Live data from Hacker News

Yahoo Triples Estimate of Breached Accounts to 3B

wsj.com

151–160 of 311 posts

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#151

Earlier quoted context omitted.

> My personal data is an asset. And it belongs to me. Hm. How would this work for (say) a social security number? Does it belong to you? Does every number anyone chooses to identify you belong to you?

Any non government entity storing data about me (PII and beyond) can only do so with my (revokable) permission and owes me my cut.

In Switzerland, anyone collecting data about other people must make a public declaration of that collection, and may not keep such records about people who disagree with being thus documented ("fiché").

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#152
post #73

Earlier quoted context omitted.

How much do you actually need to know about someone to serve up email to them?

For a consumer mail service, you to need to know enough to let them recover their account, possibly with decades of un-backed-up correspondence with and photos of since-deceased friends and relatives, when they’ve forgotten their password, and without letting someone else recover their account. This is a hard problem. (I’m expecting some idealized “solutions” from people with idealized beliefs about mass market tech…

Most sites solve this problem with a combination of 2fA and at least one security question.

Having my phone number isn't even good 2fA.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#153
post #45

I tried to enable MFA on a Yahoo account I was helping someone with at work 24 hours ago. Their MFA is still SMS-based, which I’m pretty sure is a bad thing. They don’t allow an app like Duo (although they do reject VOIP numbers which I guess is good).

Download Yahoo Mail app and setup. They call their MFA Account Key and it uses the Mail app to push similar to Duo. I think other apps include Account Key, but it was just being pushed out when I last worked with Yahoo. The SMS is just a bootstrap and once you have the app you can pick your second authenticator as login.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#156

Earlier quoted context omitted.

I know a guy who uses a service that creates a unique email account for every service he signs up for. That way, he tells me, if he ever gets any spam, he can delete the account and it doesn't affect any of his other email accounts.

This can be done easily if you own a domain and use a service that lets you specify a catch-all address. I do this with my own domain and G Suite. Then, you don't even need to do any preparation before giving out the address. It does sound weird to the person writing it down and I've had more than one person say something like "well, if you're just going to give me a fake address, then don't bother" before I explaine…

Go into Gmail settings and add aliases there for each “account” you want to add to the catch-all. Actual separate accounts costs you $5+/month each.

(I do similar on my domains and the Gmail alias is easier to do than logging into Admin CP and adding aliases there)

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#157

Earlier quoted context omitted.

Does that mean that your ID number (social security for U.S. readers) is taxable upon receipt (birth or immigration)? Also we will need a birthday tax as your age (a key demographic data point) changes then. A marriage tax, moving (address change) tax, employment change tax etc. Tax law will have a concept of taxable data event much like a liquidity event. Obviously this is a silly thought exercise but it is fun to t…

Careful there tiger. You're starting to sound like a Sovereign man with your corporate federal account.

I do not know what any of that means. Googling it led to a bunch of conspiracy sites and equally incomprehensible shady semi-legal advice and advocacy sites

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#158
post #54

Earlier quoted context omitted.

I’ve run a fair amount of email campaigns where we strip out the + if gmail is the domain to ensure it doesn’t end up in some weird filter. Dick move, I know. Tell marketing that though. I personally use gmail through a vanity domain and have a catch all rule, so I end up signing up with a fake email account for every domain (hn@mydomain.com) and then the catch all forwards it to my real account (me@mydomain.com).

> I’ve run a fair amount of email campaigns where we strip out the + if gmail is the domain to ensure it doesn’t end up in some weird filter. At which point you should wind up in the "how widely can I advertise that you're a spammer and all your outbound email should all be routed straight to /dev/null for sending mail to an email address you were never given" filter.

I think that marking the mail as spam sends a signal to their email provider, putting a mark on their account?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#159

Earlier quoted context omitted.

User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service

Sure, but you don't need first name, last name, phone number, birth date or gender. All of which are asked on the signup and of which only Gender is specified as optional: https://login.yahoo.com/account/create On my small business we ask only for an email address, password and confirm password. Everything else is excessive. Tax obligations can be another problem which may require an address, but often have a simpler…

You need to collect date of birth for COPPA compliance

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#160
post #43

Earlier quoted context omitted.

Alternatively, if it's truly an asset, can it be taxed as an asset? If I give a company a car, that is taxed. If I give a company my data which is worth more than a car, it isn't. Is it possible that current accounting/tax law can be interpreted so that these are viewed similarly?

That’s a fascinating premise. Revenues generated from the use of ones data is taxed like anything else (unless routed through Ireland ;-) ) but I don’t think assets are taxed at rest. I could be wrong.

Indirectly, they are. Governments don't let you blow all your profits on assets that are as-good-as-cash, and then claim you didn't make any taxable profits.

So if you make $X in profit and then use it to buy a tractor, then (from the government's perspective), you've just swapped $X for an asset worth $X. No change in book value, no reduction in profit, no reduction in tax liability.

You are, however, allowed to treat the tractor as an expense that's distributed over several years of its useful life, which is called "depreciating" it.

So yes, to the extent that your cash is exchanged for assets, that counts as a higher book value and higher tax liability (than if it were a pure expense). I don't know if you'd have to treat a "data purchase" more like a tractor or more like buying electricity (a pure expense) though.

My previous, longer comment on the constrains of the tax code and how it results in needing the concept of depreciation: https://news.ycombinator.com/item?id=15060604#15061439

Post reply on HN