Live data from Hacker News

An Important Message About Yahoo User Security

yahoo.tumblr.com

231–240 of 356 posts

Re: An Important Message About Yahoo User Security

#231
post #149

Earlier quoted context omitted.

I use Yahoo for fantasy sports. When I signed up I was forced to register a RocketMail account. Logging into Yahoo Fantasy is the only thing I've used it for. I wonder how many other people are in this scenario. Some hacker might have my password, hopefully they don't pull Aaron Rodgers from my line up this week.

Yahoo's been authenticating me nearly every time I try to access the fantasy app on my phone. They've made me change my password 3 times in the past month or so. And the password I set doesn't seem to work, so I keep having to use their phone based authentication. With all the money that they have, it's hard to fathom how Yahoo is so bad at delivering secure identity services.

I started using their "Account Key" process, any time I log in on the site from a computer, I get a notification from my Yahoo sports app (iPhone) asking me if I would like to allow the login attempt. I actually like it better than the two-factor auth I use for other accounts. Whether it's more secure or not, I don't know..

EDIT: just for clarification, this replaces the password entirely. So I never enter a password on the site.

Re: An Important Message About Yahoo User Security

#232

Earlier quoted context omitted.

You also get 1TB of storage with that, and unlimited storage with 5+ accounts. I do this for my family, and we all have unlimited backups and custom domain email.

What client software do you use to access the storage and to backup to it? Is it reliable and cross-platform, by any chance? =)

I use Arq https://www.arqbackup.com

Encrypts everything, and manages the revisions. Available for Mac and Windows. I use for Mac.

Re: An Important Message About Yahoo User Security

#233
post #219

Earlier quoted context omitted.

> may not have included unprotected passwords Yeah, they shouldn't have unprotected passwords in any way, shape, or form. The statement makes it sound like they do store unprotected passwords, but they don't think those were stolen.

I read it as perhaps some old dormant accounts never got migrated out of an ancient DB, and may have been picked up with the rest of the data. Yahoo is an old company, I'm sure procedures have changed drastically over the years.

Is that good? They have poor data handling and sunsetting protocols is what you're saying.

UK law requires that personal data is not kept for longer than is necessary and is securely handled and such. So if those passwords in an "ancient DB" had personal data associated with them (real names, say) then they've been breaking the law (for a long time, is the implication).

Surely if you had passwords in old DBs then when you introduce hashing you salt and hash them and sanitise the DB and all backups ... having them still hanging around is a significant failure too. But yes, not as significant as having plaintext passwords in DBs now would be.

Re: An Important Message About Yahoo User Security

#234
post #107

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

Investors are conflicted: on the one hand, Yahoo had a data breach that will cost them trust, but on the other hand, investors are surprised to hear there are still 500 million Yahoo users.

It's because we all keep logging in to change our passwords.

Re: An Important Message About Yahoo User Security

#235

"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this. also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.

[deleted]

Re: An Important Message About Yahoo User Security

#236
post #171

Earlier quoted context omitted.

> Yahoo has zero value as a web property What!? Surely you're being flippant. Alexa currently ranks Yahoo.com as #5 worldwide and in the United States. NUMBER 5! How anyone could think that has zero value makes no sense to me.

Yeah I keep hearing the same thing, but obviously it's at least worth around what Verizon paid for it. I think it's actually worth more, but there is so much hate for the company and its management team.

While the thing you're responding to is obviously idiotic it occurs to me that the sanity of the valuation of Yahoo! is not "obvious" at all. It's a result of the application of partially visible heuristics to determine the worth of things like users, views, "talent," and etc, all passed through back-room dealing at the executive level and bargaining behind closed doors.

The reason I bother coming here to say this is that I think the idea that 4.8 billion dollars "makes sense" to an outsider is endemic of thinking that leads to a dangerous lack of regulation. In other words, I'd be careful not to assume that the left hand always knows what the right hand is doing in companies at this scale.

Re: An Important Message About Yahoo User Security

#237
post #177

Earlier quoted context omitted.

I think it has to do with the sophistication of the attack. If they used multiple zero-days, multiple pieces of custom coded software, and a team of operators working full time for long periods of time then it can be assumed it's a multi-million dollar effort involving a large team of engineers. In such a case the list of potential adversaries can be reduced to corporate or state actors.

It is PR. It makes them seem less incompetent if the attack was performed by a "state sponsored actor".

I agree, but the typical PR spin tends to be "a sophisticated adversary". It'd look bad to say an attack was state sponsored if you didn't have good reason to believe it, since that's a pretty specific accusation.

My guess is they hired a firm that actually knows security - probably FireEye or Crowdstrike - and their analysts came to that conclusion.

Re: An Important Message About Yahoo User Security

#238

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

Many hedge funds spent time analyzing the effect on a stock price after breach disclosure. From what I read overall, the only negative effect comes if the breach is repeated over longer period of time in media. But as Elena Kvochko put it, "shareholders are numb to news of data breaches" [0].

[0] https://hbr.org/2015/03/why-data-breaches-dont-hurt-stock-pr...

Re: An Important Message About Yahoo User Security

#239
post #177

Earlier quoted context omitted.

I think it has to do with the sophistication of the attack. If they used multiple zero-days, multiple pieces of custom coded software, and a team of operators working full time for long periods of time then it can be assumed it's a multi-million dollar effort involving a large team of engineers. In such a case the list of potential adversaries can be reduced to corporate or state actors.

>potential adversaries can be reduced to corporate or state actors // Don't black-hat hacker groups exist?

Yes. There have been several that operate at a level equivalent to state-sponsored actors.

"Corporate adversaries" are pretty much a myth, or are just a black hat group hired by a company.

Re: An Important Message About Yahoo User Security

#240
post #231

Earlier quoted context omitted.

Yahoo's been authenticating me nearly every time I try to access the fantasy app on my phone. They've made me change my password 3 times in the past month or so. And the password I set doesn't seem to work, so I keep having to use their phone based authentication. With all the money that they have, it's hard to fathom how Yahoo is so bad at delivering secure identity services.

I started using their "Account Key" process, any time I log in on the site from a computer, I get a notification from my Yahoo sports app (iPhone) asking me if I would like to allow the login attempt. I actually like it better than the two-factor auth I use for other accounts. Whether it's more secure or not, I don't know.. EDIT: just for clarification, this replaces the password entirely. So I never enter a password…

If you don't enter a password, then it isn't two factor auth at all. It just swapping one-factor (something you know) for another (something you have).
Post reply on HN