Live data from Hacker News

Yahoo Triples Estimate of Breached Accounts to 3B

wsj.com

111–120 of 311 posts

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#111

Earlier quoted context omitted.

User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service

How much do you actually need to know about someone to serve up email to them?

You almost certainly need a password hash, and that’s (as I understand it) the main privacy worry related to the Yahoo breach.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#113
post #95
post #75

Earlier quoted context omitted.

Using the black market as a standard, your identity-related information isn't worth enough to be taxable.[0][1][2] The more common data you give away is worth even less. Your "gift" is akin to giving away a few grains of sand to a glassmaker who provides a free grain counting service. Now let's say you dumped a lot sand that we could value at $10K. Any smart sand-counting glassmaker will claim his once "free" sand co…

Value is derived from user data when its used to target ads. Black market data is never used for that purpose, so its value is much lower. (A company would never take the risk of using black market data)

Value is derived from the potential application of data. Ads as an application isn't worth much since you can still be shown ads just fine without any personal data targeting.

Black market data is worth way more because it's often more personal than just demographic markers and interests, and can potentially lead to large sums of money.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#114

Earlier quoted context omitted.

Why make hundreds of accounts?

Test accounts.

+1. I did the same. At the time I had to do this (around 2015), Yahoo was the least concerned about identifying duplicate accounts. I was testing for an actual paying job, not some side interest investigation, mind you. Some of the services I had to test were clever enough to reject fakeinbox accounts so I used Yahoo.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#115

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

This could be a voluntary insurance that companies purchase on behalf of their users. If the company suffers a breach, they will be bound to pay X amount to their users depending on the data lost.

Dress it up with a fancy badge to slap on the front of their site. Maybe a silver badge means user data is insured up to $10 each; a gold badge is up to $100; platinum up to $1000.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#116

Earlier quoted context omitted.

I know a guy who uses a service that creates a unique email account for every service he signs up for. That way, he tells me, if he ever gets any spam, he can delete the account and it doesn't affect any of his other email accounts.

This can be done easily if you own a domain and use a service that lets you specify a catch-all address. I do this with my own domain and G Suite. Then, you don't even need to do any preparation before giving out the address. It does sound weird to the person writing it down and I've had more than one person say something like "well, if you're just going to give me a fake address, then don't bother" before I explaine…

Thunderbird has the virtual identity plugin for this.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#117

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

My personal data is an asset. And it belongs to me. Anyone who has my data for any purpose owes me my cut. Making this a property rights issue solves all the privacy & identity issues.

You agree to give up your data in return for services. Yahoo mail, or gmail for that matter aren't actually free. You are trading your data for a service.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#118

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

My personal data is an asset. And it belongs to me. Anyone who has my data for any purpose owes me my cut. Making this a property rights issue solves all the privacy & identity issues.

> My personal data is an asset. And it belongs to me.

Hm. How would this work for (say) a social security number? Does it belong to you? Does every number anyone chooses to identify you belong to you?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#119
post #73

Earlier quoted context omitted.

How much do you actually need to know about someone to serve up email to them?

For a consumer mail service, you to need to know enough to let them recover their account, possibly with decades of un-backed-up correspondence with and photos of since-deceased friends and relatives, when they’ve forgotten their password, and without letting someone else recover their account. This is a hard problem. (I’m expecting some idealized “solutions” from people with idealized beliefs about mass market tech…

Why don't we just ?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#120

Earlier quoted context omitted.

It really baffles me that people are still suggesting this as advice for spam reduction. All it takes is a third of a brain and a couple seconds of thought to realize that spammers know this is a thing and can adapt.

They can, but in practice, they don't.

> They can, but in practice, they don't.

And you're confident of this how? I'm not actually convinced this is true. It's definitely a widespread belief though.

Post reply on HN