Live data from Hacker News

Yahoo discloses hack of 1B accounts

yahoo.tumblr.com

51–60 of 596 posts

Re: Yahoo discloses hack of 1B accounts

#51
post #14

> August 2013 > hashed passwords (using MD5) I don't even know what to say. > investigating the creation of forged cookies that could allow an intruder to access users' accounts without a password. Based on the ongoing investigation, we believe an unauthorized third party accessed our proprietary code to learn how to forge cookies How is this possible? Aren't most auth cookies just a session ID that can be used to lo…

1) As Yahoo "upgraded" all password storage in UDB (where all login / registration details are stored) to be bcrypt before 2013, I'm curious how this was possible. 2) Yahoo doesn't use a centralized session storage. If you know a few values (not disclosing the exact ones) from the UDB, it's theoretically (guess not so theoretical now) possible to create forged cookies if you steal the signing keys. To my knowledge, t…

Is the info about the Y and T cookies in this pdf [1][2] accurate?

[1] (EDIT: now with screenshots) http://imgur.com/a/g61VZ

[2] (Not affiliated with link, but the risk-averse may wish to open in a sandbox) ftp://hackbbs.org/milworm/270

Re: Yahoo discloses hack of 1B accounts

#52
MD5 in 2016?.I hope yahoo can save itself and tech community all this embarrassment by just going out of business one and for all.Folks at the helm of affairs at yahoo are incompetent. And it is about time government started to persecute incompetent CEO.

Re: Yahoo discloses hack of 1B accounts

#53

Earlier quoted context omitted.

Which only works until you call in asking for a password reset and when they ask you the question you just say "I just hit the keyboard a bunch".

No, I pull up the answer out of 1Password and read it off to them.

Sorry, I meant to imply that the support person will hear the explanation and let you reset the password without the actual answer.

Re: Yahoo discloses hack of 1B accounts

#54

Earlier quoted context omitted.

Which only works until you call in asking for a password reset and when they ask you the question you just say "I just hit the keyboard a bunch".

No, I pull up the answer out of 1Password and read it off to them.

"Charlie capital-echo lima peru capital-october..."

Re: Yahoo discloses hack of 1B accounts

#56
post #2

In case you are looking for the important information, it seems to be MD5 hash without salt.

Bloody hell. Sloppy and incompetent.

I'm genuinely curious how the decision to use MD5 gets made. Who says, "hey, maybe we should use MD5." And then who responds, "that sounds like a great idea Bob." Seriously. I've known for years that MD5 is insufficient for hashing passwords and I'm just some random guy. This kind of thing really baffles me.

Re: Yahoo discloses hack of 1B accounts

#58

Earlier quoted context omitted.

Bloody hell. Sloppy and incompetent.

I'm genuinely curious how the decision to use MD5 gets made. Who says, "hey, maybe we should use MD5." And then who responds, "that sounds like a great idea Bob." Seriously. I've known for years that MD5 is insufficient for hashing passwords and I'm just some random guy. This kind of thing really baffles me.

I doubt that decision was made in the last decade. It's surely just something that's been around for a long time and was never upgraded.

Still neglectful, but I sincerely doubt it was just a recent engineer's bad decision-making.

Re: Yahoo discloses hack of 1B accounts

#60

Earlier quoted context omitted.

No, I pull up the answer out of 1Password and read it off to them.

Sorry, I meant to imply that the support person will hear the explanation and let you reset the password without the actual answer.

Diceware is a decent option for security questions. They work fine over the phone.
Post reply on HN