"The data stolen may have included names, email addresses, telephone numbers, dates of birth and hashed passwords but may not have included unprotected passwords, payment card data or bank account information, the company said." What's the difference between "may have" and "may not have" in this context? It seems like they're saying anything could have been stolen.
An Important Message About Yahoo User Security
71–80 of 356 posts
Re: An Important Message About Yahoo User Security
#72"The data stolen may have included names, email addresses, telephone numbers, dates of birth and hashed passwords but may not have included unprotected passwords, payment card data or bank account information, the company said." What's the difference between "may have" and "may not have" in this context? It seems like they're saying anything could have been stolen.
Re: An Important Message About Yahoo User Security
#73"by what it believed was a "state-sponsored actor.""
Re: An Important Message About Yahoo User Security
#74GCHQ? Although GCHQ seems to have hacked them even earlier than that.
https://www.theguardian.com/world/2014/feb/27/gchq-nsa-webca...
Re: An Important Message About Yahoo User Security
#75You can verify if your credentials have been compromised at https://heroic.com
Re: An Important Message About Yahoo User Security
#76"by what it believed was a "state-sponsored actor.""
It seems like Yahoo's PR wants to switch focus to state-sponsored hacking and form a narrative around what's been in the news lately as opposed to Yahoo's incompetence.
Also it's less embarrassing to get hacked by a whole nation than a few nerds in their basement.
Re: An Important Message About Yahoo User Security
#77also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.
Re: An Important Message About Yahoo User Security
#78Re: An Important Message About Yahoo User Security
#79Re: An Important Message About Yahoo User Security
#80Yahoo's login experience has been horrible lately. This must be a contributing factor.
I logged in from my only computer, they presented my recovery email addresses with check boxes. I didn't read the prompt, but I selected the one I still use (one was so freaking old--a netzero address). It seemed to remove it from the list, which was the opposite of the behavior I'd expect. I literally didn't care enough to add it back. If I get locked out of my yahoo account...so?
Anyway, then they sent me a "new device" email that said I should login from one of my normal devices. It was my normal device, I just hadn't logged in for maybe...years? Surely they can alter the logic to not say something so stupid.