Live data from Hacker News

Yahoo discloses hack of 1B accounts

yahoo.tumblr.com

301–310 of 596 posts

Re: Yahoo discloses hack of 1B accounts

#301
post #75

Earlier quoted context omitted.

I'm genuinely curious how the decision to use MD5 gets made. Who says, "hey, maybe we should use MD5." And then who responds, "that sounds like a great idea Bob." Seriously. I've known for years that MD5 is insufficient for hashing passwords and I'm just some random guy. This kind of thing really baffles me.

And nobody ever seemed to say "hey, maybe we should be using something more secure". Yahoo's been around for how many decades, and the fact they were still using MD5 in 2013 is just shameful. Yeah if it was some legacy code from 1993 you can probably excuse it, but I just can't believe after 20 years nobody thought it was a problem. I'm not really a software developer but I really can't imagine it being a huge change…

You're assuming engineering is just sitting on their thumbs, reviewing their code once a week, thinking of ways to optimize it.

In reality, they're constantly under pressure to develop new features, fix reported bugs, move on to the next project, keep the site from falling over, etc etc.

And the ones who choose NOT to work hard aren't sitting around reviewing old code either.

Re: Yahoo discloses hack of 1B accounts

#302
post #75

Earlier quoted context omitted.

And nobody ever seemed to say "hey, maybe we should be using something more secure". Yahoo's been around for how many decades, and the fact they were still using MD5 in 2013 is just shameful. Yeah if it was some legacy code from 1993 you can probably excuse it, but I just can't believe after 20 years nobody thought it was a problem. I'm not really a software developer but I really can't imagine it being a huge change…

There are likely to be a lot of identity systems using the password in the database, all of which have been coded to look for an MD5 hash, not a salted hash. This means code in a number of applications have to be updated at the same time. The typical way around this is to create your new destination column (e.g. sha256 with salt), and progressively have applications reference this column rather than the MD5 unsalted…

>It's a huge amount of work //

Really? Moving from doing md5(password) to bcrypt(password,salt)? I see organisations make things hard and legacy code-base, yadda, yadda but surely if Yahoo couldn't do this then they couldn't manage scratching their own butt; it really seems like quite a small change in the scheme of things. Like one senior engineer, one afternoon of work (then testing, etc., OK, sure) ... ?

Re: Yahoo discloses hack of 1B accounts

#303
post #244
post #195

Earlier quoted context omitted.

> I hate Google's mail interface Their IMAP interface is both standards compliant and fully functional. I'm not terribly fond of the Gmail web/native apps either, so I just don't use them (though I do occasionally hop on the web app when my client isn't searching the email as effectively as google does). With 2FA it can be a bit more work adding devices, but it's not a deal breaker for me.

I don't download my email. I have a webmail for a reason - I don't want a mail client with all its attendant files gumming up my PC. I moved off Netscape Communicator to webmail because it took up over 40% of my drive, and I've never regretted the decision. And I don't like 2FA either. It's a hassle and never, ever, worth my time or energy. There was one gaming service (I think it was an MMO) that demanded 2FA or bus…

> I don't like 2FA either

That seems to be a rather dangerous position to hold these days. I personally dislike that googles 2FA is SMS based (unless there's a way to use e.g. Authy with it that I'm unaware of), but still seems that the only way to be reasonably safe is a strong password and 2FA.

I'll add that The authy app on the Apple Watch has made 2FA for services that support it rather painless.

Re: Yahoo discloses hack of 1B accounts

#305
post #230

Technically; no. Bureacratically; maybe. Given the skill and self direction of offshore workers; impossibly.

While some offshore workers might not be MIT grads (/s) like you, branding them all as an incompetent group is neither fair nor correct. If offshoring didn't provide tangible value to the US IT industry it would've been shut down a while ago.

[deleted]

Re: Yahoo discloses hack of 1B accounts

#306
post #195

Earlier quoted context omitted.

> I hate Google's mail interface Their IMAP interface is both standards compliant and fully functional. I'm not terribly fond of the Gmail web/native apps either, so I just don't use them (though I do occasionally hop on the web app when my client isn't searching the email as effectively as google does). With 2FA it can be a bit more work adding devices, but it's not a deal breaker for me.

Their IMAP implementation is anything but compliant or functional. They implement labels as folders. Every time you use a label, it downloads that message multiple times and puts it into folders. Also when you try to write drafts in Thunderbird for Gmail, it stores them in such a way as each saved draft turns into part of the conversation (WTF?!) It makes conversations totally unreadable. I quite gmail years ago and…

Fair enough, I guess it's about differing usecases. The few labels that I do use on gmail are set up such that they are indistinguishable from folders (if they match a filter, they don't go in my inbox, and I don't have any overlapping labels). I also rarely have lingering draft emails, so I guess I've not noticed that particular issue (though I do use Mail.app, not thunderbird). Gmail's imap support has been adequate for me since they introduced it however long ago that was. YMMV

Edit: my point about standards compliance for gmail imap was purely about it actually working with third party clients, I've always known that it doesn't conceptually work the same way as a standard imap server.

Re: Yahoo discloses hack of 1B accounts

#307

Earlier quoted context omitted.

You've somehow managed to turn a bug report into a soundboard for your racist insecurities. Impressive. In a sad way.

Yes, 'offshore' is a race. Every critique is a racism. Coming from said 'offshore' (at least in regards to the US), I see that 'quality' people work remotely for monies comparable to the onsite workers, launch startups, et cetera. If you outsource to the offshore for the costs, guess what, you get lesser quality for the said cost. Nothing racist in that, but I understand your position - a SJW to every household!

race is a bogus concept anyway, "racism" is the everyday term for xenophobia. give it a break.

Re: Yahoo discloses hack of 1B accounts

#308
post #268

Earlier quoted context omitted.

... "offshore workers" are not a race. You realize offshore workers could be the same race as the person posting right?

Given the context, you know damn well what he means - it's coded speech and I refuse to believe that you're that naive.

You claim to be able to accurately discern intent from plaintext on the internet? If true you're wasted anywhere outside the justice system.

Re: Yahoo discloses hack of 1B accounts

#309

Earlier quoted context omitted.

I'd like to believe that. However, I was recently asked to test a new website for an organization I volunteer for, and discovered their "forgot password" flow emailed me my plaintext password. I wrote an explanation of why this was bad, and how it could be fixed, to a non-technical friend of mine who works there; he passed my email to the (Bay Area based!) consulting shop that did their website. The shop sent this re…

Just for clarity, the "forgot password" flow emailed you the current password of the account (not a temporarily one)? That's insane...

Yes, the current password.

Re: Yahoo discloses hack of 1B accounts

#310
post #203
post #165

Fittingly, attempting to change my password to a 32-character random string generated by 1Password returns an error that the password "cannot contain my email or username", regardless of the contents of that random string (I tried several). It does, however, _happily_ accept `passwordpassword` and cheerily move along to confirming that my recovery email account from 2003 is still valid.

Gonna guess that's a bad message for a password length violation or something else. Not that it's much better. Is it so hard to allow 50 character passwords?

if the password is stored properly, (i.e. bcrypt), the number of characters shouldn't matter at all, be it 50 or 5000.
Post reply on HN