399 未加载
nojvek超过 6 年前
I hate Quora for the dark pattern practices of forcing you to login before you can see anything.<p>In a way this is a great example of why you shouldn’t collect data Willy nilly.<p>I really really really hope we get some sort of a law where companies are seriously liable for data breaches.<p>US has a ton of tech companies but very little regulation that protects the customer.
tschellenbach超过 6 年前
I&#x27;ve always been impressed with Quora&#x27;s engineering team. Kinda curious what slipped passed them.
tlow超过 6 年前
This is seriously distressing. This underscores the reasons why you should never use a third party messaging system for any sort of private conversations.<p>Why is this so easy? Is it impossible for a well-funded company to keep it&#x27;s user information private? If so, can we act like it?
iharhajster超过 6 年前
Several friends and I had our Steam passwords stollen. Lesson I learned was not to have same password to more than one service because gmail account was hijacked too. The perpetrator stopped at changing gmail language to Polish, thank God. But, damage he&#x2F;she could have done was much greater. It was before &quot;login attempt from unknown location&quot; messages. It was a drag to bring all back but we did it. The lesson also is: joining any online service&#x2F;site we must accept the risk anything you provide could be stollen at some point and modify our usage phylosophy of these services.
评论 #18596974 未加载
Cyclone_超过 6 年前
This is another reason why I don&#x27;t like the &quot;social logins&quot;. You give them so much data. They strongly encourage you to use the social login instead of using the regular email sign up.
评论 #18597355 未加载
josefresco超过 6 年前
I received an email from Quora informing me of the breach, but I do not have an account. I even used the &quot;Forgot Password&quot; function to confirm - why did I receive this email?
z0r超过 6 年前
Bruce Schneier says data is a toxic asset. He&#x27;s right. There should be (will be?) laws preventing collection of most data, and punitive liability when collected data is breached.
rv-de超过 6 年前
&gt; While the passwords were encrypted (hashed with a salt that varies for each user), it is generally a best practice not to reuse the same password across multiple services, and we recommend that people change their passwords if they are doing so.<p>According to my trusted Password Safe (<a href="https:&#x2F;&#x2F;pwsafe.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;pwsafe.org&#x2F;</a>) I call about 400 accounts my own - each one with a unique random password.
abbot2超过 6 年前
1. Force everyone to register to get access to content. 2. Leak that data. 3. ... 4. Profit. Not sure how this part works though.<p>I hope lesson should be learned: don&#x27;t force users to register just because you can
评论 #18595088 未加载
King-Aaron超过 6 年前
I somehow got added into the Quora ecosystem some time back, without even actually signing up from memory. Just one day I&#x27;m getting notifications that someone is talking to me on Quora.<p>Even though I didn&#x27;t explicitly set up an account, it seemed to have done it for me already. I just assumed it was one of those shitty content aggregation platforms like the sorts that steal all the posts from Stackoverflow and rebrand them.
ausjke超过 6 年前
From now on, I will assume all my user-data will be compromised, we need a new way to store the user-data, it will be a balance of convenience and security, but more importantly, it needs to be temporal, i.e. the use-data shall not be static anymore, something like a virtual and temporarily generated password for each session?
blablabla123超过 6 年前
It&#x27;s quite obvious that Quora doesn&#x27;t care a lot about user data. Just for looking at the website, you need to login with Facebook and in fact other users could at some point even see which parts of the site you browse to without informing you. Kind of sucks, luckily deleted my account half a year ago.
thosakwe超过 6 年前
Is it really that hard to keep a database secure?<p>Genuine question - not sarcasm. I would love to know how the attackers got in in the first place.<p>Usually when I hear about a breach, my first reaction is “yeah, I would have covered that from the start,” but if there’s something to be learned here, I’m all for it...
评论 #18596336 未加载
revskill超过 6 年前
What&#x27;s bad about Quora website is that, whenever you see Answer notification, when you click on it, instead of a popup for quick review, the website will go to new url for the answers. That&#x27;s why i don&#x27;t use Quora much these days due to the stupid UX.
reitanqild超过 6 年前
Feels good to have left Quora and gotten confirmation that they&#x27;d wiped my account shortly after they hit mainstream. (Cannot remember exactly what happened but I think they defaulted to showing every question I visited in my public timeline or something.)
peter303超过 6 年前
The game of large numbers: so hackers obtain a million passwords. How with they decide to waste their time on any of them? In Quora&#x27;s case that requires real identities and institutional affiliations will they go after the cream of the crop then?
pavanlimo超过 6 年前
Clearly this is well orchestrated and professional. I&#x27;m wondering what could be the motivation for such an attack. There is no monetary benefit whatsoever. Perhaps some AI company wanting to acquire solid data to train their models?
评论 #18596497 未加载
评论 #18596504 未加载
NietTim超过 6 年前
I didn&#x27;t even know I had a quora account. Never continuously registered one. Got the e-mail though. Tried to log in, had to &quot;complete my account&quot; before I could go on.....wtf.... I deleted my account now, tho.
评论 #18599095 未加载
评论 #18599114 未加载
MrStonedOne超过 6 年前
No mention of hashing algorithm for passwords, so until they provide that info, I would just assume they hashed with unsalted md5 or sha1 or even crc, and treat it as if they had stored them in plain text.
rblion超过 6 年前
I haven&#x27;t used Quora in over a year. It&#x27;s been overrun with gurus.
magnamerc超过 6 年前
The solution to data security is incorporating security at the base layer, i.e. <a href="https:&#x2F;&#x2F;universallogin.io&#x2F;" rel="nofollow">https:&#x2F;&#x2F;universallogin.io&#x2F;</a>
sambe超过 6 年前
Is there an email notifying all users of the incident and a separate email notifying those affected, or just one?<p>Many companies seem to use intentionally vague wording to suggest you might not have to worry.
