Yahoo installed a backdoor for the NSA behind the back of the security team
diracdeltas.github.io
Yahoo installed a backdoor for the NSA behind the back of the security team
1–10 of 302 posts
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#2But Yahoo definitely does not know how it got hacked, losing 1 billion accounts.
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#3Let's say you were on security on and found it on the network. Would you somehow be bound by a gag order about it, since you would never have seen said gag order?
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#4Why the panic? It's not like the FBI might try and throw an election or anything
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#5With the way the execs of Yahoo handled the 2015 back door, there is a likelihood that the 1 billion + 500 million compromised accounts were due to an exec decision that no one knew about. That individual or group of individuals may not be at Yahoo, and kept everything quiet. Or, the individuals may not even know that they did it!
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#6This is an old story that was discussed extensively when it was new (in October):
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#7Why the panic? It's not like the FBI might try and throw an election or anything
Funny, but it is actually the CIA that is attempting to throw the election. Proof is needed to change this opinion though...
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#8Fuck Yahoo, AOL and Verizon.
Re: Yahoo installed a backdoor for the NSA behind the back of the security team
#9Let's say you were on security on and found it on the network. Would you somehow be bound by a gag order about it, since you would never have seen said gag order?
I think it's irrelevant in practice. (In theory, that's an interesting question) You're not making the decision to make this public. If you're on the security team, you're going to notify the boss, and at that scale of the system compromise this goes all the way to the top. At that point someone who knows about the gag order is in the chain.
The only scenario where I think the question matters is if you do something really stupid that would get you fired if this was an actual exploited external access.