Live data from Hacker News

An Important Message About Yahoo User Security

yahoo.tumblr.com

71–80 of 356 posts

Re: An Important Message About Yahoo User Security

#71

"The data stolen may have included names, email addresses, telephone numbers, dates of birth and hashed passwords but may not have included unprotected passwords, payment card data or bank account information, the company said." What's the difference between "may have" and "may not have" in this context? It seems like they're saying anything could have been stolen.

Or perhaps wasn't stolen, during the year that may or may not have been 2014. Sorry, ALLEGEDLY 2014.

Re: An Important Message About Yahoo User Security

#72

"The data stolen may have included names, email addresses, telephone numbers, dates of birth and hashed passwords but may not have included unprotected passwords, payment card data or bank account information, the company said." What's the difference between "may have" and "may not have" in this context? It seems like they're saying anything could have been stolen.

It's lawyer talk. They don't want to say anything definitively in case they have to walk it back.

Re: An Important Message About Yahoo User Security

#73
post #64

"by what it believed was a "state-sponsored actor.""

The de facto excuse to use when you get hacked these days. Who could possibly defend against an entire nation? And it's incredibly easy to "prove" that some Russian IP accessed your system at some point, therefore Putin is directly involved and no amount of security would've prevented him from getting in.

Re: An Important Message About Yahoo User Security

#74
> We have confirmed that a copy of certain user account information was stolen from the company’s network in late 2014 by what it believes is a state-sponsored actor.

GCHQ? Although GCHQ seems to have hacked them even earlier than that.

https://www.theguardian.com/world/2014/feb/27/gchq-nsa-webca...

Re: An Important Message About Yahoo User Security

#76
post #64

"by what it believed was a "state-sponsored actor.""

I don't understand what difference it makes if it's state-sponsored or not.

It seems like Yahoo's PR wants to switch focus to state-sponsored hacking and form a narrative around what's been in the news lately as opposed to Yahoo's incompetence.

Also it's less embarrassing to get hacked by a whole nation than a few nerds in their basement.

Re: An Important Message About Yahoo User Security

#77
"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this.

also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.

Re: An Important Message About Yahoo User Security

#80

Yahoo's login experience has been horrible lately. This must be a contributing factor.

I had a terrible experience recently. It was so dumb I wrote a rant to a no-reply address they had sent me some options about.

I logged in from my only computer, they presented my recovery email addresses with check boxes. I didn't read the prompt, but I selected the one I still use (one was so freaking old--a netzero address). It seemed to remove it from the list, which was the opposite of the behavior I'd expect. I literally didn't care enough to add it back. If I get locked out of my yahoo account...so?

Anyway, then they sent me a "new device" email that said I should login from one of my normal devices. It was my normal device, I just hadn't logged in for maybe...years? Surely they can alter the logic to not say something so stupid.

Post reply on HN