Live data from Hacker News

Yahoo discloses hack of 1B accounts

yahoo.tumblr.com

231–240 of 596 posts

Re: Yahoo discloses hack of 1B accounts

#231
post #208

Earlier quoted context omitted.

1) As Yahoo "upgraded" all password storage in UDB (where all login / registration details are stored) to be bcrypt before 2013, I'm curious how this was possible. 2) Yahoo doesn't use a centralized session storage. If you know a few values (not disclosing the exact ones) from the UDB, it's theoretically (guess not so theoretical now) possible to create forged cookies if you steal the signing keys. To my knowledge, t…

On a number of engagements I've come across password databases that have been migrated to bcrypt. In one case I checked CVS to see who made the code change, and found the MD5 passwords on his dev box. In another I tracked down a MySQL slave that had broken replication for over a year. In both cases I tried to track down backups, but discovered neither company was keeping them. That is another possible vector.

1) I'd be flabbergasted beyond belief if there was ever a Yahoo! engineer who had user passwords on their laptop / Dev box. The technical hurdle for that would be a stretch, let alone the fact of the other ramifications of doing this.

2) there's no SQL database involved with Yahoo!'s storage of passwords. It's a custom built db system with proprietary access and replication protocols.

Re: Yahoo discloses hack of 1B accounts

#232
post #165

Fittingly, attempting to change my password to a 32-character random string generated by 1Password returns an error that the password "cannot contain my email or username", regardless of the contents of that random string (I tried several). It does, however, _happily_ accept `passwordpassword` and cheerily move along to confirming that my recovery email account from 2003 is still valid.

Just leave it at passwordpassword, it will be leaked eventually anyway Strong passwords that need to be memorized shouldn't be wasted on security bozos

He doesn't need to memorize it. He mentioned he used 1Password to generate it. I'd assume he's storing it there too.

Re: Yahoo discloses hack of 1B accounts

#233

Earlier quoted context omitted.

What do you mean by a password that can't be reasonably brute forced? EDIT: To clarify, I mean specifically with md5. I'm by no means an expert, just curious because I had considered md5 so broken that this comment caught my attention.

Rumours of MD5's death have been greatly exaggerated. MD5's weakness is that it's (relatively) easy to produce two strings which have the same hash. However, given an MD5 hash, it's not easy to produce a string which also has that hash. In principle , one could intentionally construct two passwords which have the same hash. It's hard to see how that could be exploited maliciously - any attacker knows both passwords t…

[deleted]

Re: Yahoo discloses hack of 1B accounts

#234
post #218
post #153

Earlier quoted context omitted.

If Yahoo goes down, I won't have email; or at best I'll maybe keep a Zoho. I hate Google's mail interface, I hate the way they make 'conversations' out of discrete emails, and I especially hate their lack of folders. I use GMail begrudgingly at work, and only when necessary, and every time, I look at it and go, "what dipshit ever thought this was a functional way to deal with email?" As a dedicated Windows user, I'm…

> I especially hate their lack of folders GMail supports labels as folders. When you create a new label it will ask you if you want to nest the label under another label and you can do this repeatedly to make a nested folder structure. Crucially, this will show up as nested folders via IMAP.

No, no - I understand that you can think this, and that they claim it, but from a UI angle, it's wrong. I hate the implementation of labels.

They don't actually disappear when I click on inbox. When I want my inbox, I want just that folder - all filtered content goes elsewhere and disappears until I want it. That's not GMail's way.

Re: Yahoo discloses hack of 1B accounts

#235
post #104

What value does Yahoo have for Verizon now, the brand is so tainted?

I'm not sure Average Joe really associates these hacks with incompetence or negligence. Those nasty hackers are making victims of poor Yahoo.

Average joe won't even know what happened let alone care about it. A small minority of hackers care/know how shitty Yahoo! is, and that's about it.

Re: Yahoo discloses hack of 1B accounts

#237
post #219
post #137

Earlier quoted context omitted.

