28 ms·
Quora User Data Compromised
- kimjongman 8y agothank you very mush
- brad0 8y agoExposed Data: --- Based on what we have learned, some of our users’ information has been exposed, including: - Account information (e.g. name, email address, encrypted password, data imported from linked networks when authorized by users) - Public content and actions (e.g. questions, answers, comments, upvotes) - Non-public content and actions (e.g. answer requests, downvotes, direct messages) Questions and answers that were written anonymously are not affected by this breach as we do not store the identities of people who post anonymous content.
- thomasfromcdnjs 8y agoFrom an email I got --- What information was involved The following information of yours may have been compromised: Account and user information, e.g. name, email, IP, user ID, encrypted password, user account settings, personalization data Public actions and content including drafts, e.g. questions, answers, comments, blog posts, upvotes Data imported from linked networks when authorized by you, e.g. contacts, demographic information, interests, access tokens (now invalidated) Non-public actions, e.g. answer requests, downvotes, thanks Non-public content, e.g. direct messages, suggested edits Questions and answers that were written anonymously are not affected by this breach as we do not store the identities of people who post anonymous content.
- johnmc408 8y agoWho is getting fired? Oh that's right, no one...
- johnmc408 8y agoJust got my email from Quroa...Who writes this drivel: Conclusion It is our responsibility to make sure things like this don’t happen, and we failed to meet that responsibility. We recognize that in order to maintain user trust, we need to work very hard to make sure this does not happen again. There’s little hope of sharing and growing the world’s knowledge if those doing so cannot feel safe and secure, and cannot trust that their information will remain private. We are continuing to work very hard to remedy the situation, and we hope over time to prove that we are worthy of your trust.
- Puer 8y agoSome poor peon at the bottom of the ladder instead of the engineers/managers actually responsible for the mistake. The great thing about being at the top is being able to delegate away blame. After all, it's your job.
- TylerE 8y agoMuch more likely some highly paid PR flack, likely with corporate counsel sitting adjacent.
- ramenmeal 8y agoDoesn't seem like every breach warrants someone to get fired. The Equifax breach makes sense, there was an obvious lack of due diligence to protect user's data. But we should wait to see the reason for the breach. Mistakes can happen even if the company was trying to protect user's data.
- shawn 8y agoHopefully no one, yes. You have likely written a security vuln. The smugness just doesn't go away till you realize it.
- sharkweek 8y agoAt this point I am operating on the assumption that ALL businesses that have my data are going to inadvertently leak it at some point, and thus I am attemtping to provide individual companies with as little information about me as possible. The toughest ones here are my online banking and my online health portal, but other than that, I have gotten pretty picky about what information I give any company.
- Yhippa 8y agoIf they get your data from brokers they may be building comprehensive profiles about you without your explicit permission.
- beefsack 8y agoThis is a healthy mindset to have. I feel that for every company that self-reports a leak, there are multiple other companies that have leaked your data and either haven't discovered the breach, refuse to disclose it, or flat out sold your data to the highest bidder.
- SOLAR_FIELDS 8y agoI’m even more worried about the ones that don’t have the facilities to even detect and know they’ve been breached.
- spydum 8y agoYou would be correct. In the US, which I might remind you, does not have a national law on the books regarding data breach notification. Even at the state levels, it’s varies pretty wildly on top of, most notifications are only required if there is evidence. So here is the challenge: what if I keep no logs, and have terrible security monitoring capability? If I am notified or discover a critical vulnerability on my own, but have inadequate logs to show or detect if it was exploited... am I required to notify? I have been told no (I fervently disagreed; I think suspected breaches, or critical vulnerabilities which may lead to breaches but were inconclusive should still require notification).
- bigiain 8y agoInteresting (to me, at least) that the regular Quora update emails land in my inbox (or in the Social tab in Gmail, anyway), but the security breach notification was spam filtered...
- elorant 8y agoWell they probably sent a shit-ton of emails in a short timespan to notify most if not all users which could have triggered spam algorithms.
- deleted 8y ago[deleted]
- dang 8y agohttps://help.quora.com/hc/en-us/articles/360020212652 https://help.quora.com/hc/en-us/articles/360020212652 contains more detail.
- stickfigure 8y agoWow. If this had happened a couple years ago, before they made all the anonymous entries truly anonymous, this would have been really ugly. It's a valuable lesson in "don't keep data you don't need". EDIT: A little backstory for non-Quorans. Until early 2017, anonymous Quora answers and comments were anonymous to the public but not actually anonymous in the database (they were still "your" entries). In early 2017 they (presciently) made all this content fully anonymous, even in the database.
- aviv 8y agoNo, the lesson is: "don't give companies data they don't need".
- npunt 8y agoTheir doc says: > Is content posted anonymously still secure? > Yes. Anonymous content cannot be connected to user accounts, so content posted anonymously is still secure. https://help.quora.com/hc/en-us/articles/360020212652 https://help.quora.com/hc/en-us/articles/360020212652
- deleted 8y ago[deleted]
- anonytrary 8y ago> It's a valuable lesson in "don't keep data you don't need". Unfortunately, though, most companies operate under the "keep data you might eventually need" principle.
- abbot2 8y ago1. Force everyone to register to get access to content. 2. Leak that data. 3. ... 4. Profit. Not sure how this part works though. I hope lesson should be learned: don't force users to register just because you can
- YetAnotherNick 8y agoI see no lesson to be learned from the business perspective. If equifax can recover from their data loss, any company can.
- mulmen 8y agoWell equifax didn’t harm any of their customers so their bounce back should be no surprise.
- zbentley 8y agoI'll bite. How did they not harm their users?
