Live data from Hacker News

Yahoo Triples Estimate of Breached Accounts to 3B

wsj.com

121–130 of 311 posts

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#121
post #115

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

This could be a voluntary insurance that companies purchase on behalf of their users. If the company suffers a breach, they will be bound to pay X amount to their users depending on the data lost. Dress it up with a fancy badge to slap on the front of their site. Maybe a silver badge means user data is insured up to $10 each; a gold badge is up to $100; platinum up to $1000.

So Yahoo would have been insured for somewhere between $30 Billion and $3 Trillion in this scheme? That seems untenable. Good luck collecting from the bankrupt insurer.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#122
post #43

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

Alternatively, if it's truly an asset, can it be taxed as an asset? If I give a company a car, that is taxed. If I give a company my data which is worth more than a car, it isn't. Is it possible that current accounting/tax law can be interpreted so that these are viewed similarly?

Stunning... How badly do you really want to be a tax-serf?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#123

Earlier quoted context omitted.

They can, but in practice, they don't.

> They can, but in practice, they don't. And you're confident of this how? I'm not actually convinced this is true. It's definitely a widespread belief though.

Because I'm using the + thing, and I'm still receiving spam to the +ed addresses.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#124

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service

Sure, but you don't need first name, last name, phone number, birth date or gender. All of which are asked on the signup and of which only Gender is specified as optional: https://login.yahoo.com/account/create

On my small business we ask only for an email address, password and confirm password. Everything else is excessive.

Tax obligations can be another problem which may require an address, but often have a simpler way to resolve them by simply picking the appropriate country and state off a list or even with just a checkbox for "are you in X jurisdiction which I am required to tax?". I believe Tarsnap handles it that way.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#125

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

My personal data is an asset. And it belongs to me. Anyone who has my data for any purpose owes me my cut. Making this a property rights issue solves all the privacy & identity issues.

> My personal data is an asset. And it belongs to me.

> Anyone who has my data for any purpose owes me my cut.

It's well established in the US that you do not in fact own your data. You don't own your school records or employment records. You don't own your medical records or your credit records. In general the best you have is a right to view those records and that's only in certain cases.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#126

Earlier quoted context omitted.

> You really do need user accounts to run an email service Exactly, regardless of that companies keep asking users for a whole collection of personal data, not always making it obvious which fields are actually required because it's good business for them to get as much personal data as possible. Average users are usually unsure about a lot of this stuff and naive enough to enter their real data for fear of getting c…

>> User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service > Exactly, regardless of that companies keep asking users for a whole collection of personal data, not always making it obvious which fields are actually required You literally don't need any user information to run an email service. You only need a means to identify them which could just amount to gi…

Wouldn't the emails themselves count as user information?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#127

Earlier quoted context omitted.

User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service

Sure, but you don't need first name, last name, phone number, birth date or gender. All of which are asked on the signup and of which only Gender is specified as optional: https://login.yahoo.com/account/create On my small business we ask only for an email address, password and confirm password. Everything else is excessive. Tax obligations can be another problem which may require an address, but often have a simpler…

First and last name at least needed for meet the email protocol. Emails shouldn't be addressed to handles/nicknames

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#128

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

My personal data is an asset. And it belongs to me. Anyone who has my data for any purpose owes me my cut. Making this a property rights issue solves all the privacy & identity issues.

Does it really belong to you if you have no control over it?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#130

> A massive data breach at Yahoo in 2013 was far more extensive than previously disclosed, affecting all of its 3 billion user accounts, new parent company Verizon Communications Inc. said on Tuesday. Imagine the buyers remorse

Does anyone have insight on how this works? Do you just sue the pants off of the execs, or the lawyers who did due diligence, or the SREs maybe? Do the clawback the difference in goodwill + legal costs from the selling investors? Is there recourse at all? It'll probably the some poor schmuck SRE getting the blame, like always, right?

There'll be a small chunk of the purchase price left in escrow for a year for any extra liabilities that weren't discovered in DD. They'll be claiming that. But it won't be much.
Post reply on HN