Live data from Hacker News

Yahoo Triples Estimate of Breached Accounts to 3B

wsj.com

211–220 of 311 posts

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#211
post #185
post #159

Earlier quoted context omitted.

You need to collect date of birth for COPPA compliance

Where in COPPA does it say the DOB needs to be collected? I don't think that statement is true as you word it.

My memory of implementing COPPA compliance a decade ago was that DOB was an implicit requirement, the explicit requirement being “confirm they’re over 13; a checkbox isn’t good enough because they’ll clearly just lie.” (paraphrased, not quoted).

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#213
post #151

Earlier quoted context omitted.

Any non government entity storing data about me (PII and beyond) can only do so with my (revokable) permission and owes me my cut.

In Switzerland, anyone collecting data about other people must make a public declaration of that collection, and may not keep such records about people who disagree with being thus documented ("fiché").

There is a similar law in the UK: https://en.m.wikipedia.org/wiki/Data_Protection_Act_1998

Which itself is based on an EU directive: https://en.m.wikipedia.org/wiki/Data_Protection_Directive

This is to be replaced with an updated version between now and Brexit (that’s just going to add to the fun!): https://en.m.wikipedia.org/wiki/General_Data_Protection_Regu...

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#215
So, let's see: We have a server farm and it is working along. We want to know right along, in real time, if it is sick or healthy. So, we do some monitoring.

There are two kinds:

(1) The first kind looks for problems never seen before. Here we get to use data of two kinds, (i) when the system was healthy and (ii) when the system was sick and we detected the problem, understood it, found out why, and tried to prevent that problem in the future.

(2) The second kind looks for problems never seen before, that is, zero-day problems. Here we have no data on the problems but likely do have a lot of data on when the system was healthy or at least seemed to be, not just on the day of the data collection but also later.

In both cases we have two ways to be wrong:

(A) Say that the system is sick when it is healthy -- a false alarm.

(B) Say that the system is healthy when it is sick -- a missed detection.

So, from (A) and (B), we get two rates and want both to be low.

We can get data on many variables at high data rates.

Now, what do we do?

Okay, it's a problem in, say, data analysis, data science, statistics, AI/ML, right?

Hmm .... What do we do?

Uh, be warned: If the false alarm rate is too high, then the monitoring will be ignored.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#216
post #16

3 billion - we live in an age where half the population of the earth can exist on a service, and everyone is vulnerable. Yes, a good chunk of these are probably duplicates for business / spam / anon accounts, but this is where the world is trending. How long is it until facebook or google have a massive breach?

Well I would say close to half of those accounts are duplicate - as in not 1 account per person.

I would go further and say 3b is an order of magnitude too large. Bots aside, If there are only 3 accounts per user, our estimate is at 1b. Now, we take into account malicious agents like bots and spammers, easily carrying a bloat factor of 3-5. The closer estimation might be 100s of millions of unique human users, and maybe half of those users actually care.

TLDR+Edit: Didn't see your other post and accidentally straw manned you. Anyway, I agree it's gonna be "a lot lot less" than 3b unique human accounts.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#217
post #169

Earlier quoted context omitted.

Sorry to be that guy, but: I spend over $5m a year on rtb ads. I literally spend 50 hours a week doing this. If the money I spend doesn't produce verifiable results, I lose it. For example, that 40cpm is to reach a pool of <1000 users who are in charge of purchasing for networks of hospitals, and my ads are for MRI machines. 3rd party data is unbelievably valuable, probably $1.5 million of my budget goes to data cost…

They're swayed by ads? I'm surprised they don't need to do a formal RFP among the handful of companies who can make an MRI certified for medical use.

Who do you send the RFP to?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#218
post #177

Earlier quoted context omitted.

No contract may take away a person's rights.

On the contrary, it is commonplace for contracts to take away your rights. A common example is an arbitration clause, where you sign away your rights to use the courts to resolve disputes.

Some rights, but not all rights. You cannot (in any country I am aware of) contract away your right to life, nor turn yourself into a slave in exchange for your debts being forgiven.

The latter used to be possible, if I understand serfdom correctly.

Question is, should data rights be alienable or inalienable?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#219

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

My personal data is an asset. And it belongs to me. Anyone who has my data for any purpose owes me my cut. Making this a property rights issue solves all the privacy & identity issues.

Okay? People signed up for Yahoo accounts so that Yahoo could provide them email, messaging, fantasy sports, and other account-based webapps. How is their possession of the records of those accounts some kind of property crime? This isn't Equifax.

I'd buy a negligence argument, but there's no much to find fault with regarding possession.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#220
post #211
post #185

Earlier quoted context omitted.

Where in COPPA does it say the DOB needs to be collected? I don't think that statement is true as you word it.

My memory of implementing COPPA compliance a decade ago was that DOB was an implicit requirement, the explicit requirement being “confirm they’re over 13; a checkbox isn’t good enough because they’ll clearly just lie.” (paraphrased, not quoted).

Thank you for explaining that for me.

That's what I had thought. However, users will lie about a DOB if they will lie about an age.

Post reply on HN