- mulmen 8y agoEquifax’s customers are whoever pays them for access to data. Their customers are not the people who had their personal data exposed. The first rule of Web 2.0 is still true: if you are not paying for the product you are the product.
- zbentley 8y agoIt costs me money (past a certain number of freebies) to access Equifax's data on me--to get a credit report. I get that this is not their main business model, and that their customers that they bundle and sell consumer data to are more valuable. But end users, in this case, are still customers. They still pay money and get a service in return. Contrasted with e.g. Google services, it's a different scenario.
- 8y ago
- s3r3nity 8y agoSo I'm not a security expert, so I ask this in real earnest to learn: what is it that these companies keep doing wrong, and/or why aren't they adjusting to the climate that these types of attacks are increasing over time? Or are they trying to adjust, and the attacks are getting so sophisticated that the pace of investment in counter-measures is below that of the pace of advancement in the complexity of attacks? Or something in the middle?
- spydum 8y agoSadly, security is still hard in a lot of cases, and most everyone (product / developer / customer) is fixated on features and performance. Security is only important when it fails (very much like availability) - and by then it is really hard to retrofit.
- dyu 8y agoAs an example, consider an army attacking a defending army. The defending side is as good as the weakest member, because you can presume the attacking side to be looking for the weakest part and attacking that. On the other hand, the attacking side is as good as the strongest member, and having a few weaker members is ok. It is generally harder to make sure you have uniformly good defense, than getting a few really good people to spend dedicated time attacking. Of course, this model assumes that as soon as you have penetrated the perimeter, the rest becomes easy. This is the more traditional model. People are increasingly adopting a you-are-already-hacked approach, which makes it harder to move laterally once someone gets in. However, the general challenge still applies.
- deleted 8y ago[deleted]
- mulmen 8y agoNo harm comes to the company after a breach so from their perspective there is no risk. Since there is no risk there is no need to improve security or reduce retained data. It’s not really a security issue as much as an incentive issue.
- deleted 8y ago[deleted]
- throwawayquora 8y agoAre there any details about how the passwords were stored? "Encrypted" is a bit questionable. I'd expect hashed.
- varenc 8y agoThey clarify that the passwords were indeed hashed and salted. "Encrypted" is just there to help the non-technical audience understand their passwords aren't exactly leaked in plaintext. No details on the hashing scheme used though, so we don't really know how easy it'll be for the attacker to brute force the password hashes.
- tootahe45 8y agoBecause they didn't mention it, and the age of the site makes me think it isn't something we'd consider secure.
- deleted 8y ago[deleted]
- cornstalks 8y ago> encrypted password I hope they mean hashed, not encrypted.
- guscost 8y agoDid a double take at this too, but they clarified that it means “hashed with a unique salt” later on. Not a good word choice for a summary though!
- ianai 8y agoWho’s password hash would it be? Ie could it be a linked accounts password?
- cornstalks 8y agoThanks, I missed that tidbit in my initial pass through!
- jtmarmon 8y agoProbably written this way because this is a release for the general public. I would imagine most people expect passwords to be "encrypted" and don't know what "hashed" means, and they correctly assumed technical people will keep reading for more info
- gsich 8y agoAll the more incentive to inform people what hashing means.
- hunter2_ 8y agoThey do indeed, but then for some reason, they also say "this breach may have exposed ... the password you used" [0] which is a statement I think is wholly incompatible with the notion of "hashed with a salt that varies for each user" (but please let me know if I'm incorrect). They can rightfully say "encrypted" to a lay audience because the definition of encrypted is not so strict as to require decryptability, but why would they say that the password might be exposed? [0] https://help.quora.com/hc/en-us/articles/360020212652 https://help.quora.com/hc/en-us/articles/360020212652
- productdev 8y agoQuora would not allow you to read multiple answers by clicking on "similar questions" (on the side) without creating an account. And then this happens!
- vtesucks 8y agoValid point. If you're aggressively farming data, so much so that you log them in automatically if they are logged into the google account then you better be careful with data too
- xiphias2 8y agoFrom reading the details it looks like almost all user data (and every user's data) is compromised. Using the word ,,some'' should be illegal in this instance.
- foobarbecue 8y agoAnd now they're 504ing...
- spike021 8y ago>I didn’t know I had a Quora account. How is it that my email or information was exposed? You may have signed up for Quora some time ago. While you might not have regularly visited or used Quora, your account remained, and this breach may have exposed some of your information, such as the email address you signed up with, the password you used, or actions you took on Quora. Would be nice if websites measured user activity and could 'lock out' or otherwise release their data if they never use the site; at least, confirm with said user via email if the account is needed. But in this era, I'm sure companies would prefer to keep whatever data they can get.
- MrStonedOne 8y agoByond (2d tile/sprite based online gaming platform) does this. After a year of no activity they inactivate your account, and delete the hashed password. You have to reset your password to regain access.
- deleted 8y ago[deleted]
- tschellenbach 8y agoI've always been impressed with Quora's engineering team. Kinda curious what slipped passed them.
- RoadieRoller 8y agoBarely a month back in the facebook data breach thread in HN, I was downvoted and my comment removed when I said that it has become a fashion for the top 500 web/e-com companies to come one day and announce data breach and walk away. I said there that it all looks to me as part of a conspiracy theory where they hide behind a breach to sell data/ buy data en masse for marketing purposes.
- IshKebab 8y agoWell yeah because that is stupid.
- jacquesm 8y agoThe conspiracy is mostly in your head. No sane company would do this.
