Live data from Hacker News

An Important Message About Yahoo User Security

yahoo.tumblr.com

141–150 of 356 posts

Re: An Important Message About Yahoo User Security

#141

There’s one thing I don’t understand with this “state sponsored actor”. Say you are an oppressive regime and you target activists who use yahoo mail to publish your dirty laundry. Why on earth would you hack half a billion accounts just to get access to a few dozen ones? Doesn’t make sense. You attract too much attention. A thing like that would never go unnoticed. If on the other hand you’ve found some exploit and t…

Maybe you are NSA and you say "All your data are belong to US", as discovered by Snowden.

Re: An Important Message About Yahoo User Security

#142
post #107

Earlier quoted context omitted.

Investors are conflicted: on the one hand, Yahoo had a data breach that will cost them trust, but on the other hand, investors are surprised to hear there are still 500 million Yahoo users.

I don't think investors are quite that stupid. First that was 500m users in 2014 , not today. It also doesn't say active so it's likely some subset of a total. I wouldn't be surprised if Yahoo had even more than 500m accounts in 2014 and today but I would be SHOCKED if they had nearly that many active users.

Yahoo currently is clocking around 900M - 1B monthly uniques.

Consider that third-party tracking still places Yahoo as one of the top trafficked websites in the world, with only Google, Baidu, and Facebook higher.

Full disclosure: I work for Yahoo.

Re: An Important Message About Yahoo User Security

#143

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

The price of the stock has little to do with how the company does it's business or what it does.

It is as much about other investors as it is about the company itself.

The motivation there is pure profit, not some higher moral purpose or justice or "make the world better" idealism.

The stock price indirectly affects the company performance, just as the company performance affects the stock price, so it's a feedback loop (or conflict?) created between the investors and the company.

Apparently, investors think that this hack won't affect yahoo's performance or stock price.

These is just my interpretation of it of course, I guess very few people (if any) actually understand all the forces at play here.

Re: An Important Message About Yahoo User Security

#144

Earlier quoted context omitted.

IMO: State attack = a state steals the access and keep the breach secret for as long as they can [or until they get hacked themselves]. They use it for espionage and similar purposes Evil bad guy = all accounts and passwords are already available on blackmarket.com since Day+1 after the breach. They'll probably end up in a torrent within the next month. Evil bad guy sponsored by a state = Well, somewhere between the…

Once the accounts are for sale on the black market (they are), then the distinction between state and non-state is moot.

Do you have a source? Has it been mentioned that these accounts are afor sale?

Re: An Important Message About Yahoo User Security

#145

"The data stolen may have included names, email addresses, telephone numbers, dates of birth and hashed passwords but may not have included unprotected passwords, payment card data or bank account information, the company said." What's the difference between "may have" and "may not have" in this context? It seems like they're saying anything could have been stolen.

"may have" = "is likely to have", "may not have" = "is not likely to have".

Re: An Important Message About Yahoo User Security

#146

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

YHOO is being bought by Verizon. The stock price will not move out of a fixed range.

YHOO still owns a chunk of BABA. If (for whatever reason) BABA shoots up (or down), expect the stock price to follow very closely.

Re: An Important Message About Yahoo User Security

#147

"The data stolen may have included names, email addresses, telephone numbers, dates of birth and hashed passwords but may not have included unprotected passwords, payment card data or bank account information, the company said." What's the difference between "may have" and "may not have" in this context? It seems like they're saying anything could have been stolen.

> may not have included unprotected passwords Yeah, they shouldn't have unprotected passwords in any way, shape, or form. The statement makes it sound like they do store unprotected passwords, but they don't think those were stolen.

The other possibility is somehow intercepting them between SSL termination and hashing.

Re: An Important Message About Yahoo User Security

#149
post #107

Earlier quoted context omitted.

Investors are conflicted: on the one hand, Yahoo had a data breach that will cost them trust, but on the other hand, investors are surprised to hear there are still 500 million Yahoo users.

Nobody said they were active users.

I use Yahoo for fantasy sports. When I signed up I was forced to register a RocketMail account. Logging into Yahoo Fantasy is the only thing I've used it for. I wonder how many other people are in this scenario.

Some hacker might have my password, hopefully they don't pull Aaron Rodgers from my line up this week.

Re: An Important Message About Yahoo User Security

#150
post #64

"by what it believed was a "state-sponsored actor.""

The de facto excuse to use when you get hacked these days. Who could possibly defend against an entire nation? And it's incredibly easy to "prove" that some Russian IP accessed your system at some point, therefore Putin is directly involved and no amount of security would've prevented him from getting in.

Sidetracked: Can someone explain to me why there seem to be a culture of blackhat hacking from Russia? Do their CS degrees have mandatory advanced courses on how to exploit vulnerabilities for lulz?

Not really even saying this in a mean way. Almost all top CS programs in the US have assignments on writing buffer overflow attacks and reverse engineering in their mandatory intro to systems course. But I don't seem to see them going off on their own to learn more sophisticated attacks and acutally using it in the real world.

Why does russia seem to foster so many blackhats? Or is it just the proxies that are hosted there?

Post reply on HN