Live data from Hacker News

Yahoo Triples Estimate of Breached Accounts to 3B

wsj.com

261–270 of 311 posts

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#261

Somewhat off-topic, but does anyone know what top-level domains are in practice "safe" to use for email addresses if we're going to migrate to our own domain? I mean "safe" in the sense of being unlikely to cause confusion or problems with less-than-well-written software (or humans). Obviously .com is okay, and I haven't heard of problems with .edu/.gov/.org/.net, but I'm a little afraid of getting a domain for email…

For about 9 years or so, I've used the .CC TLD for my personal/family's email without any technical issues...though it is important to know that throughout the entire time, I've used G Suite as my email provider (used to be called google apps for your domain, etc.). So, one could speculate that perhaps my lack of technical issues was less due to the TLD that i used, and maybe because google considers my domain name "not spammy".

HOWEVER, an annoying problem that I've had over the years - and while it has diminished slightly still persists - is that people (or at least people here in the U.S.) are not used to hearing domain names that don't end in the usual .COM, .ORG, .NET...so I ALWAYS have to clarify and explain that my email ends in .CC and not .COM, etc. i find myself still doing this even today - almost a decade later - with so many lay people "being online". I sort of expect that more often with lay people more explanation is needed, but you'd be surprised how many technical people also are not as used to hearing domain names that don't end in the usual top 3. I like the .CC TLD, I really do...but having lived these last 9 or so years with having to constantly explain to people (with whom I plan to correspond with) that there are soooooo many other TLDs out there (beyond just .COM, .ORG, .NET) does get really tiring. If I had to do this all over again, I would have gone with .NET or .ORG (the .COM back then was already taken for my domain name). Oh well.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#262

Earlier quoted context omitted.

My personal data is an asset. And it belongs to me. Anyone who has my data for any purpose owes me my cut. Making this a property rights issue solves all the privacy & identity issues.

I'm torn between liking this view of personal data as property and also liking the view of Richard Stallman and the FSF that "intellectual property" is a legal fiction that we ought to resist. What does it actually mean to "own" data, and is "property" the best metaphor to represent a set of personal data control rights?

I hear ya. Pinko commie liberal me abhors the idea.

Legal fictions like "property", "money", and "rights" are practical innovations that make society work better (eg more moral, greater public good). Kinda like the tech tree in games like Civilization.

The books "The Mystery of Capital" and "Nonzero" influenced me a lot. Good starting points, optimistic, and more right than wrong.

https://en.wikipedia.org/wiki/Hernando_de_Soto_Polar

https://en.wikipedia.org/wiki/Robert_Wright_(journalist)

Until something better comes along...

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#263
post #218
post #177

Earlier quoted context omitted.

On the contrary, it is commonplace for contracts to take away your rights. A common example is an arbitration clause, where you sign away your rights to use the courts to resolve disputes.

Some rights, but not all rights. You cannot (in any country I am aware of) contract away your right to life, nor turn yourself into a slave in exchange for your debts being forgiven. The latter used to be possible, if I understand serfdom correctly. Question is, should data rights be alienable or inalienable?

Thank you for articulating, explaining stuff better than I can.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#265

Earlier quoted context omitted.

Sure, but you don't need first name, last name, phone number, birth date or gender. All of which are asked on the signup and of which only Gender is specified as optional: https://login.yahoo.com/account/create On my small business we ask only for an email address, password and confirm password. Everything else is excessive. Tax obligations can be another problem which may require an address, but often have a simpler…

First and last name at least needed for meet the email protocol. Emails shouldn't be addressed to handles/nicknames

Deliberate sarcasm?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#266
post #186
post #142

Earlier quoted context omitted.

True, it wouldn't be 3 billion individuals claiming the benefit. Still the scale is so large that it would utterly bankrupt most companies to pay out for a single breach.

If the cost of disclosure was a dollar a user there's pretty much no way we'd see them voluntarily tell us they were hacked. We'd have to wait until the information got out some other way.

Not a perfect solution, but sure. "You're the weakest link - goodbye!"

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#267
This still is a huge concern for us web app developers. Most people re-use their email addresses and passwords across multiple sites. One breach at one internet company affects all the others.

IMO, password reuse is the #1 web application security problem in the world right now, and there's very little in the way of accepted industry standards to mitigate it.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#268

Earlier quoted context omitted.

> I’ve run a fair amount of email campaigns where we strip out the + if gmail is the domain to ensure it doesn’t end up in some weird filter. At which point you should wind up in the "how widely can I advertise that you're a spammer and all your outbound email should all be routed straight to /dev/null for sending mail to an email address you were never given" filter.

I think that marking the mail as spam sends a signal to their email provider, putting a mark on their account?

Depends on your isp and which email provider they use. The big marketing email services generally do have the feedback loop setup with Gmail though, so yes, you are right.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#269
post #243

Earlier quoted context omitted.

You (and every other responder) miss larger the point of my comment. Let's use Google as an example. Your clicks throughout the internet, like sand, don't amount to much of value. It's a very unrefined, raw material, with limited quantity. Even if Google were forced to value that raw material, they can argue they're trading it in equal exchange for whatever service they offer you, so there would still be no tax. In a…

Like data in general, user data is essentially worthless until aggregated en masse and refined into insights. But when you consider how much data companies are hoarding, it doesn't take much of an assessed value to create a nontrivial taxable asset. Also, it doesn't matter that there's an exchange happening. Sales tax and income tax are assessed on fair exchanges of goods, services, and currency.

Sales tax isn't paid on trades. When you trade in a car for $2k off a $10k car, you only pay taxes on the difference: $8k.

And if you grow oranges on your property that you never sell, you never pay taxes on those oranges.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#270

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

This is how the civil legal system is supposed to function. There needs to be some very large class action lawsuits brought against these companies, and huge awards need to be extracted in order increase the financial risk of having shitty infosec.

For PCI Compliance purposes, at least, holding user credit card information is already seen as a liability because maintaining compliance is a cost center. That's why there's been some shift towards tokenizing transactions on the fly and directly submitting to the CC company via javascript so that shopping websites never see your CC number even when you enter it on their website - even if you're scheduling future payments.

Maybe we should include other data elements under PCI or similar regulations. SSN?

I imagine HIPAA has similar requirements and associated costs.

Post reply on HN