- wpietri 8y agoI don't think large companies have much interest in selling data. It's a long-term asset. The real money is in renting. E.g., Google and Facebook make a lot of money renting access to you based on the data they have. That's far more lucrative than selling the raw data once. Also, it's implausible to me that selling the data wouldn't come out eventually. As we saw with Cambridge Analytica, even pretty obscure uses of data can eventually turn into giant media exposure for privacy breaches. The brand damage is is very expensive. Facebook's market cap is down something like $100 billion; there's no way they could have made that kind of money from trying to quietly sell copies of their data.
- manigandham 8y agoSelling the data outright is not worth anything. Public identities can be scrapped and bought very easily already. Most companies with personal and contextual data like this sell access to it, usually in the form of ads.
- productdev 8y agoThe long term cost / benefit for this sort of deal doesn't work in favour of the company selling their user's data
- thwy12321 8y agoMy take on Quora and business like them: They are hiring people based on leet code questions and school prestige and not based on real technical knowledge about systems. Their business people are top school MBA grads with no security domain expertise. They then proceed to build massive data collection programs using open source tooling that non of them fully understand. Their business model depends on that data and monetizing it in various ways. An so the complexity of their application goes through the roof with regards to user data. Their user facing web apps are the tip of the iceberg for a massive surveillance scheme.
- amrx431 8y ago> They are hiring people based on leet code questions and school prestige and not based on real technical knowledge about systems Isn't that true for almost all companies based in the Sillicon Valley?
- thwy12321 8y agoThe big companies, Google/Fb/etc hire that way but they also bring on niche experts. Leet code at those companies is for the code monkeys. They hire the people writing the ML/distributed systems/security code out of PhD programs and targeted hiring. Theres more to it, dont feel like typing it all up
- dreyfiz 8y agoI'm experiencing a sense of schadenfruede because I'm embittered by Quora's arrogant "real names" policy. They won't "let me" contribute. Nothing insightful. I'm just here to kick them while they're down.
- WilliamEdward 8y agoI believe you're being cynical, because this forced name policy allows for answers to be of higher quality, which is basically their entire selling point - being a better yahoo answers. If you want anonymity there are other platforms for that, stackexchange for example.
- dreyfiz 8y agoThat's a false dichotomy. Ask MetaFilter is a much better Yahoo Answers, but I can be pseudonymous there. Also, my pseudonym is much closer to a real identity than what's on my driver's license. I don't have any real reason to fear sharing my "real name" with Quora. I'm lucky. But I'm not the only person in the world. Good thing I'm not trans or a religious dissident. Good thing the only thing stopping me from contributing to Quora is my ornery nature. I would hate to for the world to miss out on my Quora contributions for a good reason. Good thing Quora doesn't have my "real name" is all I'm saying. I have an interest in privacy, even though I use the same pseudonym as my identity on LinkedIn, Twitter, Facebook, and Instagram. And Ask MetaFilter. And so many other places. I shouldn't have to beg to use my preferred name on Quora's bulletin board, regardless of my reasons. It's none of their business. There's nothing about a "real names" policy that automatically turns a shitposter into a quality contributor. There are plenty of reasons not to wear a target on your back and self-doxx. Today's misadventure is one very good reason.
- adventured 8y ago> That's a false dichotomy. Ask MetaFilter is a much better Yahoo Answers, but I can be pseudonymous there. There's an example that just happens to be the greatest knowledge platform ever built in world history. Wikipedia allows non real name contributions. Plainly next to that, Quora has no legitimate excuse for requiring real names to ensure quality. It's for one reason: $$$. They have to figure out how to reach a $3b valuation at some point so their VC owners can get a reasonable exit. It guarantees an inevitable disaster for a knowledge service. The conflict between quality and always needing more and more junk content to slap ads on and allowing for abusive business practices to reach for that fat exit for the VCs. And if you don't do it, they'll put someone in charge that will. Unless you can find another business model as Stack Exchange did, stay private & small/lean (so you don't have to try to pretend to be a $3b company when your business model will never legitimately get you beyond 1/20th that), or go the donation Wikipedia route.
- jacquesm 8y agoThis is why I hate companies that force you to sign up to gain access to content. I do not want that relationship. Sooner or later those systems will be legacy and then maintaining them will be a pain. Bitrot will set in and sooner or later there will be a breach. One new development is that you used to be able to get your invoices mailed via snail mail. Then that disappeared and you got your invoices mailed via email. Then that disappeared and now you have to create an account on some portal so that you can download your invoice. So that's one userid/password combo per business relationship or service that you use privately. Healthcare, HOA, insurance, payroll etc., every bloody two bit player requires you to log-in to their oh-so-secure service rather than that they send you your stuff. Which requires a ton of overhead and - sure enough - sooner or later they get hacked because by then the amount of data they hold on to is more valuable than their security could reasonably be expected to defend.
- giobox 8y agoIf your main concern is the sheer number of username/unique password combos, pick a good password manager that works well across the devices you use. I’ve literally stopped caring about this aspect of my family’s online life thanks to 1Password. That iOS 12 added OS level integration for the service was the icing on the cake for me.
- 2arrs2ells 8y agoAgreed. I never would have thought that the problem that motivated Persona would have been solved this way... but the combination of TouchID/Face ID and 1Password has made account setup/maintenance sufficiently frictionless.
- lisper 8y agoUntil 1password gets compromised. https://thehackernews.com/2017/02/password-manager-apps.html https://thehackernews.com/2017/02/password-manager-apps.html
- jacquesm 8y agoThat's only part of it. The other part is that - invariably - they get hacked.
- fouric 8y agoDoes Quora still have a real name policy?
- manigandham 8y agoYes, but they also allow organization accounts now, and they're rather slow at dealing with spam so around half the people you see are using fake names.
- axiom92 8y agohttps://xkcd.com/1269/ https://xkcd.com/1269/ Just be a nihilist, guys.
