Live data from Hacker News

Yahoo Triples Estimate of Breached Accounts to 3B

wsj.com

91–100 of 311 posts

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#91
post #73

Earlier quoted context omitted.

How much do you actually need to know about someone to serve up email to them?

For a consumer mail service, you to need to know enough to let them recover their account, possibly with decades of un-backed-up correspondence with and photos of since-deceased friends and relatives, when they’ve forgotten their password, and without letting someone else recover their account. This is a hard problem. (I’m expecting some idealized “solutions” from people with idealized beliefs about mass market tech…

You also need a process for resolving ownership disputes. Facebook takes the tactic of having the person claiming ownership upload government-issued ID, which seems like it would be the only foolproof way to do so, yet they're constantly maligned for it.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#92

> A massive data breach at Yahoo in 2013 was far more extensive than previously disclosed, affecting all of its 3 billion user accounts, new parent company Verizon Communications Inc. said on Tuesday. Imagine the buyers remorse

I used to work at aol. Neither company trusted the others networks or security processes. Integration planning meetings were like negotiating a prisoner exchange.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#93

Earlier quoted context omitted.

User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service

> You really do need user accounts to run an email service Exactly, regardless of that companies keep asking users for a whole collection of personal data, not always making it obvious which fields are actually required because it's good business for them to get as much personal data as possible. Average users are usually unsure about a lot of this stuff and naive enough to enter their real data for fear of getting c…

>> User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service

> Exactly, regardless of that companies keep asking users for a whole collection of personal data, not always making it obvious which fields are actually required

You literally don't need any user information to run an email service. You only need a means to identify them which could just amount to giving them a long, randomly generated password. Even the username is only necessary for the purpose of being able to identify them as a recipient, not for login itself.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#94

A spokesman for Oath, the new name of Verizon’s Yahoo unit, said the company determined last week that the break-in was much worse than thought, after it received new information from outside the company. Can they claw back money from Yahoo shareholders because of this?

Possibly from the remnants of yahoo called altababa

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#95
post #75
post #43

Earlier quoted context omitted.

Alternatively, if it's truly an asset, can it be taxed as an asset? If I give a company a car, that is taxed. If I give a company my data which is worth more than a car, it isn't. Is it possible that current accounting/tax law can be interpreted so that these are viewed similarly?

Using the black market as a standard, your identity-related information isn't worth enough to be taxable.[0][1][2] The more common data you give away is worth even less. Your "gift" is akin to giving away a few grains of sand to a glassmaker who provides a free grain counting service. Now let's say you dumped a lot sand that we could value at $10K. Any smart sand-counting glassmaker will claim his once "free" sand co…

Value is derived from user data when its used to target ads. Black market data is never used for that purpose, so its value is much lower. (A company would never take the risk of using black market data)

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#96
post #69

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

I believe EU's GDPR made some efforts in that direction, but I'm not sure it went far enough. We need laws that give companies incentive to store very little data on us outside of what's absolutely required for the functioning of the service. And if they do store additional info, and their servers are breached, then automatic hefty fines should be paid (right after the mandatory notification to authorities and the pu…

I was about to mention the GDPR - it definitely is a step in the right direction. I don't think that it doesn't go far enough - compared to previous regulations, it is quite severe, and it already is a pain to implement as it is. If it went any further, many companies would probably not even bother and somehow do their business outside the EU, or just prepare to be fined

> if they do store additional info, and their servers are breached, then automatic hefty fines should be paid (right after the mandatory notification to authorities and the public).

This is already in the GDPR - you have to notify everyone affected about breaches, and the fines can go up to 20 million or 4% of annual turnover, whichever is greater.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#97
post #54

Earlier quoted context omitted.

With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header.

I’ve run a fair amount of email campaigns where we strip out the + if gmail is the domain to ensure it doesn’t end up in some weird filter. Dick move, I know. Tell marketing that though. I personally use gmail through a vanity domain and have a catch all rule, so I end up signing up with a fake email account for every domain (hn@mydomain.com) and then the catch all forwards it to my real account (me@mydomain.com).

Sounds like a great way to get your email marked as spam.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#98

Earlier quoted context omitted.

Hundreds? Are you sure?

I know a guy who uses a service that creates a unique email account for every service he signs up for. That way, he tells me, if he ever gets any spam, he can delete the account and it doesn't affect any of his other email accounts.

This can be done easily if you own a domain and use a service that lets you specify a catch-all address. I do this with my own domain and G Suite. Then, you don't even need to do any preparation before giving out the address.

It does sound weird to the person writing it down and I've had more than one person say something like "well, if you're just going to give me a fake address, then don't bother" before I explained myself.

One other down side is that it is not as easy to reply to mail as the other, generated identity (in gsuite, you need to create a new account in the domain to write as that username and also maybe jump through a hoop or two). Replying casually can often reveal your main identity, which is often the one you are trying to strongly protect.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#99

On a related note Equifax stated yesterday that they identified an additional 2.5 million accounts that were breached: https://www.nytimes.com/2017/10/02/business/equifax-breach.h... Is proper audit capability just not seen as important at these companies?

I imagine that if it's not the type of audit required by the government then it's a liability. You can plausibly deny something you never audited.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#100

I feel a little sad that pay-walled articles make it to the top of HN. I'm sure the article is interesting, but a lot of us can't actually read it.

There's a workaround: submit the article to archive.is. http://archive.is/d8LTZ I didn't come up with this trick, but unfortunately I forgot who donated it.

Maybe me. ;-) I've been suggesting it for a while. It works wonders and has worked every time I've tried it.

It seems likely that they know about this backdoor and have opted to allow it. They must surely know the IO addresses associated with archive.is and have yet to make any effort to block then.

Post reply on HN