Live data from Hacker News

An Important Message About Yahoo User Security

yahoo.tumblr.com

161–170 of 356 posts

Re: An Important Message About Yahoo User Security

#161

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

Almost all of Yahoo's value is in its Alibaba holding.

https://www.bloomberg.com/view/articles/2015-12-02/yahoo-is-...

"Yahoo's actual core business of being Yahoo (and Tumblr and whatever) is worth negative $13 billion"

"Even after deducting 38 percent from the value of [the Alibaba shares] to account for taxes, you get a value for Yahoo's actual business of just $1.7 billion"

Re: An Important Message About Yahoo User Security

#162
post #151

Earlier quoted context omitted.

all hacks have signatures.. usually the tools used by the hackers to compromise the system.

> all hacks have signatures.. usually the tools used by the hackers to compromise the system. There's always the more basic: echo "Russians wuz here!" > /var/tmp/hacker.sig ( Bonus points to readers who understand why /var/tmp instead of /tmp :D )

http://unix.stackexchange.com/questions/30489/what-is-the-di...

Re: An Important Message About Yahoo User Security

#163

Earlier quoted context omitted.

That is an incredibly deceptive sentence. They should have listed everything under "may have", unless I'm misunderstanding because they used some convoluted English.

The way I read it is that the stolen data has a relatively high probability of including the first set of things, but a relatively low probability of including the second set of things. They don't want to say definitively for whatever reason.

I take it as "as far as we know, these weren't stolen, but don't sue us if we turn out to be wrong".

Re: An Important Message About Yahoo User Security

#164
post #137

Earlier quoted context omitted.

I believe a common reason for this is that they don't want to announce it until they're completely sure the breach is gone and that they have control of things again. Announcing that it happened and that it's ongoing forces them to either cease operations or face liability.

So covering up a known in-progress security breach is standard procedure? Instead of telling your users to change their passwords and so on? Personally, I demand criminal investigation and at least a $1000 fine per account breached.

I don't think they actually broke any laws. How do you expect them to be charged for your demands?

Re: An Important Message About Yahoo User Security

#165

"The data stolen may have included names, email addresses, telephone numbers, dates of birth and hashed passwords but may not have included unprotected passwords, payment card data or bank account information, the company said." What's the difference between "may have" and "may not have" in this context? It seems like they're saying anything could have been stolen.

That is an incredibly deceptive sentence. They should have listed everything under "may have", unless I'm misunderstanding because they used some convoluted English.

[deleted]

Re: An Important Message About Yahoo User Security

#167
post #155
post #92

Earlier quoted context omitted.

That means nothing. If a hacker somehow managed to get tools previously used by a state doesn't mean the hacker now works for the state.

didn't a cache of supposedly state-sponsored tools just get auctioned off by a group who (supposedly) compromised a machine which was under the ownership of one of the three-letter groups?[0] Seems to give more credence to the viewpoint that the tool doesn't indicate the perpetrator too easily. [0]: https://www.wired.com/2016/08/hackers-claim-auction-data-sto...

If I hand you an F-16 and you use it to do damage that would indicate possible US air force involvement. If the F-16 that attacked me was preceded by advanced ECM, suppression of air defenses using stand-off munitions, and was performed in a particular precision attack pattern then US air force involvement would be much more likely. These signatures are not just about the tools, but the opsec and procedures that the hackers used to deploy the tools, how they moved laterally to the target, and how they exfiltrated the information. It is the whole package that identifies a real state-sponsored actor vs a freelancer with access to a bag of zero days.

Re: An Important Message About Yahoo User Security

#168
It seems bizarre that Yahoo would use a post on tumblr.com to make such an important announcement. From what I've seen Tumblr has become mostly a wasteland of worthless garbage in the past few years and no one takes it seriously any more. Isn't this the sort of thing that ought to be on the yahoo.com home page from a PR crisis management standpoint?

Re: An Important Message About Yahoo User Security

#169

Yahoo will survive this regardless of their 'state sponsored' hand waving or not. The day the same happens to Google or Facebook will be very different.

Will it? Why? If anything, Google and Facebook seem to be more firmly entrenched in everyone's day-to-day lives and are more likely to get the "too big to fail" treatment.

Agreed. My sense is that if this happened to political heavyweights like Google or Facebook, we'd have serious diplomatic muscle on the case, as indeed we have already seen in the past with Google's China travails, or Obama's barely-hidden warnings to Europe about the antitrust fines.

Re: An Important Message About Yahoo User Security

#170
post #156
post #91

Earlier quoted context omitted.

You mean asking me my mother's maiden name or what school I went to isn't bullet proof?!

The problem is that people give the right answers. Mother's maiden name? Mozilla. School? Mio Fit.

Weird. My mother's maiden name is AjhuZ52nzFyDXDom4h8Vw01 and my school is 3zJi&MsGpSHf%z$GbDW!ngs7
Post reply on HN