- pier25 8y agoor a sage
- wenbin 8y agoThis is the email that they sent to users: https://nfil.es/w/kHYd7t/ https://nfil.es/w/kHYd7t/
- pavanlimo 8y agoClearly this is well orchestrated and professional. I'm wondering what could be the motivation for such an attack. There is no monetary benefit whatsoever. Perhaps some AI company wanting to acquire solid data to train their models?
- askafriend 8y agoRumors are that it was a disgruntled ex-employee.
- thwy12321 8y agoReally? Do tell
- deleted 8y ago[deleted]
- Chazprime 8y agoI think we’re at a point where it’s safe to assume most of our data can be collated into a frighteningly thorough profile of our lives for anyone on the internet to see.
- Bucephalus355 8y agoOne thing I would like to do is have various US Senators send letters to the major corporations, and perhaps even large open source groups (like npm), and ask them, proactively, what they are doing to secure citizens around the world's data. There is something called the Cybersecurity Bipartisan Caucus in the US Senate. I have found calling these senators (which I have never done before for any politician about anything) extraordinarily helpful and gratifying. I have even explained that I don't live in their state, and yet they still listen and clearly need the advice from good security/sysadmin people (like asking them why Facebook still doesn't have a CSP Security Header). It was only 6 days ago that the "International Committee on Privacy", made up of Senators from countries around the globe, met in London to question Richard Allan, VP of Privacy at Facebook. Mark Zuckerberg rejected the request for his attendance. [1] https://www.warner.senate.gov/public/index.cfm/cybersecurity https://www.warner.senate.gov/public/index.cfm/cybersecurity [2] https://www.parliament.uk/business/committees/committees-a-z/commons-select/digital-culture-media-and-sport-committee/news/grand-committee-evidence-17-19/ https://www.parliament.uk/business/committees/committees-a-z... [3] https://www.youtube.com/watch?v=1P97ubLDbJI https://www.youtube.com/watch?v=1P97ubLDbJI
- deleted 8y ago[deleted]
- throwaway292939 8y agoI feel that this is becoming a standard narrative. SV company comes up with an idea, decides harvesting lots of user data is how they will monetize. VCs pump in a lot of money and expect their returns, so company is now forced to collect even more data aggressively (the sign-in wall that many others have pointed out is an example of this). VC pressure causes company to "innovate" fast, most likely trading off security for new features in the meantime. As this progresses and they become more valuable, they are then targeted by hackers, which causes some type of compromise of users' data. Quora is an intimate medium — tied to real names, real and often deep interests. It's especially bad that this happened. There needs to be a better way to realign incentives in this ecosystem, otherwise this story will repeat.
- ttty2 8y agoI'm still amazed to this day that people give real names to their online accounts. I'd never put my real name anywhere online. It works quite well for me and if my data is leaked, I'm still ok. Probably I should use more email accounts to don't be linked, but it's fine anyway.
- pmart123 8y agoI think the success of Facebook and Google (being ad businesses) had a lot to do with this, i.e. "you are the product." If the trend to subscription businesses continues, do you think investors will approach how a company should scale differently?
- mychael 8y agoI'm angry at them for this, but more angry at myself for not deleting my data years ago when I stopped logging in.
- system2 8y agoI am angry at myself for signing up for this stupid quora. Nothing but advertising of offshore "web developers" explaining how their "product" can solve the "question" they asked with their fake accounts. I would love to punch the CTO of this company in the nose with passion.
- tlow 8y agoThis is seriously distressing. This underscores the reasons why you should never use a third party messaging system for any sort of private conversations. Why is this so easy? Is it impossible for a well-funded company to keep it's user information private? If so, can we act like it?
- breckuh 8y ago> ...there’s little hope of sharing and growing the world’s knowledge if those doing so ... cannot trust that their information will remain private. Here's a crazy idea, circa 1990's: don't store their personal information! Allow people to browse Quora without using their real names. I'm very happy I deleted my Quora account when I did.
- 9dev 8y agoSo you're under the impression Quota actually deletes all information related to your account when you click on delete? I'd be surprised.
- MrStonedOne 8y agoNo mention of hashing algorithm for passwords, so until they provide that info, I would just assume they hashed with unsalted md5 or sha1 or even crc, and treat it as if they had stored them in plain text.
- sn41 8y agoIs Quora legally liable for compromised data? Making companies legally liable for compromised data might be one way for them to be scrupulous about minimal data retention.
- rishikeerthi 8y agoIs anonymous question or answers also compromised?
- Jedd 8y agoIt's genuinely hard to imagine a second-rate question and answer site could have any credentials, or indeed any non-public content, that anyone else could be interested in. From the list of what's been taken, it sounds like it's mostly email and hashed passwords, though I suspect Quora's user base is not entirely populated by people committed to a strict one-off password policy. Happily I get to once again bemoan the disappearance of JCSV, who was astounded that Quora was still a thing five years ago: http://jesuschristsiliconvalley-blog.tumblr.com/post/48962035819/quoraquoraquora http://jesuschristsiliconvalley-blog.tumblr.com/post/4896203...
- snek 8y agoquora already sells your data to as many third parties as possible... i don't suspect this changes much.
- abraae 8y agoThe Quora link to more details is a masterpiece of corporate obfuscation. Posing as a FAQ, it presents questions, then proceeds to not answer them (at least, as of a few minutes ago). https://help.quora.com/hc/en-us/articles/360020212652 https://help.quora.com/hc/en-us/articles/360020212652 What happened? - not answered in any detail What kind of user data was affected? - answered! How do I know if I was affected? - not answered How was it brought to your attention? - not answered How many Quora users are affected? - not answered
- codezero 8y agoAll of these appear filled out now. Quora is good about responding quickly, which should be appreciated. That the FAQ wasn't fully filled out was just because it was being filled out. I know this can be an awkward experience for someone who immediately sees and responds to the tech news, but a bulk of their users won't be that profile. They got the framework for response laid out immediately, and are working on the responses. This seems pretty solid.
