Live data from Hacker News

Notifying Our Users of Attacks by Suspected State-Sponsored Actors

yahoo-security.tumblr.com

31–40 of 46 posts

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#31

Earlier quoted context omitted.

I want one of these companies to define state-sponsored actors? It's great if one is a dissenter in Egypt and the authorities there go after their Yahoo! account but what about a US citizen's account being attacked by the FBI or NSA?

There's no attack from the FBI or NSA, there's a court order.

Secret court orders are an attack on democracy.

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#32

A big source of confusion on this kind of thing is that the HN crowd tends to see "state actor" and think "pervasive surveillance (by the NSA)". In context, and in the security industry in general, "state actor" refers to active (although often broadly cast) penetration attempts by groups thought to be operated by foreign governments. These groups do not have significant surveillance capabilities, so they're trying t…

So, what you are saying is we should lose all hope of ever being notified about an NSA attack because they own the networks. Like that made it all-right... REALLY????

Consider this your notification.

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#33
post #22

Earlier quoted context omitted.

At the risk of stating the obvious, a From or Reply-To address of something@yahoo.com doesn't necessarily mean that Yahoo had anything to do with the message.

I've got more experience in hunting down spam than is healthy and can read headers. Receiving SPF, DKIM validated spam from Yahoo's email systems, then discovering there's absolutely no way in hell to kick it back to them, sours one rather rapidly. Trying to send mail to Yahoo has been roughly equally annoying for about as long.

You're not Google or Microsoft, so you don't matter as an email provider.

  -- The Yahoo! Mail Team

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#34
post #22

Based upon the amount of spam I receive from Yahoo! mail systems, I'm not confident in their ability to detect "attacks by suspected state-sponsored actors" as they apparently don't even have the ability to detect phished/compromised accounts.

At the risk of stating the obvious, a From or Reply-To address of something@yahoo.com doesn't necessarily mean that Yahoo had anything to do with the message.

I manage e-mail systems with thousands of users. I'm quite capable of looking at mail headers and figuring out where a message originates. Besides that, messages originating at Yahoo! are DKIM signed.

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#35

Based upon the amount of spam I receive from Yahoo! mail systems, I'm not confident in their ability to detect "attacks by suspected state-sponsored actors" as they apparently don't even have the ability to detect phished/compromised accounts.

What the hell are you talking about?!

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#36
post #22

Earlier quoted context omitted.

At the risk of stating the obvious, a From or Reply-To address of something@yahoo.com doesn't necessarily mean that Yahoo had anything to do with the message.

I've got more experience in hunting down spam than is healthy and can read headers. Receiving SPF, DKIM validated spam from Yahoo's email systems, then discovering there's absolutely no way in hell to kick it back to them, sours one rather rapidly. Trying to send mail to Yahoo has been roughly equally annoying for about as long.

Can you clarify regarding no way to kick it back to them? My understanding was that they operate typical feedback loops per RFC 6449 (though I haven't personally verified this).

They also host a spam FAQ which has a link to a form to submit spam reports: https://help.yahoo.com/kb/SLN3402.html

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#37

Based upon the amount of spam I receive from Yahoo! mail systems, I'm not confident in their ability to detect "attacks by suspected state-sponsored actors" as they apparently don't even have the ability to detect phished/compromised accounts.

The most obvious one was a persistent (and wild) XSS vuln on yahoo mail accounts that seemingly couldn't be fixed in 2012, 2013, and some argue it's still present in 2015.

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#38
post #22

Earlier quoted context omitted.

At the risk of stating the obvious, a From or Reply-To address of something@yahoo.com doesn't necessarily mean that Yahoo had anything to do with the message.

I manage e-mail systems with thousands of users. I'm quite capable of looking at mail headers and figuring out where a message originates. Besides that, messages originating at Yahoo! are DKIM signed.

True, but Yahoo doesn't consider a properly DKIM or Domainkeys email something that should not just end up in the spam folder...

My experience with Yahoo mail is that there are tons of false positives on spam, and that none of the headers matter much... preference is given to a small number of whitelisted sending companies.

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#39
post #5

Earlier quoted context omitted.

It's more likely to be the NSA nowadays. It would be good if these notifications said where the attacks appeared to originate.

Why would the NSA need to attack? They can just ask Yahoo for the data.

Perhaps because, instead of targeting the inbox of the victim, they may need to attack the victim him/herself?

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#40

Earlier quoted context omitted.

I manage e-mail systems with thousands of users. I'm quite capable of looking at mail headers and figuring out where a message originates. Besides that, messages originating at Yahoo! are DKIM signed.

True, but Yahoo doesn't consider a properly DKIM or Domainkeys email something that should not just end up in the spam folder... My experience with Yahoo mail is that there are tons of false positives on spam, and that none of the headers matter much... preference is given to a small number of whitelisted sending companies.

Sorry, I was referring to messages received at my mail system that originate on Yahoo!'s mail system; more specifically, messages that are signed by a yahoo.com key and coming from a yahoo.com mail host (according to DKIM and SPF).

Anyways...

> "Yahoo doesn't consider a properly DKIM or Domainkeys email something that should not just end up in the spam folder"

Nor should they. There's plenty of actual spam that passes SPF and DKIM checks -- which brings us back to my original point (the amount of spam that I receive from Yahoo!). A message should not be treated as non-spam just because it passes those checks -- they are merely one factor to consider.

Post reply on HN