Live data from Hacker News

Notifying Our Users of Attacks by Suspected State-Sponsored Actors

yahoo-security.tumblr.com

41–46 of 46 posts

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#41
post #16

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Cybersecurity_Information_Shar... This passed along with the budget bill at the end of last week. It establishes a system whereby the US defense department shares with corporations their signals for detecting state-sponsored attacks, and companies are allowed to opt in to sharing anonymized attack information with the DoD

CISA is a terrible bill and not a solution to this problem. Security teams have been able to manage this data on their own for years without government intervention. There have always been other methods for determining if an attacker is state sponsored. One example: Seeing your account, and a number of dissident or activists being attacked from a block of IPs or similar password attempts, probably means the attack is…

didn't say i agreed with it, just pointed out a likely reason why such a narrowly specific threat notification tool would be launched now.

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#43
post #36

Earlier quoted context omitted.

I've got more experience in hunting down spam than is healthy and can read headers. Receiving SPF, DKIM validated spam from Yahoo's email systems, then discovering there's absolutely no way in hell to kick it back to them, sours one rather rapidly. Trying to send mail to Yahoo has been roughly equally annoying for about as long.

Can you clarify regarding no way to kick it back to them? My understanding was that they operate typical feedback loops per RFC 6449 (though I haven't personally verified this). They also host a spam FAQ which has a link to a form to submit spam reports: https://help.yahoo.com/kb/SLN3402.html

Try self-hosted mail. The section on reporting spam from Yahoo conspicuously omits such options as submitting full headers to abuse or postmaster. Doing so in past (mutt, full headers) generates a "you're holding it wrong" messagee.

This goes back years, I've not tried recently, status may have changed. But again, the long, long term experience has been pretty sour.

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#44

Earlier quoted context omitted.

True, but Yahoo doesn't consider a properly DKIM or Domainkeys email something that should not just end up in the spam folder... My experience with Yahoo mail is that there are tons of false positives on spam, and that none of the headers matter much... preference is given to a small number of whitelisted sending companies.

Sorry, I was referring to messages received at my mail system that originate on Yahoo!'s mail system; more specifically, messages that are signed by a yahoo.com key and coming from a yahoo.com mail host (according to DKIM and SPF). Anyways... > "Yahoo doesn't consider a properly DKIM or Domainkeys email something that should not just end up in the spam folder" Nor should they. There's plenty of actual spam that passe…

> Nor should they

Of course not as the only criterion. But the messages in question were not spam, they were legitimate emails with DKIM, Domainkeys, SPF, long term non-spam IP address, etc.

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#45
post #36

Earlier quoted context omitted.

Can you clarify regarding no way to kick it back to them? My understanding was that they operate typical feedback loops per RFC 6449 (though I haven't personally verified this). They also host a spam FAQ which has a link to a form to submit spam reports: https://help.yahoo.com/kb/SLN3402.html

Try self-hosted mail. The section on reporting spam from Yahoo conspicuously omits such options as submitting full headers to abuse or postmaster. Doing so in past (mutt, full headers) generates a "you're holding it wrong" messagee. This goes back years, I've not tried recently, status may have changed. But again, the long, long term experience has been pretty sour.

The section on reporting spam from Yahoo has a link to a form where you can submit spam reports from Yahoo:

> Submit your report using our "Got Spam?" form if your email provider doesn't offer a spam reporting feature.

The "Got Spam?" link takes you to a form where you can supply the headers and content of the spam message sent from Yahoo.

Re: Notifying Our Users of Attacks by Suspected State-Sponsored Actors

#46
post #45

Earlier quoted context omitted.

Try self-hosted mail. The section on reporting spam from Yahoo conspicuously omits such options as submitting full headers to abuse or postmaster. Doing so in past (mutt, full headers) generates a "you're holding it wrong" messagee. This goes back years, I've not tried recently, status may have changed. But again, the long, long term experience has been pretty sour.

The section on reporting spam from Yahoo has a link to a form where you can submit spam reports from Yahoo: > Submit your report using our "Got Spam?" form if your email provider doesn't offer a spam reporting feature. The "Got Spam?" link takes you to a form where you can supply the headers and content of the spam message sent from Yahoo.

What part of "mail to abuse@ or postmaster@ fails" don't you understand?

The web-form workflow breaks in many ways: console tools (which I use for email), mobile, and more.

The fact that I can simply "bounce" the whole message at Yahoo's spamtraps, if they had such a thing, and they can sort the message's legitimacy and structure themselves, but they don't allow this, speaks volumes.

And again, this shit for a decade or more.

Now, if Yahoo wanted to creat CLI tools to incorporate into mailflows for those of us who know what we're doing to slot into their systems, great.

But ultimately, their problems aren't mine, I've washed my hands.

Post reply on HN