- abraae 8y agoThey were already filled out, but with non-answers. For example: > When did you first learn of the issue? How was it brought to your attention? > We first learned of the issue on November 30. Upon learning about the issue, we immediately launched a comprehensive investigation and remediation effort. There is absolutely nothing in there about how this was brought to Quora's attention. Did they see identities for sale on the dark net? Were they approached for a ransom? Did a user inform them? Nothing. The other questions ditto.
- codezero 8y agoAh OK – I read this wrong then. My bad. I am confident, or at least optimistic, they will make improvements, if not, then I'll let you know how my foot tastes.
- robbiemitchell 8y agoAdvertisers had their campaign data compromised, too. Yeesh.
- orliesaurus 8y agoI really started hating Quora a while back, probably 3 years ago and stopped collaborating. Most because "people" were spamming answers with marketing bs... So many answers start with "I'm Bob, CEO of MyCompany.com, I am an expert in this and that" Most Quora users are hungry for answers and flood-request you to answer their question just because the system recommends them to do so. No matter how many times you pass, the system still keeps notifying you that "you are needed". Quora doesn't understand a no is a no. IMHO -> There truly isn't any benefit on providing good answers on Quora, other than stroking your ego, might as well become a micro-influencer on Instagram. Even worse most questions seem truly 1-Google search away and the answers are low-effort. Sure you do have some rare gems, and those are truly amazing to read. Alas, that's not often and spamming answers just for the sake of answering has become a reality.
- deleted 8y ago[deleted]
- thewhitetulip 8y agoThere is one benefit of writing answers on quora: self promotion. The last time I checked, both my Python & Go open source text books get decent views from Quora & reddit, daily. That's why I just deactivated it and didn't delete.
- Clyybber 8y agoI feel like questions like "Why is <insert my opinion here> true?" have become increasingly common too. Thats like asking: "Please confirm my opinion, I don't want to learn anything new!"
- nabnob 8y agoA lot of the quora answers on topics outside of computer science and math are just plain wrong, especially in history, philosophy, and economics.
- z0r 8y agoBruce Schneier says data is a toxic asset. He's right. There should be (will be?) laws preventing collection of most data, and punitive liability when collected data is breached.
- EamonnMR 8y agoI always found Quora's demand that I make an account merely to read, like Pinterest, extremely rude. I don't think I ever gave in and made an account but I suppose I can find out now.
- red023 8y ago"data imported from linked networks when authorized by users" That why I never use that shit and always just make a new account. Its just putting in a email instead of pushing a button but this providers have fooled everyone in to signing in with 3rd partys for no reason other then to collect more stuff from you.
- mindcrime 8y agoThe folks asking for snail mail are joking right? Snail mail is an obsolete relic of a time gone by, and belongs in the dust-bin of history alongside buggy whips, wood fired steam engines, betamax, etc. Personally I'd pay to be able to stop getting snail mail. If it weren't for the one or two rare pieces of semi-important crap that show up, sent by dinosaurs that don't realize we aren't living in the 20th century anymore, I'd quit checking my physical mailbox once and for all. I mean, it's not like 99/100'ths of what comes in there isn't junk catalogs, fundraising letters from politicians I hate, sales flyers from stores I hate, bills that I pay online already, mail meant for the previous residents, etc. But unlike email spam, it actually costs me effort to scrape that garbage out of the box and haul it to the dumpster. Blech. Personally, I want no part of it.
- thosakwe 8y agoIs it really that hard to keep a database secure? Genuine question - not sarcasm. I would love to know how the attackers got in in the first place. Usually when I hear about a breach, my first reaction is “yeah, I would have covered that from the start,” but if there’s something to be learned here, I’m all for it...
- codezero 8y agoYes it is, when you have the surface area of a company like Quora, or even a much smaller company. I worked at Quora, and totally unrelated, at my current company, had the opportunity to source and be point on multiple penetration tests. At my current company, I work with some people I consider extremely competent at SQL, and in particular PostgreSQL, but that didn't stop the pentesters from finding SQLi in our code. It sneaks in, and all it takes is one fuck up for a hacker to go to town. I think that most startups don't understand the value of dropping 20-30k on an engagement with a competent pentest company, and this can propagate even longer into an org to the point that they never bother to get outside testing. Don't fall into that trap. Having a third-party with eyes on your org is worth every cent. If you run a startup or aspire to, I highly recommend you consider getting a pentest when you have ~5M ARR, and continue to do a yearly engagement to make sure your shit is covered until you can afford a full time security staff.
- sombragris 8y agoNo announcement for me, but I cannot login no matter what I try.
- jcampbell1 8y agoThey need to release their hashing algorithm. If it is some sha1+salt nonsense, then they have exposed plaintext passwords for most of these people.
- Cyclone_ 8y agoThis is another reason why I don't like the "social logins". You give them so much data. They strongly encourage you to use the social login instead of using the regular email sign up.
- King-Aaron 8y agoI somehow got added into the Quora ecosystem some time back, without even actually signing up from memory. Just one day I'm getting notifications that someone is talking to me on Quora. Even though I didn't explicitly set up an account, it seemed to have done it for me already. I just assumed it was one of those shitty content aggregation platforms like the sorts that steal all the posts from Stackoverflow and rebrand them.
