Live data from Hacker News

An Important Message About Yahoo User Security

yahoo.tumblr.com

261–270 of 356 posts

Re: An Important Message About Yahoo User Security

#262
post #212
post #107

Earlier quoted context omitted.

Investors are conflicted: on the one hand, Yahoo had a data breach that will cost them trust, but on the other hand, investors are surprised to hear there are still 500 million Yahoo users.

500m users is different than 500m active users, plus I wonder how many people use yahoo for fantasy sports and nothing else

Yahoo hosts the email for many ISPs, including AT&T.

Re: An Important Message About Yahoo User Security

#263

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

It makes a lot of sense if you consider that most users don't give a damn about security.

They do when their identity is stolen.

Re: An Important Message About Yahoo User Security

#264
post #95
post #90

Earlier quoted context omitted.

Don't many sites require them?

Yes but the parent is telling you, as a developer, don't use them. Personally, I'll make up a fake answer (e.g. What's your favorite pizza topping? A:338192). Just make it something reasonably short as you might have to repeat it to a live customer service agent.

"My fave pizza is colon backslash open-cursive-brace pipe ay eight dollar with cheese".

Re: An Important Message About Yahoo User Security

#265

Earlier quoted context omitted.

Nobody seems to have any trouble with "jon@jrock.us", other than spelling "jon" wrong. I think one time someone at American Airlines said "oh, that's neat". Otherwise, nobody cares.

Congratulations on being the outlier!

I never have trouble either. You picked a particularly weird domain.

Re: An Important Message About Yahoo User Security

#266
post #107

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

Investors are conflicted: on the one hand, Yahoo had a data breach that will cost them trust, but on the other hand, investors are surprised to hear there are still 500 million Yahoo users.

What? You inferring this is actually part of a marketing campaign?

Re: An Important Message About Yahoo User Security

#267

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

Harvard Business review has a pretty good paper on this.

https://hbr.org/2015/03/why-data-breaches-dont-hurt-stock-pr...

Re: An Important Message About Yahoo User Security

#268
post #68

Earlier quoted context omitted.

for the longest time, it was unsalted MD5. it may still be. very easy to crack with a rainbow table.

"hashed passwords (the vast majority with bcrypt) and, in some cases, encrypted or unencrypted security questions and answers" The went on to say they have unactivated all clear text security questions. Really, WTF Yahoo. Why bother hashing a pw if you are going to have plaintext security questions. Though at least they were not using MD5

old accounts. the reason for the "vast majority" and "in some cases" terminology is very likely because the user records only get updated when the user logs in. for accounts that haven't been used in a long long time, it's possible you'd still find pre-bcrypt hashes and plain text question/answers.

Regarding your last sentence, I think other comments have chimed in on what they believe the pre-bcrypt hashes were made with.

Re: An Important Message About Yahoo User Security

#270
post #241

I found it rather perverse that the login and account recovery screens of Yahoo! have 3rd party ads running. Doesn't give me any confidence in their security (in addition to the breach).

You, sir, have just landed at an important topic that we're all too lax on. This third-party injected javascript into otherwise 'trusted' pages is a real serious issue.

Besides the 'kill all ads' talk which isn't very helpful, there really needs to be some serious conversation about how this particular issue with the internet is addressed.

Post reply on HN