In case you are looking for the important information, it seems to be MD5 hash without salt.
Bloody hell. Sloppy and incompetent.
Yahoo discloses hack of 1B accounts
201–210 of 596 posts
Re: Yahoo discloses hack of 1B accounts
#202Sorry, there's no shielding Marrisa Mayer from this. Yes, she had only been there a year or so. But that's long enough she should have been on top of security. Yes, she's just killing time until she leaves now anyway. But, the symbolic statement is still important - she should resign.
Re: Yahoo discloses hack of 1B accounts
#203Fittingly, attempting to change my password to a 32-character random string generated by 1Password returns an error that the password "cannot contain my email or username", regardless of the contents of that random string (I tried several). It does, however, _happily_ accept `passwordpassword` and cheerily move along to confirming that my recovery email account from 2003 is still valid.
Not that it's much better. Is it so hard to allow 50 character passwords?
Re: Yahoo discloses hack of 1B accounts
#204When credit cards are compromised, the responsible party is usually responsible for providing identity theft protection. Why not tech firms that seek to store sensitive personal information? Maybe it'd scale back the desire for every firm to collect as much personal info as you'll provide them.
To be fair, that identity theft protection is lip service/worthless bullshit.
On the other hand, adding a price may embolden deep pocketed organizations to 'pay to absolve' for losing data to hackers on an ad hoc basis as a cheaper alternative to strong security and limiting data collection scope. In that case, the impotence of ID theft protection hurts a lot more.
Re: Yahoo discloses hack of 1B accounts
#205Earlier quoted context omitted.
It occurred in 2013
Unsalted MD5 has been demonstrated to be vulnerable to collisions since 2005. Rainbow tables existed way before 2013. There's no excuse for a tech company of this size.
Re: Yahoo discloses hack of 1B accounts
#206Earlier quoted context omitted.
But it's not like if we didn't have a pretty much continuous stream of major data leaks for the past 5 years. Surely yahoo engineers occasionally open a newspaper...
From everything I've read, the engineers did. The problem was that the security team had to go head-to-head with the budget team. And unfortunately, the budget team won - since the upper levels didn't feel that the IT security salaries were a necessary expenditure. And beyond that, there was concern that making people actually change their passwords regularly and requiring anything like security in said passwords was…
Re: Yahoo discloses hack of 1B accounts
#207Earlier quoted context omitted.
What do you mean by a password that can't be reasonably brute forced? EDIT: To clarify, I mean specifically with md5. I'm by no means an expert, just curious because I had considered md5 so broken that this comment caught my attention.
A preimage attack for MD5 has complexity of about 2^123. So, even if you get the MD5 hash for a password, it will be exceedingly hard to find a password that has the same hash (assuming the original password is long and random).
This site from 2006 claims they could find collisions in an average of 45 minutes on a 1.6 Ghz Pentium 4: http://www.bishopfox.com/resources/tools/other-free-tools/md...
If you account for speed increases over the last 10 years and assume the password thief has access to a botnet, then it wouldn't surprise me if they've found collisions for the entire list.
Edit: Nevermind, the link finds two strings that hash to the same thing; it does not find a string that hashes to an existing hash.
Re: Yahoo discloses hack of 1B accounts
#208> August 2013 > hashed passwords (using MD5) I don't even know what to say. > investigating the creation of forged cookies that could allow an intruder to access users' accounts without a password. Based on the ongoing investigation, we believe an unauthorized third party accessed our proprietary code to learn how to forge cookies How is this possible? Aren't most auth cookies just a session ID that can be used to lo…
1) As Yahoo "upgraded" all password storage in UDB (where all login / registration details are stored) to be bcrypt before 2013, I'm curious how this was possible. 2) Yahoo doesn't use a centralized session storage. If you know a few values (not disclosing the exact ones) from the UDB, it's theoretically (guess not so theoretical now) possible to create forged cookies if you steal the signing keys. To my knowledge, t…
In both cases I tried to track down backups, but discovered neither company was keeping them. That is another possible vector.
Re: Yahoo discloses hack of 1B accounts
#209Guys... let's just delete our Yahoo accounts. That company can't go bankrupt fast enough. It will sell our data for quarters.