Live data from Hacker News

An Important Message About Yahoo User Security

yahoo.tumblr.com

341–350 of 356 posts

Re: An Important Message About Yahoo User Security

#341
post #212
post #107

Earlier quoted context omitted.

Investors are conflicted: on the one hand, Yahoo had a data breach that will cost them trust, but on the other hand, investors are surprised to hear there are still 500 million Yahoo users.

500m users is different than 500m active users, plus I wonder how many people use yahoo for fantasy sports and nothing else

The good news about this breach is that it will greatly increase their "active user" count because of password reset logins. That looks good for the buyout deal.

Twitter did this to me right after their last not-so-great quarterly report came out: sent an email saying they have noticed "suspicious activity on my Twitter account and have suspended it. Click this link to reset your password." Which is kinda funny because I never posted one thing to my Twitter account. So locking it for me was the next best thing to deleting it.

When I got the LinkedIn breach email, I too just deleted my account there. Wasn't worth the fretting about security problems.

Re: An Important Message About Yahoo User Security

#342

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

Yahoo is being bought by Verizon, so unless VZ know decides to not purchase YHOO, the stock price is pretty much hard-coded. Otherwise there would be an arbitrage opportunity.

Re: An Important Message About Yahoo User Security

#343

Earlier quoted context omitted.

It is PR. It makes them seem less incompetent if the attack was performed by a "state sponsored actor".

I agree, but the typical PR spin tends to be "a sophisticated adversary". It'd look bad to say an attack was state sponsored if you didn't have good reason to believe it, since that's a pretty specific accusation. My guess is they hired a firm that actually knows security - probably FireEye or Crowdstrike - and their analysts came to that conclusion.

> It'd look bad to say an attack was state sponsored if you didn't have good reason to believe it

Did you just say it would "look bad"? They just had one of the biggest data breaches in history..

Re: An Important Message About Yahoo User Security

#345

Earlier quoted context omitted.

So, what would be the "signature" of a state-sponsored actor, what in this sort of hack costs money and resources on the scale of "[physical?] suppression of air defenses"?

Isn't the signature of state sponsored hacking basically: 1) careful, narrow targeting 2) sophisticated tools 3) being covert as possible 4) really being covert as possible Going for account info for 500 million accounts doesn't really fit #1.

To avoid being caught targeting one person you could choose to target all of them.

Re: An Important Message About Yahoo User Security

#346
post #256

Earlier quoted context omitted.

If you don't enter a password, then it isn't two factor auth at all. It just swapping one-factor (something you know) for another (something you have).

I know that it's not, I just said that I like it better than the two-factor auth that I use elsewhere. If I need to pull out my phone; its just easier to click my notification and click "approve", than to go to Authy to get the 6 digit code, and type it in to my computer.

Sorry, I misunderstood your statement. I thought you were comparing it to 2FA elsewhere. Now I see that you were just comparing it to the second factor elsewhere (not the whole 2FA0).

Re: An Important Message About Yahoo User Security

#347

Earlier quoted context omitted.

If you don't enter a password, then it isn't two factor auth at all. It just swapping one-factor (something you know) for another (something you have).

if something you have requires a password, you still have two-factor. Kind of.

Right, but in this case, it does not require a password. So it is not two-factor.

Re: An Important Message About Yahoo User Security

#348

Earlier quoted context omitted.

I often wonder if there really was a Linkedin breach, or if it was just to force people to remember they had a Linkedin account.

A LOT of people use Linkedin regularly, perhaps not where you live.

I hardly doubt so.

Re: An Important Message About Yahoo User Security

#349

Earlier quoted context omitted.

I agree, but the typical PR spin tends to be "a sophisticated adversary". It'd look bad to say an attack was state sponsored if you didn't have good reason to believe it, since that's a pretty specific accusation. My guess is they hired a firm that actually knows security - probably FireEye or Crowdstrike - and their analysts came to that conclusion.

> It'd look bad to say an attack was state sponsored if you didn't have good reason to believe it Did you just say it would "look bad"? They just had one of the biggest data breaches in history..

It'd look worse if security researchers started poking holes in their story. (Which has happened before for other breaches.)

Re: An Important Message About Yahoo User Security

#350
post #288

Earlier quoted context omitted.

I agree, but the typical PR spin tends to be "a sophisticated adversary". It'd look bad to say an attack was state sponsored if you didn't have good reason to believe it, since that's a pretty specific accusation. My guess is they hired a firm that actually knows security - probably FireEye or Crowdstrike - and their analysts came to that conclusion.

> since that's a pretty specific accusation. No it's not. It's an entirely vague specification. Was it the Russians, the Chinese, the NSA ? It's also something they'll never have to prove or verify so from a PR perspective it makes you look far less incompetent if you say 'state sponsored actor' instead of '17 year old high-schooler from Estonia'.

>It's also something they'll never have to prove or verify so from a PR perspective

I disagree. In breaches like these, attribution discussion begins pretty quickly after the announcement. If researchers find evidence it was some script kiddie or a black hat group or whatever, that would embarrass Yahoo even more.

If you don't know who the attacker is, you have nothing to lose by saying you were compromised by a sophisticated adversary in a targeted attack. You have more to lose by saying a nation-state attacked you if they actually didn't.

Post reply on HN