Live data from Hacker News

Yahoo Triples Estimate of Breached Accounts to 3B

wsj.com

131–140 of 311 posts

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#131

Earlier quoted context omitted.

Sure, but you don't need first name, last name, phone number, birth date or gender. All of which are asked on the signup and of which only Gender is specified as optional: https://login.yahoo.com/account/create On my small business we ask only for an email address, password and confirm password. Everything else is excessive. Tax obligations can be another problem which may require an address, but often have a simpler…

First and last name at least needed for meet the email protocol. Emails shouldn't be addressed to handles/nicknames

"username " is perfectly valid in SMTP last I checked.

If it's a user experience thing, fine, but at least make it an optional field.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#132

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

Someone somewhere is going to get rich

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#133

On a related note Equifax stated yesterday that they identified an additional 2.5 million accounts that were breached: https://www.nytimes.com/2017/10/02/business/equifax-breach.h... Is proper audit capability just not seen as important at these companies?

To be fair Equifax's adjustment was relatively minor, and they did disclose that they were still investigating the matter.

2.5 million people is minor?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#134

Earlier quoted context omitted.

My personal data is an asset. And it belongs to me. Anyone who has my data for any purpose owes me my cut. Making this a property rights issue solves all the privacy & identity issues.

You agree to give up your data in return for services. Yahoo mail, or gmail for that matter aren't actually free. You are trading your data for a service.

No contract may take away a person's rights.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#135
post #125

Earlier quoted context omitted.

My personal data is an asset. And it belongs to me. Anyone who has my data for any purpose owes me my cut. Making this a property rights issue solves all the privacy & identity issues.

> My personal data is an asset. And it belongs to me. > Anyone who has my data for any purpose owes me my cut. It's well established in the US that you do not in fact own your data. You don't own your school records or employment records. You don't own your medical records or your credit records. In general the best you have is a right to view those records and that's only in certain cases.

Because Freedom Markets™?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#136

3 billion - we live in an age where half the population of the earth can exist on a service, and everyone is vulnerable. Yes, a good chunk of these are probably duplicates for business / spam / anon accounts, but this is where the world is trending. How long is it until facebook or google have a massive breach?

If that's the case, I think the bigger news then is that yahoo actually had 3B users!

How much of a rounding error can there be when they say "3 billion" instead of "y'know what, it was all of them"?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#137

Earlier quoted context omitted.

My personal data is an asset. And it belongs to me. Anyone who has my data for any purpose owes me my cut. Making this a property rights issue solves all the privacy & identity issues.

> My personal data is an asset. And it belongs to me. Hm. How would this work for (say) a social security number? Does it belong to you? Does every number anyone chooses to identify you belong to you?

Any non government entity storing data about me (PII and beyond) can only do so with my (revokable) permission and owes me my cut.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#138
post #128

Earlier quoted context omitted.

My personal data is an asset. And it belongs to me. Anyone who has my data for any purpose owes me my cut. Making this a property rights issue solves all the privacy & identity issues.

Does it really belong to you if you have no control over it?

So you do understand.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#139
post #121
post #115

Earlier quoted context omitted.

This could be a voluntary insurance that companies purchase on behalf of their users. If the company suffers a breach, they will be bound to pay X amount to their users depending on the data lost. Dress it up with a fancy badge to slap on the front of their site. Maybe a silver badge means user data is insured up to $10 each; a gold badge is up to $100; platinum up to $1000.

So Yahoo would have been insured for somewhere between $30 Billion and $3 Trillion in this scheme? That seems untenable. Good luck collecting from the bankrupt insurer.

Good point, although the report states 3 billion user accounts were breached but this doesn't mean 3 billion people. I am guessing the vast majority of accounts did not contain any sensitive information.

And maybe insurance isn't the right word; the risk should probably fall to the company holding the data, not a third party who would never be able to audit every single step to ensure there is no weak link.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#140
post #88

Earlier quoted context omitted.

With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header. I’m sure spammers have already figured that out.

Lots of programmers haven't, though. I get addresses rejected as invalid when signing up for some service at least once a month.

I've seen programmers get overruled by "product managers" in regards to handling email as it is intended to be handled.
Post reply on HN