"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this. also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.
all hacks have signatures.. usually the tools used by the hackers to compromise the system.
> all hacks have signatures.. usually the tools used by the hackers to compromise the system.
There's always the more basic:
echo "Russians wuz here!" > /var/tmp/hacker.sig
(Bonus points to readers who understand why /var/tmp instead of /tmp :D)
You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.
In this case, most are looking to how Verizon responds. The share price should be near equivalent to acquisition price. Verizon pulling out of the deal would see it plummet in my opinion. Edit: acquisition offer usually priced into share price, harder to calculate in this situation since Verizon isn't buying the whole company and all assets.
It is almost certain that this evolving risk was disclosed to Verizon (and other officially interested parties) during the initial stages of the sale negotiating process, and could well explain the difficult gestation of the Yahoo sale. Note that standard procedure would have been for interested parties wishing to enter into formal discussions, to sign watertight non-disclosures at the risk of very big legal liabilities if they don't abide by them. Any M&A professional would know that the valuation hit of "owning up early" is much smaller than the catastrophic effect of trying to hide such a thing until the inevitable noisy leak.
> may not have included unprotected passwords Yeah, they shouldn't have unprotected passwords in any way, shape, or form. The statement makes it sound like they do store unprotected passwords, but they don't think those were stolen.
The other possibility is somehow intercepting them between SSL termination and hashing.
That's a good point. If they got ahold of Yahoo's cert key they could even grab passwords before SSL termination.
all hacks have signatures.. usually the tools used by the hackers to compromise the system.
That means nothing. If a hacker somehow managed to get tools previously used by a state doesn't mean the hacker now works for the state.
didn't a cache of supposedly state-sponsored tools just get auctioned off by a group who (supposedly) compromised a machine which was under the ownership of one of the three-letter groups?[0]
Seems to give more credence to the viewpoint that the tool doesn't indicate the perpetrator too easily.
The de facto excuse to use when you get hacked these days. Who could possibly defend against an entire nation? And it's incredibly easy to "prove" that some Russian IP accessed your system at some point, therefore Putin is directly involved and no amount of security would've prevented him from getting in.
Sidetracked: Can someone explain to me why there seem to be a culture of blackhat hacking from Russia? Do their CS degrees have mandatory advanced courses on how to exploit vulnerabilities for lulz? Not really even saying this in a mean way. Almost all top CS programs in the US have assignments on writing buffer overflow attacks and reverse engineering in their mandatory intro to systems course. But I don't seem to s…
Maybe it's just that the avails of theft and fraud are not limited by prevailing wages in your area, so are relatively a better deal?
FWIW... I just logged in to my Yahoo Account and removed the security questions. Just to be sure. I had already changed my password a few months ago when first rumors of this came up. I'm pretty sure that the option to remove the security questions wasn't there back then.
I don't think investors are quite that stupid. First that was 500m users in 2014 , not today. It also doesn't say active so it's likely some subset of a total. I wouldn't be surprised if Yahoo had even more than 500m accounts in 2014 and today but I would be SHOCKED if they had nearly that many active users.
Yahoo currently is clocking around 900M - 1B monthly uniques. Consider that third-party tracking still places Yahoo as one of the top trafficked websites in the world, with only Google, Baidu, and Facebook higher. Full disclosure: I work for Yahoo.
Oh I'm well aware around the uniques; Yahoo is ranked #5 in Alexa worldwide. Uniques do not count as users, however and my original conjecture stands in my opinion. Now if you have active, monthly user data that would be awesome to see :)
I believe a common reason for this is that they don't want to announce it until they're completely sure the breach is gone and that they have control of things again. Announcing that it happened and that it's ongoing forces them to either cease operations or face liability.
So covering up a known in-progress security breach is standard procedure? Instead of telling your users to change their passwords and so on? Personally, I demand criminal investigation and at least a $1000 fine per account breached.
Yeah, that sucks because I have my business stuff with them (I know, I know). On the bright side I didn't receive an email so maybe they didn't get the biz accounts. Changed my pw anyway.
And something's changed with their biz accounts anyway- it's been sold/rebranded or something and I'm not sure where the future lays... :[