Live data from Hacker News

An Important Message About Yahoo User Security

yahoo.tumblr.com

251–260 of 356 posts

Re: An Important Message About Yahoo User Security

#252
post #167

Earlier quoted context omitted.

If I hand you an F-16 and you use it to do damage that would indicate possible US air force involvement. If the F-16 that attacked me was preceded by advanced ECM, suppression of air defenses using stand-off munitions, and was performed in a particular precision attack pattern then US air force involvement would be much more likely. These signatures are not just about the tools, but the opsec and procedures that the…

So, what would be the "signature" of a state-sponsored actor, what in this sort of hack costs money and resources on the scale of "[physical?] suppression of air defenses"?

It's not so much about scale as about characteristic types. If you find that the air defenses were suppressed with anti-radiation missiles that the US doesn't sell much or at all, that makes it reasonable to find US involvement more likely than the bombs just having come off an F-16's racks does. That's just as true whether one such missile was used, or one hundred.

(In military parlance "suppress" usually means not specifically to destroy, but to render ineffective. For example, at the infantry level, "suppressing fire" isn't intended specifically to kill members of an enemy formation, but rather to make them keep their heads down so as not to die, rather than doing something useful like actively opposing a move by another of your fire teams. In the case of anti-air defenses being suppressed to clear the way for an air attack, though, the tool of choice is going to be a standoff anti-radiation missile; see "Wild Weasels" for more detail on how it's done.)

Re: An Important Message About Yahoo User Security

#253
post #242

Earlier quoted context omitted.

Is that good? They have poor data handling and sunsetting protocols is what you're saying. UK law requires that personal data is not kept for longer than is necessary and is securely handled and such. So if those passwords in an "ancient DB" had personal data associated with them (real names, say) then they've been breaking the law (for a long time, is the implication). Surely if you had passwords in old DBs then whe…

Interesting point on the UK laws, but I doubt PII is kept alongside login data, just referenced, and removed as needed without removing a user's login credentials. Far from an expert, but hasn't flagging an account as needing a password change on next login been used as a way to migrate to properly encrypted passwords in the past?

Often. But you want to back it up with a blanket invalidation and password deletion after some grace period, to deal with the case where the user just never logs back in - and a password reset process outside the auth flow, to handle anyone who comes back after that.

Re: An Important Message About Yahoo User Security

#254
post #107

Earlier quoted context omitted.

Investors are conflicted: on the one hand, Yahoo had a data breach that will cost them trust, but on the other hand, investors are surprised to hear there are still 500 million Yahoo users.

It's because we all keep logging in to change our passwords.

Increased engagement!

Re: An Important Message About Yahoo User Security

#255

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

Yahoo are forever having security breaches. I think people kind of take it for granted.

Re: An Important Message About Yahoo User Security

#256
post #231

Earlier quoted context omitted.

I started using their "Account Key" process, any time I log in on the site from a computer, I get a notification from my Yahoo sports app (iPhone) asking me if I would like to allow the login attempt. I actually like it better than the two-factor auth I use for other accounts. Whether it's more secure or not, I don't know.. EDIT: just for clarification, this replaces the password entirely. So I never enter a password…

If you don't enter a password, then it isn't two factor auth at all. It just swapping one-factor (something you know) for another (something you have).

I know that it's not, I just said that I like it better than the two-factor auth that I use elsewhere. If I need to pull out my phone; its just easier to click my notification and click "approve", than to go to Authy to get the 6 digit code, and type it in to my computer.

Re: An Important Message About Yahoo User Security

#257
post #67

Earlier quoted context omitted.

On the flip side, I did that and while generally it's been a positive experience, providing your email address over the phone has become huge pain! I definitely took for granted how easy it is to say to someone "first initial + last name at major email provider . com", instead of "really easy first part at custom domain, wait let me give you the phonetic alphabet equivalent, no just the letter b, not actually the wor…

Nobody seems to have any trouble with "jon@jrock.us", other than spelling "jon" wrong. I think one time someone at American Airlines said "oh, that's neat". Otherwise, nobody cares.

Congratulations on being the outlier!

Re: An Important Message About Yahoo User Security

#258

Earlier quoted context omitted.

Oh I'm well aware around the uniques; Yahoo is ranked #5 in Alexa worldwide. Uniques do not count as users, however and my original conjecture stands in my opinion. Now if you have active, monthly user data that would be awesome to see :)

I'm not sure what you're trying to say. The algorithms adjust for bots, spam, cross-platform duplication, etc. 900M - 1B is defined as the Monthly Active Users figure. Naturally, there are areas where we know the algorithms are not translating the inputs to real users with 100% fidelity, but we know that the discount is relatively minor, not nearly as substantial as youre suggesting. Multiple counter-parties had thei…

> 900M - 1B is defined as the Monthly Active Users figure.

Okay that's the disconnect. Monthly uniques typically count is unique accesses of a web page by non-bots / spam. This is how I've seen it defined in every analytics software package I've ever used. Monthly active users is a vastly different concept as it implies repeat access within the month.

Though judging by the downvotes on my parent comment I'm guessing my thinking of the terms is NOT standard? Not going to lie I'm a bit confused around this. I'm going to have to look into it more.

Re: An Important Message About Yahoo User Security

#259

Moving email addresses out from one provider and creating another one is more difficult than moving phone numbers (in the latter case, number portability could help, if available). What exactly can an average/common end user do for such incidents, even if it is to avoid them in the future? I use different passwords across accounts, with all of them being somewhat complex or very complex. I have looked at a few differ…

I've had a Yahoo email for years and then got fed up with it so got a Gmail one and set Yahoo to forward to it. Works for me and I think Gmail is fairly secure. Yahoo seems kind of bad security wise. It's all free now though I used to have to pay Yahoo to forward.

Re: An Important Message About Yahoo User Security

#260

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

Actually, the stock price is being majorly affected today! YHOO usually tracks BABA quite precisely, and BABA was up big today (+3.5%). This usually means that YHOO would be up around 2%, which equates to nearly $1.00 in upside. Instead it was flat today.

To make matters worse, YHOO has actually fallen off quite a bit since BABA reached $105/share 1.5 weeks ago, and YHOO corresponded with a high of around $45. If you do the math, with BABA currently nearing $110, YHOO should actually be just north of $46.

tl;dr YHOO shares are actually suffering, but it's harder to see if you're not familiar with the underlying mechanisms at play.

Post reply on HN