Live data from Hacker News

Yahoo discloses hack of 1B accounts

yahoo.tumblr.com

371–380 of 596 posts

Re: Yahoo discloses hack of 1B accounts

#371
post #341
post #24

I'm speechless. More and more are migrating to cloud these days, I expect more and more epidemic leakage will come. I host everything myself except for email, which is always a headache but contains more private info than all others I manage combined. Maybe it is time to run a small email server again but it is easily said than done, gosh please give me something like a working PGP or whatever for safe emails(PGP is…

I've heard that setting up an outbound email server on places like Linode or DO is tricky, because of how likely it is the IP block you're on will be considered spammy. To get around that, I rent a VPS from a local ISP here in Seattle. They have their own equipment, their own IP ranges, etc. It's a bit spendier than Linode but it's not breaking the bank.

good to know that, not sure if aws is better as far as IP-range-blocking is concerned.

Re: Yahoo discloses hack of 1B accounts

#372
post #165

Fittingly, attempting to change my password to a 32-character random string generated by 1Password returns an error that the password "cannot contain my email or username", regardless of the contents of that random string (I tried several). It does, however, _happily_ accept `passwordpassword` and cheerily move along to confirming that my recovery email account from 2003 is still valid.

Just follow NIST guidelines and never change it. That way when the servers in Utah crack your password, they don't have to recrack it later.

Re: Yahoo discloses hack of 1B accounts

#373
post #14

> August 2013 > hashed passwords (using MD5) I don't even know what to say. > investigating the creation of forged cookies that could allow an intruder to access users' accounts without a password. Based on the ongoing investigation, we believe an unauthorized third party accessed our proprietary code to learn how to forge cookies How is this possible? Aren't most auth cookies just a session ID that can be used to lo…

I'm wondering if this is one of the reason Alex Stamos left...

Re: Yahoo discloses hack of 1B accounts

#374
post #344

Earlier quoted context omitted.

While some offshore workers might not be MIT grads (/s) like you, branding them all as an incompetent group is neither fair nor correct. If offshoring didn't provide tangible value to the US IT industry it would've been shut down a while ago.

The tangible benefit is working for less money.

It is impossible for US corporations to do what they do with out offshoring unless migration policy is reformed , you can't have both ways guys. And offshore quality is bad is BS 99% percent of the time when you really analyze it is purportedly made to be as bad quality.

Re: Yahoo discloses hack of 1B accounts

#376
post #360
post #321

Earlier quoted context omitted.

There is actually no such thing as different human races (in the biological sense of the word). People who believe that are... you guessed it... called racists.

I honestly doubt that many people on this forum hold that opinion. I really hope not, anyway. I also haven't heard any good conversations about race that deny it. If you accept the existence of racism, you should accept the evident existence of race. I think the other-ness of offshore labor has parallels to many things in the history of racism—namely, the exploitation of xenophobia and tribalism to justify cheap labo…

> If you accept the existence of racism, you should accept the evident existence of race.

This seems to be a non sequitur to me. I can accept that people exist who divide humanity into X number of races based on some perceived fundamental differences and treat those groups differently without accepting that their divisions are valid and in practice real.

And in practice, race doesn't exist. That is, humans don't fit nicely into the given "race" boxes. For example, North Africans don't look much like Middle Africans, so are they part of the "black" race? How about native Malays, are they Asian? Or Indians, are they black, or a separate race? What about Pacific Islanders, are they black or Asian or a fourth race? Are Mediterraneans as "white" as Scandinavians? How about Bangladeshis, are they Asian or black or part of the "Indian" race if that exists? Are Arabs white or a different race or black? What about people who have grandparents who are white, black, Asian, and Middle Eastern? What race are they?

In practice, at best you can divide into broad familial groups typically centered in countries, which results in hundreds of ethnic groupings which could hardly be called "race" in the way it is commonly used. And those ethnic groupings are the result of large amounts of intermarriage and continue to intermarry, because humanity is a big mess of DNA originating from the same source, the first of the human race. The only human race that exists is humanity itself.

Re: Yahoo discloses hack of 1B accounts

#377

Earlier quoted context omitted.

Aren't the details "three years after we were hacked, law enforcement told us that we had been hacked, and we believe them?" The press release explicitly says "We have not been able to identify the intrusion associated with this theft." I especially noticed that the "What are we doing to protect our users?" section doesn't mention anything about Yahoo fixing any security issues. Presumably, then, as a Yahoo engineer,…

Do you honestly believe a press release covers every detail, especially ones with strong legal implications, and might not have rather been worded very carefully?

The contrast between your statements and the press statement is great enough to imply Yahoo is being dishonest.

Re: Yahoo discloses hack of 1B accounts

#379

Earlier quoted context omitted.

Do you honestly believe a press release covers every detail, especially ones with strong legal implications, and might not have rather been worded very carefully?

The contrast between your statements and the press statement is great enough to imply Yahoo is being dishonest.

"Dishonest", not in the slightest. From what I'm told, they really don't know how they got in. But that's only the part of the story discussed in the press release, what's not discussed is how the data existed in that format.

Re: Yahoo discloses hack of 1B accounts

#380
post #363

Security question : mothers maiden name?answer: 1q&#*v83%?ghd53 Date of birth : 01/01/2011

Using a random answer doesn't help against an attack it the security questions are stored in plain text. I'm not saying storing security questions as a hash is any better practice since these questions just need to go away. I am saying that most likely they aren't stored as hashes so a phone operator can query you hence random is only as good as something like BarkBarkRuffRuff for a maiden name.
Post reply on HN