Even anarcho-capitalists, the most hardcore libertarians, believe heavily in the court system. So I'm not sure what the OP means "without lawsuits". Because lawsuits would most likely be their answer here. Also maybe competition from other email vendors who take your security seriously and doesn't leak 1 billion emails? Or pressure from investors not to create that type of liability? Pretty obviously a strawman, it's…

Seems that anarchy is contrary to government, and out of necessity a government is needed to have a court. Those pure free market types I'm referring to self describe exactly as anarcho capitalists and say all disputes are resolved by insurance, exactly zero government. If there's a court, maybe that's a venue the insurance companies all agree upon. But if you don't have insurance or don't have good enough insurance…

Quoting Mises who is the Marx of anarcho-capitalism:

> To be opposed to the state is then not necessarily to be opposed to services that have often been linked with it; to be opposed to the state does not necessarily imply that we must be opposed to police protection, courts, arbitration, the minting of money, postal service, or roads and highways. Some anarchists have indeed been opposed to police and to all physical coercion in defense of person and property, but this is not inherent in and is fundamentally irrelevant to the anarchist position, which is precisely marked by opposition to all physical coercion invasive of, or aggressing against, person and property.

and

> An important point to remember is that any society, be it statist or anarchist, has to have some way of resolving disputes that will gain a majority consensus in society. There would be no need for courts or arbitrators if everyone were omniscient and knew instantaneously which persons were guilty of any given crime or violation of contract. Since none of us is omniscient, there has to be some method of deciding who is the criminal or lawbreaker which will gain legitimacy; in short, whose decision will be accepted by the great majority of the public.

https://mises.org/library/society-without-state

(Note: not defending this stuff, just pointing it out for sake of discussion).

Elsewhere someone pointed out the book "Anarchy, State, and Utopia" which has a better overview of what libertarians believe in. Which is a "night-watchman" state, a minimalist government which includes courts, police, and border control.

https://www.amazon.com/Anarchy-State-Utopia-Robert-Nozick/dp...

Re: Yahoo discloses hack of 1B accounts

#238

Earlier quoted context omitted.

Just leave it at passwordpassword, it will be leaked eventually anyway Strong passwords that need to be memorized shouldn't be wasted on security bozos

He doesn't need to memorize it. He mentioned he used 1Password to generate it. I'd assume he's storing it there too.

At the very least you need to memorize the 1pw password, but I do memorize some others as well

Re: Yahoo discloses hack of 1B accounts

#239
post #142

Earlier quoted context omitted.

I had a Yahoo account entirely to use a Yahoo email list; I used to have it for Yahoo chat, but I haven't used that in years. So I ignored the hack a few months ago. I also never got notified that I was vulnerable. Just now I tried to log in to see if my password had been invalidated. Nope. It was my old insecure "pattern-based" password (myprefixYAHOO) that I use nowhere any more. Probably short enough to have brute…

It's more that there's more then 1B accounts out there - remember that this isn't just "yahoo.com" that got affected, it's Yahoo, YMail, RocketMail, yahoo.co.jp (a HUGE community btw), and several others which all fall under the "Yahoo accounts" umbrella. Not every account was hacked by any means; terrifyingly, the number of accounts isn't nearly what you'd expect as a percentage of "Yahoo accounts".

[deleted]

Re: Yahoo discloses hack of 1B accounts

#240

there's a couple of things that these major providers getting pwned teaches you: 1) their security isn't good just because of their scale/size (that begins to seem more and more like a false-assumption nowadays) 2) migrating your email to a new provider is quite difficult (consider that the average person will have just 1 - or 2 - email accounts and they link EVERYTHING to it) 3) the price of ads/convenience is no lo…

Migrating e-mail is very difficult, especially if you're like me and decide to setup your own e-mail server. The biggest problem I had was my e-mail getting falsely classified as spam:

http://penguindreams.org/blog/how-google-and-microsoft-made-...

I've also occasionally found really old services that use my old e-mail account. Even thought I have the password, they still require e-mail verification; which can't be done because the gmail account doesn't exist and it bounces.

Post reply on HN