Live data from Hacker News

Yahoo Triples Estimate of Breached Accounts to 3B

wsj.com

231–240 of 311 posts

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#231
post #207

Earlier quoted context omitted.

Might be better off spending £5k+ on personal gifts for each decision maker than bothering with Web advertising if it's that few people you're targeting :-)

I may not be a lawyer, but gifts of $5k to induce someone to purchase a thing for their workplace feels like it should count as corruption and bribery. If someone tried to do that to me, I’d report the attempt to the company lawyer, and I’d doubt the quality of the thing they were selling was as good as the quality of the thing the other poster was advertising.

what about a $5k rebate or discount?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#232
post #166

Earlier quoted context omitted.

> Another possibility is that only one particular system is breached, which wouldn't actually affect all users of a given company And a third possibility, especially given today's trend to distributed systems, is that the attacker gains access to one shard (or its dump) only.

I am assuming shards are much smaller than 1/3rd of all the data.

If you store EU user data in the EU and other user data somewhere with less restrictive privacy laws, an attacker could get hold of one or the other reasonably.

On the other hand, yeah, it's much more likely the entire account database was dumped.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#234

I feel a little sad that pay-walled articles make it to the top of HN. I'm sure the article is interesting, but a lot of us can't actually read it.

Here's a bookmarklet I use sometimes: javascript:window.location.href='https://m.facebook.com/l.php?u='+encodeURIComponent(window.location.href);

Why does that even work? I get technically what is going on - WSJ see the link as having been referred from Facebook. But why does the WSJ display the content for free to somebody that seems to be coming from Facebook yet look for a subscription for direct access (or from a Google search result referral) .

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#235

Earlier quoted context omitted.

Hundreds? Are you sure?

With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header. I’m sure spammers have already figured that out.

What standard is foo+bar@test.com a part of?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#236

Earlier quoted context omitted.

With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header. I’m sure spammers have already figured that out.

What standard is foo+bar@test.com a part of?

I don't think there's a standard which says that "X+Y delivers to X" - it's a configurable option in exim and you could equally well make it "XqY delivers to X" if you were wilfully perverse.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#237

3 billion - we live in an age where half the population of the earth can exist on a service, and everyone is vulnerable. Yes, a good chunk of these are probably duplicates for business / spam / anon accounts, but this is where the world is trending. How long is it until facebook or google have a massive breach?

For FB the breach might be the feature?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#238
post #169

Earlier quoted context omitted.

Sorry to be that guy, but: I spend over $5m a year on rtb ads. I literally spend 50 hours a week doing this. If the money I spend doesn't produce verifiable results, I lose it. For example, that 40cpm is to reach a pool of <1000 users who are in charge of purchasing for networks of hospitals, and my ads are for MRI machines. 3rd party data is unbelievably valuable, probably $1.5 million of my budget goes to data cost…

Might be better off spending £5k+ on personal gifts for each decision maker than bothering with Web advertising if it's that few people you're targeting :-)

In the old days, you would do that.

Now that’s not allowed in most places, plus you need to hire fancy salespeople to deliver those gifts.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#239
post #75

Earlier quoted context omitted.

Using the black market as a standard, your identity-related information isn't worth enough to be taxable.[0][1][2] The more common data you give away is worth even less. Your "gift" is akin to giving away a few grains of sand to a glassmaker who provides a free grain counting service. Now let's say you dumped a lot sand that we could value at $10K. Any smart sand-counting glassmaker will claim his once "free" sand co…

"None of us is as [valuable] as all of us," is a saying that has been around for decades, surely there are business rules that have cropped up to support a valuation of this scenario in the meantime.

I'm not saying anything different. Whenever a business/individual sells information at a value, they'll be taxed on the sale, just like anything else. OP mentioned selling a cars worth of his own data, which doesn't exist.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#240
post #207

Earlier quoted context omitted.

I may not be a lawyer, but gifts of $5k to induce someone to purchase a thing for their workplace feels like it should count as corruption and bribery. If someone tried to do that to me, I’d report the attempt to the company lawyer, and I’d doubt the quality of the thing they were selling was as good as the quality of the thing the other poster was advertising.

what about a $5k rebate or discount?

Difficult to say. My mental framing has, as a result of my previous post, become “be suspicious”.
Post reply on HN