- break_the_bank 8y agoCan anyone explain how is Quora still relevant? How did they raise the $85M for their series D only last year? To me it seems its going the way of Yahoo Answers, if it already hasn't. It might be gaining some traction in developing countries but the ratio of signal:noise seems really low at this time, coupled with terrible UI.
- pandler 8y agoI've started keeping a log of all information I provide to a company: addresses, phone numbers, names, social security number, etc... I started doing it just to keep track of everywhere I need to update next time I change address, phone, cards, and emails at the same time[1], but it's been eye opening to watch the list grow. I think of it as something like a reverse password manager; instead of "here's a website, what's my data", it's "here's a bit of information about myself, who has it?" It's a pain keeping that list updated but at this point I'm so hooked on being able to see my personal info leak out into the world bit by bit that the friction is worth it. I'm still trying to figure out what I should do with the data I have on myself, if anyone has any suggestions. [1] That situation seems sketchy seeing it written down like that, so just want to explain that it's because I moved to a different country (address, phone, credit cards) and away from gmail at the same time.
- manigandham 8y agoSeems like a complete database exfiltration. Quora advertisers also had info compromised from a separate email notice: - Account information available on the Ads Manager account settings page. - The email address provided for notifications about your ad campaigns. - Campaign structure and setup, including information like budgets, schedule, bids, targeting, and ad information. - Notifications that were in your Ads Manager, such as ad paused, logo approved, and ad ready. - Audience setup information available on the Ads Manager audience page such as types and creation date. - Partial credit card information, including name, expiration date, and the last four digits of the credit card.
- sambe 8y agoIs there an email notifying all users of the incident and a separate email notifying those affected, or just one? Many companies seem to use intentionally vague wording to suggest you might not have to worry.
- Dreami 8y agoI too got one email and I'm not sure now if I'm affected (I got the same content as on the website in this email)
- ranpr0 8y agoQuora is an absolute shit show. It won't allow you to read content on mobile web EVEN WHEN YOU ARE SIGNED IN! To top it they disallow any screenshots of the same! Check here https://pbs.twimg.com/media/Dc-9ldcU8AUr23v.jpg https://pbs.twimg.com/media/Dc-9ldcU8AUr23v.jpg https://pbs.twimg.com/media/Dc-9ldbVAAALJfX.jpg https://pbs.twimg.com/media/Dc-9ldbVAAALJfX.jpg Even though I have been a heavy quora user (reader and contributor), I would be really happy if it died a really painful and stupid death
- ssnistfajen 8y agoZhihu (Chinese offshoot of Quora) does the exact same shit on mobile as a way to force users to download their app (which pushes a ton of ads plus other frills). Looks like they got their full playbook from Quora.
- rblion 8y agoI haven't used Quora in over a year. It's been overrun with gurus.
- onion-soup 8y agoThis is why services like metamask will take over
- iharhajster 8y agoSeveral friends and I had our Steam passwords stollen. Lesson I learned was not to have same password to more than one service because gmail account was hijacked too. The perpetrator stopped at changing gmail language to Polish, thank God. But, damage he/she could have done was much greater. It was before "login attempt from unknown location" messages. It was a drag to bring all back but we did it. The lesson also is: joining any online service/site we must accept the risk anything you provide could be stollen at some point and modify our usage phylosophy of these services.
- ngokevin 8y ago2FA when possible as well. Both Steam and Google offer this.
- lmilcin 8y ago"encrypted (hashed) passwords" Was it hashed AND encrypted or another case of people not understanding the difference?
- invalidusernam3 8y agoSeems like "encrypted" is in there for laymen and "hashed" being a clarification for more technical people. In the post they say: "... the passwords were encrypted (hashed with a salt that varies for each user) ..."
- lmilcin 8y agoIn that case how laymen are ever going to learn if we use incorrect words to make them feel safer? "Ah, they were ENCRYPTED so I don't have to worry" The thruth is they are most likely already reversed.
- deleted 8y ago[deleted]
- CiPHPerCoder 8y ago> Account information (e.g. name, email address, encrypted password, data imported from linked networks when authorized by users) Quora encrypted passwords instead of hashing them? FAIL.
- chmars 8y agohttps://blog.quora.com/Quora-Security-Update https://blog.quora.com/Quora-Security-Update seems to be misleading, especially the introduction. They start with 'some user data was compromised', however, it seems that for 'approximately 100 million Quora users' – that's basically all users! – all user data was compromised … In addition, many questions remain open, for example: Which ' leading digital forensics and security firm' is working for Quora? I hope for Quora that they met their 72-hour deadline according to the GDPR. Looking at https://www.quora.com/about/privacy https://www.quora.com/about/privacy, it does not look if Quora was / is GDPR-ready. They do not mention any legal basis for the processing (art. 13 GDPR) and they do not inform about their GDPR data representative in the EU (art. 27 GDPR).
- scarejunba 8y agoI’m going to guess that precisely nothing will happen to them under GDPR.
- MattHeard 8y agoThere can only be one digital forensics and security firm in the lead, right? All of the other firms are trailing...
- mLuby 8y agoThis is more like "leading experts"––there's no "best expert". Just marketing…
- revskill 8y agoWhat's bad about Quora website is that, whenever you see Answer notification, when you click on it, instead of a popup for quick review, the website will go to new url for the answers. That's why i don't use Quora much these days due to the stupid UX.
- the_clarence 8y agoHow were the passwords hashed? Wait. You know what? At this point it doesn’t matter. Using the same password everywhere is a broken concept and password managers are still unadopted. At this point the only solution is either SSO from a few point of trust (facebook, google, twitter, etc.) or/and password managing+generation by default (safari, iOS)
- mehrdadn 8y ago> At this point the only solution is either SSO from a few point of trust (facebook, google, twitter, etc.) No, that's what made OpenID awful. Your accounts all go down if one those "points of trust" get taken down for whatever (or no) reason.
