Author Topic: Quora hacked!  (Read 1747 times)

Offline shulem92

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Feb 2015
  • Posts: 2966
  • Total likes: 133
  • DansDeals.com Hat Tips 1
    • View Profile
  • Location: Lakewood
Quora hacked!
« on: December 04, 2018, 01:10:28 AM »
100 million users affected. heres a copy of the email they sent out.

Dear Shulem92,
We are writing to let you know that we recently discovered that some user data was compromised as a result of unauthorized access to our systems by a malicious third party. We are very sorry for any concern or inconvenience this may cause. We are working rapidly to investigate the situation further and take the appropriate steps to prevent such incidents in the future.

What Happened

On Friday we discovered that some user data was compromised by a third party who gained unauthorized access to our systems. We're still investigating the precise causes and in addition to the work being conducted by our internal security teams, we have retained a leading digital forensics and security firm to assist us. We have also notified law enforcement officials.

While the investigation is still ongoing, we have already taken steps to contain the incident, and our efforts to protect our users and prevent this type of incident from happening in the future are our top priority as a company.

What information was involved

The following information of yours may have been compromised:

Account and user information, e.g. name, email, IP, user ID, encrypted password, user account settings, personalization data
Public actions and content including drafts, e.g. questions, answers, comments, blog posts, upvotes
Data imported from linked networks when authorized by you, e.g. contacts, demographic information, interests, access tokens (now invalidated)
Non-public actions, e.g. answer requests, downvotes, thanks
Non-public content, e.g. direct messages, suggested edits
Questions and answers that were written anonymously are not affected by this breach as we do not store the identities of people who post anonymous content.

What we are doing

While our investigation continues, we're taking additional steps to improve our security:

We’re in the process of notifying users whose data has been compromised.
Out of an abundance of caution, we are logging out all Quora users who may have been affected, and, if they use a password as their authentication method, we are invalidating their passwords.
We believe we’ve identified the root cause and taken steps to address the issue, although our investigation is ongoing and we’ll continue to make security improvements.
We will continue to work both internally and with our outside experts to gain a full understanding of what happened and take any further action as needed.

What you can do

We’ve included more detailed information about more specific questions you may have in our help center, which you can find here.

While the passwords were encrypted (hashed with a salt that varies for each user), it is generally a best practice not to reuse the same password across multiple services, and we recommend that people change their passwords if they are doing so.

Conclusion

It is our responsibility to make sure things like this don’t happen, and we failed to meet that responsibility. We recognize that in order to maintain user trust, we need to work very hard to make sure this does not happen again. There’s little hope of sharing and growing the world’s knowledge if those doing so cannot feel safe and secure, and cannot trust that their information will remain private. We are continuing to work very hard to remedy the situation, and we hope over time to prove that we are worthy of your trust.

The Quora Team

Offline shulem92

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Feb 2015
  • Posts: 2966
  • Total likes: 133
  • DansDeals.com Hat Tips 1
    • View Profile
  • Location: Lakewood
Re: Quora hacked!
« Reply #1 on: December 04, 2018, 02:08:04 PM »
While the passwords were encrypted (hashed with a salt that varies for each user)
is there any point of using a password saver like lastpass or something, if hackers are able to get past the encryption?

Offline yesitsme

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Dec 2014
  • Posts: 5116
  • Total likes: 2238
  • DansDeals.com Hat Tips 4
  • Gender: Male
    • View Profile
Re: Quora hacked!
« Reply #2 on: December 04, 2018, 02:33:40 PM »
is there any point of using a password saver like lastpass or something, if hackers are able to get past the encryption?
if if done properly they shouldn't be able to,
["-"]

Offline gozalim

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Oct 2008
  • Posts: 4305
  • Total likes: 821
  • DansDeals.com Hat Tips 0
  • Gender: Male
    • View Profile
Re: Quora hacked!
« Reply #3 on: December 04, 2018, 03:56:07 PM »
is there any point of using a password saver like lastpass or something, if hackers are able to get past the encryption?
this is more reason to.
sofar, they haven't reported gotten past places like lastpass, which supposedly uses good encryption.
more of these have been individual websites who have lapsed on their security. without a password saver, most people end up using identical passwords across multiple sites, then when one gets hacked, you're only as strong as your weakest link.
with a password saver you can more comfortably change your passwords on each site.

Offline shulem92

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Feb 2015
  • Posts: 2966
  • Total likes: 133
  • DansDeals.com Hat Tips 1
    • View Profile
  • Location: Lakewood
Re: Quora hacked!
« Reply #4 on: December 04, 2018, 04:23:57 PM »
this is more reason to.
sofar, they haven't reported gotten past places like lastpass, which supposedly uses good encryption.
more of these have been individual websites who have lapsed on their security. without a password saver, most people end up using identical passwords across multiple sites, then when one gets hacked, you're only as strong as your weakest link.
with a password saver you can more comfortably change your passwords on each site.
i get all of that, but if they were able to get past individual encryption (after they hacked in to the website) and then have access to everyones encrypted passwords, and still quora feels that they got everyones passwords (even though they were individually encrypted!, i feel the need to mention that again) why do i feel any more confident with lastpass? if lastpass gets hacked, they will KNOW where all your passwords go, now they can only guess...

Offline gozalim

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Oct 2008
  • Posts: 4305
  • Total likes: 821
  • DansDeals.com Hat Tips 0
  • Gender: Male
    • View Profile
Re: Quora hacked!
« Reply #5 on: December 04, 2018, 04:26:15 PM »
i get all of that, but if they were able to get past individual encryption (after they hacked in to the website) and then have access to everyones encrypted passwords, and still quora feels that they got everyones passwords (even though they were individually encrypted!, i feel the need to mention that again) why do i feel any more confident with lastpass? if lastpass gets hacked, they will KNOW where all your passwords go, now they can only guess...
-what was the last bank you heard this about?
-password holders are in the encyrption business

Offline shulem92

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Feb 2015
  • Posts: 2966
  • Total likes: 133
  • DansDeals.com Hat Tips 1
    • View Profile
  • Location: Lakewood
Re: Quora hacked!
« Reply #6 on: December 04, 2018, 04:29:06 PM »
-what was the last bank you heard this about?
-password holders are in the encyrption business
bank?
so the response is simple, that lastpass has better encryption

Offline gozalim

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Oct 2008
  • Posts: 4305
  • Total likes: 821
  • DansDeals.com Hat Tips 0
  • Gender: Male
    • View Profile
Re: Quora hacked!
« Reply #7 on: December 04, 2018, 04:29:31 PM »
bank?
so the response is simple, that lastpass has better encryption
seems they do

Offline yesitsme

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Dec 2014
  • Posts: 5116
  • Total likes: 2238
  • DansDeals.com Hat Tips 4
  • Gender: Male
    • View Profile
Re: Quora hacked!
« Reply #8 on: December 04, 2018, 09:27:06 PM »
["-"]

Offline shulem92

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Feb 2015
  • Posts: 2966
  • Total likes: 133
  • DansDeals.com Hat Tips 1
    • View Profile
  • Location: Lakewood