Live data from Hacker News

An Important Message About Yahoo User Security

yahoo.tumblr.com

1–10 of 356 posts

Re: An Important Message About Yahoo User Security

#2
Is there some kind of "statute of limitations" thing that means we're suddenly finding out about a string of breaches from 2012 now?

Or is there some group that is trading breach data privately that have themselves been compromised so that data coming from them is finally leaking out?

I'm now more worried about the 4 year delay in these things coming to light than the effect of the breaches themselves given how many times I now show up on haveibeenpwned.

Re: An Important Message About Yahoo User Security

#3

Is there some kind of "statute of limitations" thing that means we're suddenly finding out about a string of breaches from 2012 now? Or is there some group that is trading breach data privately that have themselves been compromised so that data coming from them is finally leaking out? I'm now more worried about the 4 year delay in these things coming to light than the effect of the breaches themselves given how many…

I am curious to know what happened in 2012 that all these breaches occurred. I assume they are holding the data, and trying to squeeze what they can out of it all the way through. However this year there seems to have been a lot of massive breaches that year. does it all stem from one hack? 200m Yahoo accounts could lead to at least a few million LinkedIn accounts I would assume, maybe not as many as was actually compromised in the LinkedIn breach, but still.

I just want to know if the same exploits were used in all of these instances. Or maybe they have just found backups for all these companies this year from 2012 and are using those. I don't even how that would happen.

Re: An Important Message About Yahoo User Security

#5
Moving email addresses out from one provider and creating another one is more difficult than moving phone numbers (in the latter case, number portability could help, if available).

What exactly can an average/common end user do for such incidents, even if it is to avoid them in the future? I use different passwords across accounts, with all of them being somewhat complex or very complex.

I have looked at a few different paid service providers before, but they're all very expensive. Expensive for me is anything that charges more than $20 per year, or worse, charges that amount or higher for every single email address/alias on a domain. My use of email for personal purposes is writing about a handful of emails in an entire year, but on the receiving side, I get a lot of emails - most of them somewhat commercial in nature (like online orders, bank statement notifications, marketing newsletters I've explicitly signed up for, etc.). I also have several email addresses, each one used for a different purpose and with some overlap across them.

It seems like web hosting has become extremely cheap over time whereas email hosting has stagnated on the price front for a long time.

Re: An Important Message About Yahoo User Security

#6

Moving email addresses out from one provider and creating another one is more difficult than moving phone numbers (in the latter case, number portability could help, if available). What exactly can an average/common end user do for such incidents, even if it is to avoid them in the future? I use different passwords across accounts, with all of them being somewhat complex or very complex. I have looked at a few differ…

This hack involves 2012 passwords, according to the Re/code coverage. If you've still got the same password, that's a problem. If you're changing passwords every year or so, your vulnerability drops.

Two-factor identification on any account that involves your money is a good idea, too.

Re: An Important Message About Yahoo User Security

#7

Moving email addresses out from one provider and creating another one is more difficult than moving phone numbers (in the latter case, number portability could help, if available). What exactly can an average/common end user do for such incidents, even if it is to avoid them in the future? I use different passwords across accounts, with all of them being somewhat complex or very complex. I have looked at a few differ…

I have had good luck with fastmail.com, but at $30/year for the entry-level option it sits in what you classify as the "expensive" category.

For a dedicated service with keen developers and ongoing product development (yay U2F support), great and accessible support, reasonable expectations of privacy, it has been well worth it. YMMV, of course.

Re: An Important Message About Yahoo User Security

#9
post #3

Is there some kind of "statute of limitations" thing that means we're suddenly finding out about a string of breaches from 2012 now? Or is there some group that is trading breach data privately that have themselves been compromised so that data coming from them is finally leaking out? I'm now more worried about the 4 year delay in these things coming to light than the effect of the breaches themselves given how many…

I am curious to know what happened in 2012 that all these breaches occurred. I assume they are holding the data, and trying to squeeze what they can out of it all the way through. However this year there seems to have been a lot of massive breaches that year. does it all stem from one hack? 200m Yahoo accounts could lead to at least a few million LinkedIn accounts I would assume, maybe not as many as was actually com…

If they found a yahoo employee credentials in the linkedin hack (or vice-versa) then they don't need a million accounts, just those credentials.

"Hackers who used an employee’s password, re-used from the LinkedIn breach, to access Dropbox’s corporate network and steal the user credentials" - from a unnamed source quoted in a techcrunch article.

So maybe they also managed to traverse from linkedin to Yahoo or Yahoo to linkedin through similar password re-use.

Re: An Important Message About Yahoo User Security

#10
post #6

Moving email addresses out from one provider and creating another one is more difficult than moving phone numbers (in the latter case, number portability could help, if available). What exactly can an average/common end user do for such incidents, even if it is to avoid them in the future? I use different passwords across accounts, with all of them being somewhat complex or very complex. I have looked at a few differ…

This hack involves 2012 passwords, according to the Re/code coverage. If you've still got the same password, that's a problem. If you're changing passwords every year or so, your vulnerability drops. Two-factor identification on any account that involves your money is a good idea, too.

It's true that this hack was in 2012, but the information lost is not only passwords but also account information like name, addresses, other linked email addresses, etc. So those who changed their passwords after this hack still have something to worry about.
Post reply on HN