- the_clarence 8y agoIt does suck. What I’m saying is that security for the people is not getting much better than that atm.
- MattBearman 8y agoI think at this point it should be standard practice to say what hashing algorithm is used in passwords when disclosing a breach. The email I got from quota just says “encrypted” passwords, and while the blog post says “hashed”, it doesn’t say what algorithm. For all we know it could be something useless like MD5
- mnw21cam 8y agoThis comment should be voted to the top of the conversation. "Hashed" means absolutely nothing these days.
- ShinTakuya 8y agoIt'd be useful in the sense that you'd be able to warn others, but for your own password you should be using a password manager with auto generated random passwords. That way the only thing you need to do is change one password on the leaked site.
- MattBearman 8y agoThat's exactly my point. I use 1password to handle my logins, but most people I speak to use the same password for everything, so knowing how likely it is that other services could be compromised due to this is vital.
- throwaway66666 8y agoIn 2013 a quora moderator contacted me and demanded that I provide my real name, and information that my name is real or they would ban my account. I tried reasoning with them, that I just wanted to view content and did not attend to write answers or interact etc, plus, they had a valid email address and facebook profile (also fake name on facebook). They fought back "we actually want proof of your real name like a scan of ID". I danced around and did not end up giving them a scan of my id, but I changed it to my real name. Today my information is probably leaked. Information I didn't want to give and that they threatened me for it. Where is the apology Quora? From all the recent leaks this is the one that pisses me off the most, because it's the one that was forced unto me.
- ttty 8y agoHaha I never give it to them as well. Never put your real name, no matter what. They are ridiculous with these requirements. I'm waiting until the day they'll make a credit check to open an account
- gshulegaard 8y ago1000x this. Nextdoor did this to my parents. It's fairly ridiculous. The state of personal data regulation in the US is abysmal. Unfortunately, if Cambridge Analytica wasn't enough to spur new regulation, I fear nothing will.
- hrabago 8y agoI can understand NextDoor at least. It’s very neighborhood based, and they need some way to verify that you live where you say you live. If people keep seeing membership in their neighborhood has included those who don’t love in their area, the main attraction of NextDoor will disappear.
- gshulegaard 8y agoI think you're trying to start a different conversation than what I had intended to point out by adding another anecdote to the original comment I was responding to. Right now there is relatively little liability in gathering personal data about customers but huge benefits to doing so. I believe that there should be regulation governing punishments and protections for consumers whose data may be compromised or mishandled by corporate entities. As it stands right now a company can leak personal data from their customers and face very few consequences. Rather, the negative consequences of customer data leaks are felt by the customer rather than the corporation that mishandles their data. This is a similar externality-effect as pollution, where a bad actor's malfeasance generates a larger negative impact than what is directly born by the bad actor itself. We could discuss whether or not NextDoor has a legitimate use for personal identification data, but that's a tangential discussion. My point was supposed to be that any firm that gathers personal data should be assuming a greater amount of liability than they currently are.
- steve1977 8y agoMaybe they asked how to do website security on Quora...
- Jenz 8y agoThis is Why I’ve gone over to using a proper password manager, with unique passwords for all accounts
- buboard 8y agoNot gonna shed a tear for the self-important people who wanted to slap their wisdom on everyone signed with their real name. It's as much a failure of quora as it is their own. Anyone remember the glory days of facebook , when real names were "revolutionary" and all the rage? Quora followed that cargo cult (founded by facebook people, after all) and the consequences of that choice are due today. We really need to introduce the concept of "expiring data" on the internet, personal or not. After a reasonable amount of inactivity, identities shuold be anonymized.
- rv-de 8y ago> While the passwords were encrypted (hashed with a salt that varies for each user), it is generally a best practice not to reuse the same password across multiple services, and we recommend that people change their passwords if they are doing so. According to my trusted Password Safe (https://pwsafe.org/ https://pwsafe.org/) I call about 400 accounts my own - each one with a unique random password.
- reitanqild 8y agoFeels good to have left Quora and gotten confirmation that they'd wiped my account shortly after they hit mainstream. (Cannot remember exactly what happened but I think they defaulted to showing every question I visited in my public timeline or something.)
- zerop 8y agoThis is one reason I dont write anonymous answers on Quora....
- blablabla123 8y agoIt's quite obvious that Quora doesn't care a lot about user data. Just for looking at the website, you need to login with Facebook and in fact other users could at some point even see which parts of the site you browse to without informing you. Kind of sucks, luckily deleted my account half a year ago.
- skilled 8y agoActually, I was looking at an answer last night and couldn't see it because my account was logged out. This happens on Chrome from time to time, so I didn't think much of it. But, when trying to log back in it said my password was incorrect. This was before the announcement. I wonder if some had their details reset altogether? Either way, this looks like a major breach considering the value of people who have signed up with Quora.
- bogomipz 8y agoThe post states: >"We recently discovered that some user data was compromised as a result of unauthorized access to one of our systems by a malicious third party." "Some user data" Then goes on to say: >"For approximately 100 million Quora users, the following information may have been compromised: Account information, e.g. name, email address, encrypted (hashed) password, data imported from linked networks when authorized by users Public content and actions, e.g. questions, answers, comments, upvotes Non-public content and actions, e.g. answer requests, downvotes, direct messages (note that a low percentage of Quora users have sent or received such messages)" Wouldn't this be closer to "all user data was compromised"? It seems absurd for them to state "some user data was compromised." That's seems like a pretty comprehensive list of user data. What else would there be? This is a company that for years forced account sign up and obscured user generated content even for users who just wanted to browse unless you created an account. Seriously fuck Quora.
