Earlier quoted context omitted.
User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service
How much do you actually need to know about someone to serve up email to them?
Yahoo Triples Estimate of Breached Accounts to 3B
111–120 of 311 posts
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#112Re: Yahoo Triples Estimate of Breached Accounts to 3B
#113Earlier quoted context omitted.
Using the black market as a standard, your identity-related information isn't worth enough to be taxable.[0][1][2] The more common data you give away is worth even less. Your "gift" is akin to giving away a few grains of sand to a glassmaker who provides a free grain counting service. Now let's say you dumped a lot sand that we could value at $10K. Any smart sand-counting glassmaker will claim his once "free" sand co…
Value is derived from user data when its used to target ads. Black market data is never used for that purpose, so its value is much lower. (A company would never take the risk of using black market data)
Black market data is worth way more because it's often more personal than just demographic markers and interests, and can potentially lead to large sums of money.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#114Earlier quoted context omitted.
Why make hundreds of accounts?
Test accounts.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#115I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.
Dress it up with a fancy badge to slap on the front of their site. Maybe a silver badge means user data is insured up to $10 each; a gold badge is up to $100; platinum up to $1000.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#116Earlier quoted context omitted.
I know a guy who uses a service that creates a unique email account for every service he signs up for. That way, he tells me, if he ever gets any spam, he can delete the account and it doesn't affect any of his other email accounts.
This can be done easily if you own a domain and use a service that lets you specify a catch-all address. I do this with my own domain and G Suite. Then, you don't even need to do any preparation before giving out the address. It does sound weird to the person writing it down and I've had more than one person say something like "well, if you're just going to give me a fake address, then don't bother" before I explaine…
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#117I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.
My personal data is an asset. And it belongs to me. Anyone who has my data for any purpose owes me my cut. Making this a property rights issue solves all the privacy & identity issues.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#118I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.
My personal data is an asset. And it belongs to me. Anyone who has my data for any purpose owes me my cut. Making this a property rights issue solves all the privacy & identity issues.
Hm. How would this work for (say) a social security number? Does it belong to you? Does every number anyone chooses to identify you belong to you?
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#119Earlier quoted context omitted.
How much do you actually need to know about someone to serve up email to them?
For a consumer mail service, you to need to know enough to let them recover their account, possibly with decades of un-backed-up correspondence with and photos of since-deceased friends and relatives, when they’ve forgotten their password, and without letting someone else recover their account. This is a hard problem. (I’m expecting some idealized “solutions” from people with idealized beliefs about mass market tech…
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#120Earlier quoted context omitted.
It really baffles me that people are still suggesting this as advice for spam reduction. All it takes is a third of a brain and a couple seconds of thought to realize that spammers know this is a thing and can adapt.
They can, but in practice, they don't.
And you're confident of this how? I'm not actually convinced this is true. It's definitely a widespread belief though.