Live data from Hacker News

An Important Message About Yahoo User Security

yahoo.tumblr.com

81–90 of 356 posts

Re: An Important Message About Yahoo User Security

#82

"The data stolen may have included names, email addresses, telephone numbers, dates of birth and hashed passwords but may not have included unprotected passwords, payment card data or bank account information, the company said." What's the difference between "may have" and "may not have" in this context? It seems like they're saying anything could have been stolen.

That is an incredibly deceptive sentence. They should have listed everything under "may have", unless I'm misunderstanding because they used some convoluted English.

Re: An Important Message About Yahoo User Security

#84

"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this. also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.

all hacks have signatures.. usually the tools used by the hackers to compromise the system.

Re: An Important Message About Yahoo User Security

#86
post #64

"by what it believed was a "state-sponsored actor.""

The de facto excuse to use when you get hacked these days. Who could possibly defend against an entire nation? And it's incredibly easy to "prove" that some Russian IP accessed your system at some point, therefore Putin is directly involved and no amount of security would've prevented him from getting in.

Would a hacker who claims unemployment benefits be considered state sponsored?

Re: An Important Message About Yahoo User Security

#87
post #81

Does the incredible delay of this announcement count as being grossly negligent? Maybe they're trying to devalue their stock prior to the merger? Similar to what Caris did: http://www.law360.com/articles/684195/caris-employees-get-16...

Unfortunately probably not. All they have to say is that they weren't sure until now.

Re: An Important Message About Yahoo User Security

#88
post #64

"by what it believed was a "state-sponsored actor.""

I don't understand what difference it makes if it's state-sponsored or not. It seems like Yahoo's PR wants to switch focus to state-sponsored hacking and form a narrative around what's been in the news lately as opposed to Yahoo's incompetence. Also it's less embarrassing to get hacked by a whole nation than a few nerds in their basement.

If you're a human rights activist with a Yahoo account and Russia or China stole these passwords, then your communications have a much higher chances to have been breached and spied upon than if say, a Russian gang got their hands on this and used accounts to spread more ransomware around.

Re: An Important Message About Yahoo User Security

#89
You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

Re: An Important Message About Yahoo User Security

#90
post #60

"encrypted or unencrypted security questions and answers" This is bad right? Like, worse than your hashed password and your mailing address. The only good thing is that if I ever implement security questions, I'll remember Yahoo! and how it could end up in the wrong hands.

Don't implement security questions. Those are no good to begin with.

Don't many sites require them?
Post reply on HN