评论 #18596751 未加载
wenbin超过 6 年前
This is the email that they sent to users: <a href="https:&#x2F;&#x2F;nfil.es&#x2F;w&#x2F;kHYd7t&#x2F;" rel="nofollow">https:&#x2F;&#x2F;nfil.es&#x2F;w&#x2F;kHYd7t&#x2F;</a>
CiPHPerCoder超过 6 年前
&gt; Account information (e.g. name, email address, encrypted password, data imported from linked networks when authorized by users)<p>Quora encrypted passwords instead of hashing them? FAIL.
Chazprime超过 6 年前
I think we’re at a point where it’s safe to assume most of our data can be collated into a frighteningly thorough profile of our lives for anyone on the internet to see.
buboard超过 6 年前
Not gonna shed a tear for the self-important people who wanted to slap their wisdom on everyone signed with their real name. It&#x27;s as much a failure of quora as it is their own.<p>Anyone remember the glory days of facebook , when real names were &quot;revolutionary&quot; and all the rage? Quora followed that cargo cult (founded by facebook people, after all) and the consequences of that choice are due today. We really need to introduce the concept of &quot;expiring data&quot; on the internet, personal or not. After a reasonable amount of inactivity, identities shuold be anonymized.
jcampbell1超过 6 年前
They need to release their hashing algorithm. If it is some sha1+salt nonsense, then they have exposed plaintext passwords for most of these people.
axiom92超过 6 年前
<a href="https:&#x2F;&#x2F;xkcd.com&#x2F;1269&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkcd.com&#x2F;1269&#x2F;</a><p>Just be a nihilist, guys.
评论 #18595672 未加载
mychael超过 6 年前
I&#x27;m angry at them for this, but more angry at myself for not deleting my data years ago when I stopped logging in.
评论 #18595818 未加载
fouric超过 6 年前
Does Quora still have a real name policy?
评论 #18596678 未加载
lmilcin超过 6 年前
&quot;encrypted (hashed) passwords&quot;<p>Was it hashed AND encrypted or another case of people not understanding the difference?
评论 #18597211 未加载
Jenz超过 6 年前
This is Why I’ve gone over to using a proper password manager, with unique passwords for all accounts
break_the_bank超过 6 年前
Can anyone explain how is Quora still relevant? How did they raise the $85M for their series D only last year?<p>To me it seems its going the way of Yahoo Answers, if it already hasn&#x27;t. It might be gaining some traction in developing countries but the ratio of signal:noise seems really low at this time, coupled with terrible UI.
sombragris超过 6 年前
No announcement for me, but I cannot login no matter what I try.
zerop超过 6 年前
This is one reason I dont write anonymous answers on Quora....
robbiemitchell超过 6 年前
Advertisers had their campaign data compromised, too. Yeesh.
steve1977超过 6 年前
Maybe they asked how to do website security on Quora...
rishikeerthi超过 6 年前
Is anonymous question or answers also compromised?
onion-soup超过 6 年前
This is why services like metamask will take over
sj4nz超过 6 年前
This was a nice reminder to delete my account.
snek超过 6 年前
quora already sells your data to as many third parties as possible... i don&#x27;t suspect this changes much.
foobarbecue超过 6 年前
And now they&#x27;re 504ing...
nistak04超过 6 年前
can they ask if their data was compromised on the question&amp;answer site?
dreyfiz超过 6 年前
I&#x27;m experiencing a sense of schadenfruede because I&#x27;m embittered by Quora&#x27;s arrogant &quot;real names&quot; policy. They won&#x27;t &quot;let me&quot; contribute.<p>Nothing insightful. I&#x27;m just here to kick them while they&#x27;re down.
评论 #18595529 未加载
评论 #18596225 未加载
评论 #18596015 未加载
评论 #18596946 未加载
johnmc408超过 6 年前
Who is getting fired? Oh that&#x27;s right, no one...
评论 #18594812 未加载
评论 #18594979 未加载
评论 #18594980 未加载
ranpr0超过 6 年前
Quora is an absolute shit show. It won&#x27;t allow you to read content on mobile web EVEN WHEN YOU ARE SIGNED IN! To top it they disallow any screenshots of the same! Check here <a href="https:&#x2F;&#x2F;pbs.twimg.com&#x2F;media&#x2F;Dc-9ldcU8AUr23v.jpg" rel="nofollow">https:&#x2F;&#x2F;pbs.twimg.com&#x2F;media&#x2F;Dc-9ldcU8AUr23v.jpg</a> <a href="https:&#x2F;&#x2F;pbs.twimg.com&#x2F;media&#x2F;Dc-9ldbVAAALJfX.jpg" rel="nofollow">https:&#x2F;&#x2F;pbs.twimg.com&#x2F;media&#x2F;Dc-9ldbVAAALJfX.jpg</a><p>Even though I have been a heavy quora user (reader and contributor), I would be really happy if it died a really painful and stupid death
评论 #18596749 未加载
RoadieRoller超过 6 年前
Barely a month back in the facebook data breach thread in HN, I was downvoted and my comment removed when I said that it has become a fashion for the top 500 web&#x2F;e-com companies to come one day and announce data breach and walk away. I said there that it all looks to me as part of a conspiracy theory where they hide behind a breach to sell data&#x2F; buy data en masse for marketing purposes.
评论 #18595681 未加载
评论 #18596693 未加载
评论 #18595878 未加载
评论 #18595400 未加载
评论 #18595471 未加载