Live data from Hacker News

An Important Message About Yahoo User Security

yahoo.tumblr.com

191–200 of 356 posts

Re: An Important Message About Yahoo User Security

#191
post #151

Earlier quoted context omitted.

all hacks have signatures.. usually the tools used by the hackers to compromise the system.

> all hacks have signatures.. usually the tools used by the hackers to compromise the system. There's always the more basic: echo "Russians wuz here!" > /var/tmp/hacker.sig ( Bonus points to readers who understand why /var/tmp instead of /tmp :D )

> (Bonus points to readers who understand why /var/tmp instead of /tmp :D)

Because many newer Linux distributions mount /tmp as a tmpfs that gets zapped when the system shuts down. Do I get a no-prize?

> echo "Russians wuz here!" > /var/tmp/hacker.sig

Oh, that brings back memories of an incident involving Serbian/Romanian malware at a former employer of mine... when I got into the box to figure out why it was attempting to DoS Caltech, I found a complete set of DoSing tools in /root with comprehensive documentation in Romanian, plus a quick 'who' showed that the attacker was still logged in over SSH, so I looked up his IP and it came up as being somewhere in Serbia. After that, "Serbian Malware" became a meme at that company (and I quickly made sure to patch the hole -- the result of a stupid, stupid mistake that I take responsibility for -- to make sure it couldn't happen again).

Re: An Important Message About Yahoo User Security

#192
post #98

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

Yahoo has zero value as a web property. What value there is on the name and the advertising side.

you are drinking too much of the kool aid microsoft shills filed the news with when they were trying to forcefully acquire yahoo.

doubt if yahoo will ever recover. specially on the valley.

Re: An Important Message About Yahoo User Security

#193

Earlier quoted context omitted.

Yahoo currently is clocking around 900M - 1B monthly uniques. Consider that third-party tracking still places Yahoo as one of the top trafficked websites in the world, with only Google, Baidu, and Facebook higher. Full disclosure: I work for Yahoo.

Oh I'm well aware around the uniques; Yahoo is ranked #5 in Alexa worldwide. Uniques do not count as users, however and my original conjecture stands in my opinion. Now if you have active, monthly user data that would be awesome to see :)

I'm not sure what you're trying to say. The algorithms adjust for bots, spam, cross-platform duplication, etc. 900M - 1B is defined as the Monthly Active Users figure.

Naturally, there are areas where we know the algorithms are not translating the inputs to real users with 100% fidelity, but we know that the discount is relatively minor, not nearly as substantial as youre suggesting.

Multiple counter-parties had their teams diligence our user figures and associated algorithms and found them to be generally accurate representations.

Unless you're using a different definition of "active, monthly user" that deviates from the industry norms?

Re: An Important Message About Yahoo User Security

#194
post #67
post #14

Earlier quoted context omitted.

Buying a domain name is the equivalent of number portability. Recommended for everyone.

On the flip side, I did that and while generally it's been a positive experience, providing your email address over the phone has become huge pain! I definitely took for granted how easy it is to say to someone "first initial + last name at major email provider . com", instead of "really easy first part at custom domain, wait let me give you the phonetic alphabet equivalent, no just the letter b, not actually the wor…

Nobody seems to have any trouble with "jon@jrock.us", other than spelling "jon" wrong. I think one time someone at American Airlines said "oh, that's neat". Otherwise, nobody cares.

Re: An Important Message About Yahoo User Security

#195

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

[deleted]

Re: An Important Message About Yahoo User Security

#196
post #168

It seems bizarre that Yahoo would use a post on tumblr.com to make such an important announcement. From what I've seen Tumblr has become mostly a wasteland of worthless garbage in the past few years and no one takes it seriously any more. Isn't this the sort of thing that ought to be on the yahoo.com home page from a PR crisis management standpoint?

All press is good press?

Re: An Important Message About Yahoo User Security

#200
post #111
post #12

Earlier quoted context omitted.

Zoho has a free, ad-free service¹ that allows: 1 domain, 5GB per user e-mail hosting, and 5GB per user document storage for up to 25 users. Pricing seems reasonable beyond that. They provide incentives in the form of additional users for referrals (my referral code: WX7yxEKy). They also support 2-factor authentication. ¹ https://www.zoho.com/mail/zohomail-pricing.html

I love how every time a company is compromised, everyone pops with their own "uncompromised" service offer. As if, this one would never get compromised and they were much better at it. Except they probably aren't. Bet the devs have all keys on their "work" laptop (you know, the one with stickers that they take home, to starbucks, on vacations, watch their movies on, etc.) (like everyone elses is doing) Sooo narrow-si…

I think it's useful information. Many people are not aware of alternatives.

Plus, it would be better for all concerned to have 25 smaller companies with 20M accounts each than one company with 500M accounts. Less of a security monoculture, and fewer eggs in a single basket when it does get compromised.

From a user's perspective, although it may be less convenient, it's probably healthier to use a bunch of services offered by a bunch of different companies than to work with a single company for all digital needs.

Post reply on HN