Live data from Hacker News

An Important Message About Yahoo User Security

yahoo.tumblr.com

171–180 of 356 posts

Re: An Important Message About Yahoo User Security

#171
post #98

Earlier quoted context omitted.

Yahoo has zero value as a web property. What value there is on the name and the advertising side.

> Yahoo has zero value as a web property What!? Surely you're being flippant. Alexa currently ranks Yahoo.com as #5 worldwide and in the United States. NUMBER 5! How anyone could think that has zero value makes no sense to me.

Yeah I keep hearing the same thing, but obviously it's at least worth around what Verizon paid for it. I think it's actually worth more, but there is so much hate for the company and its management team.

Re: An Important Message About Yahoo User Security

#172

There’s one thing I don’t understand with this “state sponsored actor”. Say you are an oppressive regime and you target activists who use yahoo mail to publish your dirty laundry. Why on earth would you hack half a billion accounts just to get access to a few dozen ones? Doesn’t make sense. You attract too much attention. A thing like that would never go unnoticed. If on the other hand you’ve found some exploit and t…

The hack was probably "take a copy of the DB, decrypt our targets' password offline", not some sophisticated online attack.

Re: An Important Message About Yahoo User Security

#173

Earlier quoted context omitted.

Is your service any better than haveibeenpwned.com ?

HIBP is a great service and was the first one on the scene. HEROIC has more breached records than HIBP and with a free account on HEROIC you can see more details about how you have been compromised along with better search capabilities.

HIBP is still useful to me, at least, because it will let me find breaches for my entire domain, rather than just for specific email addresses. This is useful since I use a different email address per-site (username-somestring@domain), so just being able to search on my base email address on HEROIC isn't likely to turn much up...

Re: An Important Message About Yahoo User Security

#175
post #168

It seems bizarre that Yahoo would use a post on tumblr.com to make such an important announcement. From what I've seen Tumblr has become mostly a wasteland of worthless garbage in the past few years and no one takes it seriously any more. Isn't this the sort of thing that ought to be on the yahoo.com home page from a PR crisis management standpoint?

If you don't know, they own Tumblr, so maybe it's a "dogfooding" practice.

Re: An Important Message About Yahoo User Security

#176
One of the more convoluted announcements I've seen. I have to be aware that yahoo officially communicates via tumblr.com, check two different announcement pages which may not yet be up (converting time zones). When I clicked one of them I had to find the notice "in my region" which had only one option (not my region) and linked to another (non-yahoo?) site with an image of a document. I can't imagine all 500M users will jump through these hoops and remember when they last changed their password.

Re: An Important Message About Yahoo User Security

#177

"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this. also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.

I think it has to do with the sophistication of the attack. If they used multiple zero-days, multiple pieces of custom coded software, and a team of operators working full time for long periods of time then it can be assumed it's a multi-million dollar effort involving a large team of engineers. In such a case the list of potential adversaries can be reduced to corporate or state actors.

Re: An Important Message About Yahoo User Security

#178
post #137

Earlier quoted context omitted.

I believe a common reason for this is that they don't want to announce it until they're completely sure the breach is gone and that they have control of things again. Announcing that it happened and that it's ongoing forces them to either cease operations or face liability.

So covering up a known in-progress security breach is standard procedure? Instead of telling your users to change their passwords and so on? Personally, I demand criminal investigation and at least a $1000 fine per account breached.

Yes, making demands in a web forum is the way to resolve this.

Re: An Important Message About Yahoo User Security

#179

"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this. also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.

"I mean, look at this: it was a STATE-sponsored-entity that did that to us! We were overwhelmed... Did not stand a chance... I need a hug..."

- At least this is how I interpreted it. They put in all the right words: "threats, Industry, government, crosshairs, strategic".

Edit: "...by what it believes is a state..."??? Who is IT?

Re: An Important Message About Yahoo User Security

#180

"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this. also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.

While they might have seen some patterns of IP or other tell-tale signs (originating from specific IPs), it is also a powerful PR move.

What sounds better?

A) We were hacked by a very powerful state sponsored enemy with an army of experts and a billion dollar budget.

B) We were hacked by bored 18 year old kid from Nova Scotia.

Post reply on HN