Live data from Hacker News

An Important Message About Yahoo User Security

yahoo.tumblr.com

51–60 of 356 posts

Re: An Important Message About Yahoo User Security

#51
post #50

Earlier quoted context omitted.

Right, but it still needs an email service provider to point to (and I wouldn't want to run it myself for various reasons). And the providers I've seen are expensive (for me).

Did Google stop offering a free tier for Apps For Your Domain? I guess I missed the part about being grandfathered in.

Yes. It's now $5/month/user. (plans are grandfathered however)

Re: An Important Message About Yahoo User Security

#55
post #6

Earlier quoted context omitted.

This hack involves 2012 passwords, according to the Re/code coverage. If you've still got the same password, that's a problem. If you're changing passwords every year or so, your vulnerability drops. Two-factor identification on any account that involves your money is a good idea, too.

It's true that this hack was in 2012, but the information lost is not only passwords but also account information like name, addresses, other linked email addresses, etc. So those who changed their passwords after this hack still have something to worry about.

True, but if you've got any internet presence at all, it's already pretty straightforward to associate your name and email address (or addresses). Tools like Datanyze, Spokeo, SellHack, etc. do that routinely. Having 120 million Yahoo records available for mischief (without current passwords) makes things slightly worse, but not much.

Re: An Important Message About Yahoo User Security

#57

I wonder how many dummy accounts from the mid-2000s of mine were included in that. I was born in 1990, and my insecure online behavior from 2000-2005 scare me. Hopefully HaveIBeenPwned gets their hands on this so I can scan for my teenage usernames.

Same here. I've gotta have at least 10 accounts from 1996-2002.

Re: An Important Message About Yahoo User Security

#59
"encrypted or unencrypted security questions and answers"

This is bad right? Like, worse than your hashed password and your mailing address.

The only good thing is that if I ever implement security questions, I'll remember Yahoo! and how it could end up in the wrong hands.

Re: An Important Message About Yahoo User Security

#60

"encrypted or unencrypted security questions and answers" This is bad right? Like, worse than your hashed password and your mailing address. The only good thing is that if I ever implement security questions, I'll remember Yahoo! and how it could end up in the wrong hands.

Don't implement security questions. Those are no good to begin with.
Post reply on HN