Live data from Hacker News

Yahoo Triples Estimate of Breached Accounts to 3B

wsj.com

61–70 of 311 posts

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#61

Earlier quoted context omitted.

I know a guy who uses a service that creates a unique email account for every service he signs up for. That way, he tells me, if he ever gets any spam, he can delete the account and it doesn't affect any of his other email accounts.

With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header.

It really baffles me that people are still suggesting this as advice for spam reduction. All it takes is a third of a brain and a couple seconds of thought to realize that spammers know this is a thing and can adapt.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#62

Earlier quoted context omitted.

With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header.

Yeah, you do realize spammers know that, too? They will just strip part after the +

Of course I do. But most don't bother, and it still works today.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#63

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service

How much do you actually need to know about someone to serve up email to them?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#64
post #47

Earlier quoted context omitted.

Here's a bookmarklet I use sometimes: javascript:window.location.href='https://m.facebook.com/l.php?u='+encodeURIComponent(window.location.href);

Real LPT in the comments!

This isn't reddit. Keep that meme-y crap out of here.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#66

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service

> You really do need user accounts to run an email service

Exactly, regardless of that companies keep asking users for a whole collection of personal data, not always making it obvious which fields are actually required because it's good business for them to get as much personal data as possible.

Average users are usually unsure about a lot of this stuff and naive enough to enter their real data for fear of getting caught "lying".

This happens because companies see this data as an asset instead of a liability, from the companies view not asking for that data/tricking users into giving it away means missing out on assets.

But if you instead make the personal data a liability, by enforcing standards for keeping/sharing it with hefty fines, then fewer companies will go out of their way asking users for personal information they have no business asking for in the first place because it would put them in a position of liability for what happens with said data.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#67
post #54

Earlier quoted context omitted.

With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header.

I’ve run a fair amount of email campaigns where we strip out the + if gmail is the domain to ensure it doesn’t end up in some weird filter. Dick move, I know. Tell marketing that though. I personally use gmail through a vanity domain and have a catch all rule, so I end up signing up with a fake email account for every domain (hn@mydomain.com) and then the catch all forwards it to my real account (me@mydomain.com).

> I’ve run a fair amount of email campaigns where we strip out the + if gmail is the domain to ensure it doesn’t end up in some weird filter.

At which point you should wind up in the "how widely can I advertise that you're a spammer and all your outbound email should all be routed straight to /dev/null for sending mail to an email address you were never given" filter.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#68

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

Sure, I like the thinking. In theory some of these costs will hit the errors and omissions insurance, which will drive up their costs in the long run (I know they are being absorbed by Verizon, but typically...). In turn part of the insurance evaluation would they assess the collection of the data as a risk as well as their track records in keeping it secure.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#69

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

I believe EU's GDPR made some efforts in that direction, but I'm not sure it went far enough.

We need laws that give companies incentive to store very little data on us outside of what's absolutely required for the functioning of the service. And if they do store additional info, and their servers are breached, then automatic hefty fines should be paid (right after the mandatory notification to authorities and the public).

That should encourage companies to either minimize data collection or use end-to-end encryption, where most of that additional data would be stored on the client's device. This would have to exempt them from liability, and it should since the data wouldn't be on their servers if breached.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#70

Looks like both Equifax (2.5m additional accounts) and Yahoo chose today as a good day to bury bad news (the papers being filled with Las Vegas, Puerto Rico, etc). Slimy moves from their PR teams.

As well as the grilling of Wells Fargo and Equafax executives in congress.
Post reply on HN