- peter303 8y agoThe game of large numbers: so hackers obtain a million passwords. How with they decide to waste their time on any of them? In Quora's case that requires real identities and institutional affiliations will they go after the cream of the crop then?
- ulfw 8y agoThis is all bullshit. My data is all over the place. At this point I expect none of my personal data to be private. This last few weeks alone my data was stolen from British Airways, Cathay Pacific, SPG/Mariott, Quora. As users we are completely powerless. Time for change. Time for intelligent heads to come together and think of how a better internet security architecture needs to look like.
- swarnie_ 8y agoI wonder how easy it would be to piece together all these breaches with any degree of accuracy to build a "complete picture" of an individual. Say your name, email address and social get leaked in one 500m user dump and your email passport number and actual address in another. I've never worked with datasets on this scale hence the ignorance. Maybe its possible for one person of interest but how complicated would it be to match up everything?
- colinbartlett 8y agoI’ve oftened wondered if I am helped by my practice of using [servicename]@[mydomain.com] for each service I sign up for. I used to do it to help control and track spam, then I stopped when spam stopped becoming an issue. But now I feel like no longer having a single unique key to correlate my data across different leaked data sets might also be a benefit.
- TuringNYC 8y agoI'm half afraid that some sort of Cambridge Analytica type firm is buying these on the dark-net and merging all the data-sets together trying to put together even more accurate psychological profiles.
- antirez 8y agoThat's lame, but there is to always remember that information leaks are happening in almost every company out there. The way we build and run systems is no adequate, unless very large efforts (like in the case of Google) are made in order to try to limit the attack exposure, but this is not for everybody cost-wise IMHO. Makes more sense for companies to limit the amount of data they ingest. In this regard it's very bad that Quora or Linked-In force you to login just to see content. As a user, if you want to live under correct expectations, assume that your real name and profile picture, and possibly an hashed password, are always automatically leaked.
- NietTim 8y agoI didn't even know I had a quora account. Never continuously registered one. Got the e-mail though. Tried to log in, had to "complete my account" before I could go on.....wtf.... I deleted my account now, tho.
- aczerepinski 8y agoI knew I had an account but it was via oauth and I had to create a "real" quora account in order to delete it. The notice that they were storing contacts from other social networks was the part that pushed me over the top towards deletion.
- NietTim 8y agoThis must have been it. Still not sure at which point I've ever logged in to quora, but I can't think of any other explanation
- josefresco 8y agoI also received an email, do not have an account, even a partially created one like you. Odd.
- josefresco 8y agoI received an email from Quora informing me of the breach, but I do not have an account. I even used the "Forgot Password" function to confirm - why did I receive this email?
- sj4nz 8y agoThis was a nice reminder to delete my account.
- magnamerc 8y agoThe solution to data security is incorporating security at the base layer, i.e. https://universallogin.io/ https://universallogin.io/
- rahimnathwani 8y agoIt's strange that: - the linked article says the breach included hashed passwords, but makes no mention of salt - the help page says they're forcing affected users to change their passwords If the passwords were salted before being hashed and stored, then: - Why not mention it, so users (especially those who don't use unique passwords on every site) know that it's not trivial for their password to be found? - Why force people to change their passwords?
- MichaelDickens 8y agoFrom the email that I received from Quora: > the passwords were encrypted (hashed with a salt that varies for each user) Looks like the article says the same thing.
- rahimnathwani 8y agoAt the time I posted my comment, the web page said: encrypted password (hashed) Now it says: encrypted password (hashed using bcrypt with a salt that varies for each user)
- gwbas1c 8y agoI recently got an email from Quora, "you read XXX, did you find what you're looking for?" I don't want every site that I visit sending me an email every time I click on a Google result. I hit that SPAM button as fast as I could.
- MagicPropmaker 8y agoIn other cases customers have had trouble filing individual lawsuits for damage because the companies successfully argue that the information--usually credit information--doesn't belong to them, it belongs to the credit card companies. However, in this case, there is no credit card information to muddle up or confuse a case. It's only a users personal information--private messages, moderator requests, reports against other users--that has been compromised because they didn't collect credit card info. And there's an enforced "real names" policy that makes it identifiable.
- ausjke 8y agoFrom now on, I will assume all my user-data will be compromised, we need a new way to store the user-data, it will be a balance of convenience and security, but more importantly, it needs to be temporal, i.e. the use-data shall not be static anymore, something like a virtual and temporarily generated password for each session?
- niuzeta 8y agoNo system is breach-proof; security breaches happen. We as engineers should strive to reduce the break-ins and diligently push for high standards nevertheless. Having said that, this is pretty much a perfect response to the situation. 1. Quick turnaround from the breach to the announcement 2. Concise description of what happened 3. Owning the mistake 4. Update of their mitigation 5. Promise to follow up & actionable items. 6. Additional technical detail for more interested: https://help.quora.com/hc/en-us/articles/360020212652 https://help.quora.com/hc/en-us/articles/360020212652 It sucks that this happened, but for that alone I'd like to applaud Quora team. Yes, it would've been great if they didn't have to force me to sign up from the first place. It would've been great if this breach has never happened. But for the context, they're handling the issue as well as possible.
- nistak04 8y agocan they ask if their data was compromised on the question&answer site?
- nojvek 8y agoI hate Quora for the dark pattern practices of forcing you to login before you can see anything. In a way this is a great example of why you shouldn’t collect data Willy nilly. I really really really hope we get some sort of a law where companies are seriously liable for data breaches. US has a ton of tech companies but very little regulation that protects the customer.