Earlier quoted context omitted.
Yahoo has zero value as a web property. What value there is on the name and the advertising side.
> Yahoo has zero value as a web property What!? Surely you're being flippant. Alexa currently ranks Yahoo.com as #5 worldwide and in the United States. NUMBER 5! How anyone could think that has zero value makes no sense to me.
An Important Message About Yahoo User Security
171–180 of 356 posts
Re: An Important Message About Yahoo User Security
#172There’s one thing I don’t understand with this “state sponsored actor”. Say you are an oppressive regime and you target activists who use yahoo mail to publish your dirty laundry. Why on earth would you hack half a billion accounts just to get access to a few dozen ones? Doesn’t make sense. You attract too much attention. A thing like that would never go unnoticed. If on the other hand you’ve found some exploit and t…
Re: An Important Message About Yahoo User Security
#173Earlier quoted context omitted.
Is your service any better than haveibeenpwned.com ?
HIBP is a great service and was the first one on the scene. HEROIC has more breached records than HIBP and with a free account on HEROIC you can see more details about how you have been compromised along with better search capabilities.
Re: An Important Message About Yahoo User Security
#174Re: An Important Message About Yahoo User Security
#175It seems bizarre that Yahoo would use a post on tumblr.com to make such an important announcement. From what I've seen Tumblr has become mostly a wasteland of worthless garbage in the past few years and no one takes it seriously any more. Isn't this the sort of thing that ought to be on the yahoo.com home page from a PR crisis management standpoint?
Re: An Important Message About Yahoo User Security
#176Re: An Important Message About Yahoo User Security
#177"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this. also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.
Re: An Important Message About Yahoo User Security
#178Earlier quoted context omitted.
I believe a common reason for this is that they don't want to announce it until they're completely sure the breach is gone and that they have control of things again. Announcing that it happened and that it's ongoing forces them to either cease operations or face liability.
So covering up a known in-progress security breach is standard procedure? Instead of telling your users to change their passwords and so on? Personally, I demand criminal investigation and at least a $1000 fine per account breached.
Re: An Important Message About Yahoo User Security
#179"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this. also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.
- At least this is how I interpreted it. They put in all the right words: "threats, Industry, government, crosshairs, strategic".
Edit: "...by what it believes is a state..."??? Who is IT?
Re: An Important Message About Yahoo User Security
#180"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this. also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.
What sounds better?
A) We were hacked by a very powerful state sponsored enemy with an army of experts and a billion dollar budget.
B) We were hacked by bored 18 year old kid from Nova Scotia.