Live data from Hacker News

Why We Should All Dump Yahoo

dumpyahoo.com

71–80 of 102 posts

Re: Why We Should All Dump Yahoo

#71
post #8

Yahoo is simply the first company that we publicly know of that scans incoming emails. If the government can force Yahoo, they will force all of them. Yahoo has more disgruntled former employees to reveal secrets than Google, Microsoft, etc...

To be fair, according to this article, Google, Microsoft, Apple, and others have explicitly denied allowing government officials direct access to their servers. However, due to the secrecy requirements of the law, we cannot know if they did allow the government some other form of access that was functionally equivalent to a rootkit on the server in terms of what the government could access. Pure speculation on my par…

> Google, Microsoft, Apple, and others have explicitly denied allowing government officials direct access to their servers

And the government can compel them to lie about that, too. So their statements are literally useless and cannot be trusted. Period.

Re: Why We Should All Dump Yahoo

#73
post #8

Yahoo is simply the first company that we publicly know of that scans incoming emails. If the government can force Yahoo, they will force all of them. Yahoo has more disgruntled former employees to reveal secrets than Google, Microsoft, etc...

The issue I have is that Yahoo evidently didn't even fight the order. Even if they thought they would lose, they should have at least attempted it.

Or maybe they decided it was better to make money selling us out?

Re: Why We Should All Dump Yahoo

#74
post #67

Earlier quoted context omitted.

What if I decide I don't want to share publicly. By then the contents of the page as I have viewed have been sent unencrypted.

Your headers would still be unencrypted -- including the domain and URL you accessed.

The domain is unencrypted over HTTPS, but the path is encrypted.

Re: Why We Should All Dump Yahoo

#75
post #2

While I agree with the sentiment. Here's why you should not delete your yahoo account. Once you delete your account, yahoo will make it available again to everyone. This means that if you have not unlinked everything it can be used by others to reset accounts on services you forgot that you linked to your yahoo account. Instead of deleting it, forward it all to another account and stop using it. Do not forget to log…

This is an excellent argument for setting up e-mail using your own domain name, though, and for using that for all new accounts and transitioning existing accounts to your new e-mail address as soon as possible. The Internet works just fine when it's decentralised, but particularly with e-mail, relying on the big service providers (or an ISP-provided address, for that matter) immediately locks you into someone else's…

Mail in a box makes this easy. https://mailinabox.email/

Or something like sovereign. https://github.com/sovereign/sovereign

Re: Why We Should All Dump Yahoo

#76

Earlier quoted context omitted.

Isn't your E-mail address used as the username in most services' credentials? So you should know which services you registered using your Yahoo E-mail address because that's what you use to log in. Just go in and change them over to using your new address. For those few that don't use E-mail, take a Sunday afternoon and log in to each of them to check. Surely it couldn't be that difficult.

I just checked LastPass; 324 out of 770 of my accounts use an email address as the username.

770 accounts?!!!

I think this whole "set up a service for everything" concept ain't workin'.

I'm trying to think how much storage just the TOS and Privacy Policies for those would run.

Re: Why We Should All Dump Yahoo

#78
post #6

The Yahoo fiasco is horrible, but it shouldn't come as a surprise to anyone who has heard of Snowden and his leaks. He talks about programs like this, though I don't remember the program's name. So, in other words, shouldn't we all have dumped Yahoo (and everyone else) in 2013? Also, it's rather irrelevant if you communicate mostly with other Yahoo, Gmail, etc. users because, unless you encrypt (good luck with gettin…

You are probably thinking of the PRISM program, which demands information from technology companies based on warrants from the secret FISA court [1], and the MUSCULAR program which sniffs internal Google/Yahoo cloud traffic from servers based in foreign countries. MUSCULAR is completely warrantless because the information is collected outside of the United States [2]. [1] https://en.wikipedia.org/wiki/PRISM_(surveill…

While these programs are horrible, I'd like to mention how great the naming of the programs have been. One of my favorites was FIRSTDATE then BADDECISION leading to SECONDDATE.

Again, not condoning behavior, I just wish I could be so creative when naming systems.

Re: Why We Should All Dump Yahoo

#79
post #14

Earlier quoted context omitted.

Right, something so basic to mail software that in 2016 it's still under development? I'm glad Engadget saw right through that too. It's pretty obvious they're doing whatever they can from losing users.

it seems that it wasn't forwarding that caused an issue, but rather its interaction with another new feature. For sure, Yahoo deserves more trust than what this article is giving it.

/s

Re: Why We Should All Dump Yahoo

#80

Earlier quoted context omitted.

Bruce Schneier agrees with you, which lends your argument some credence to me, but I thought "We’ve never received a request like this, and were we to receive it we’d challenge it in a court" was about as broad and clear a statement as could reasonably be made about this. What would you need them to say?

Something like "We do not have any programs or agreements whatsoever with law enforcement to share any user data or metadata or summaries or analysis of said information. We screen our employees for infiltration from intelligence community members, putting them only in positions where they can not influence our systems without significant risk of discovery and where they can not influence our systems without involvin…

Your proposed requests would include responding to legal warrants, which all of those companies already admit to doing.

Could I suggest "We do not ever voluntarily comply with any requests for user data or metadata or summaries or analysis, we resist involuntarily, legally mandated compliance as much as legally allowable, and we publish as much information about information we give away in as much detail as we legally can."?

Post reply on HN