Live data from Hacker News

Engineer admits hacking Yahoo accounts searching for images

ktvu.com

41–50 of 99 posts

Re: Engineer admits hacking Yahoo accounts searching for images

#41

I had a YouTube employee login to my account, defaced my video titles and description. And Google wouldn’t do a thing about it. Don’t trust FAANGs and other ‘wangs’ with your private content !

I strongly doubt that Google harbors any negative feelings for you specifically. Do you have any concrete evidence for your claim?

Re: Engineer admits hacking Yahoo accounts searching for images

#42
post #39
post #36

Earlier quoted context omitted.

Honestly I'd like to see one of the webmail providers do a decent attempt at gpg. The web migrated from a primarily unencrypted state to an encrypted one - it's not impossible with the right UX.

ProtonMail?

Hardly a major provider though.

Re: Engineer admits hacking Yahoo accounts searching for images

#43
post #21
post #16

Banks routinely hire hit-n-run contractors to manage systems will low level, uncontrolled, unaudited access to mind boggling resources and eye popping access to private customers info. Email porn? Child play.

Everything has to get decrypted at some point, right? I try not to think about what would happen if a Google employee decided to leak everyone's search history.

The fact that it hasn't happened yet when there are so many Google employees suggests that it's infeasibly difficult.

Re: Engineer admits hacking Yahoo accounts searching for images

#44

I truly don't understand how Yahoo still exists. How have they survived this long?

What other service am I supposed to use as a permanent throwaway email account?

mail.yandex.com - they don't even require a cell phone number.

Re: Engineer admits hacking Yahoo accounts searching for images

#45
post #3

It's sobering to think about this in tandem with the fact that people in the IQ bracket for “engineer” tend to get away with crimes. Honestly, though, at least this can be turned into a concrete example to shoot down “if you don't have anything to hide...” and the like. The banal, lascivious panopticon elicits a real disgust response that might be moving, as opposed to the “shut up you alex jones weirdo” that sticks…

Let me try to rephrase this in a simpler way:

This is even more troubling because smart people are less likely to be caught.

At least, like Snowden's leaks, this is proof that privacy extremists aren't conspiracy nuts, and hopefully it will open a few eyes to the real danger of giving up privacy.

Other comments are right: stop using big words and write plain sentences.

Re: Engineer admits hacking Yahoo accounts searching for images

#46
post #16

Banks routinely hire hit-n-run contractors to manage systems will low level, uncontrolled, unaudited access to mind boggling resources and eye popping access to private customers info. Email porn? Child play.

Not just contractors. In most parts of the world there will be a 20 year old, with 3 months of "security training" paid less than $1000 a month, running around the data center with keys to the castle.

Re: Engineer admits hacking Yahoo accounts searching for images

#47
post #28
post #3

It's sobering to think about this in tandem with the fact that people in the IQ bracket for “engineer” tend to get away with crimes. Honestly, though, at least this can be turned into a concrete example to shoot down “if you don't have anything to hide...” and the like. The banal, lascivious panopticon elicits a real disgust response that might be moving, as opposed to the “shut up you alex jones weirdo” that sticks…

Just for the sake of feedback, I found your post confusing. It's not really clear to me what you are saying exactly.

That how smart people can get away with these things and employees can see your images could be a wake up call for taking privacy concerns seriously I think

Re: Engineer admits hacking Yahoo accounts searching for images

#48
post #28
post #3

It's sobering to think about this in tandem with the fact that people in the IQ bracket for “engineer” tend to get away with crimes. Honestly, though, at least this can be turned into a concrete example to shoot down “if you don't have anything to hide...” and the like. The banal, lascivious panopticon elicits a real disgust response that might be moving, as opposed to the “shut up you alex jones weirdo” that sticks…

Just for the sake of feedback, I found your post confusing. It's not really clear to me what you are saying exactly.

Presumably, this person is airing frustration with common responses to privacy oriented discussions he or she has experienced as participant and/or vicariously. He or she has characterized them ending in ad homenims, whereby the privacy minded individual is construed as politically or intellectually unmoored, similar to Alex Jones.

Spedru posits the covert and exposed deviants within companies, that we've exchanged our data with, are another style of entity (besides state actors) that we ought to strive to deprive of access to that data.

At least, that's as charitably as I can characterize the comment.

Re: Engineer admits hacking Yahoo accounts searching for images

#49
post #36

Earlier quoted context omitted.

Encryption, in email? lol... This is what happens when end-to-end encryption isn't the default in communications software. All email providers are vulnerable to this bar none.

Honestly I'd like to see one of the webmail providers do a decent attempt at gpg. The web migrated from a primarily unencrypted state to an encrypted one - it's not impossible with the right UX.

This is never going to happen because it doesn’t work very well for consumers, and works even less well for businesses.

For consumers, owning the encryption keys means account recovery is impossible when they inevitably lose their keys. IM services can get away with it, because losing your IM history is not nearly as serious as losing your inbox.

For businesses, you’re not going to be able to sell a service that makes filtering impossible. This is bad for consumers too, but an absolute deal breaker for most businesses.

Re: Engineer admits hacking Yahoo accounts searching for images

#50
End-to-end encryption is the only foolproof was of preventing this. But if that is not possible, training and audit/alerts is the next best thing.

Training is important because new employees or new college grads might not be aware of truly how egregious it is to view someone's personal data. It really had to be drilled into the culture. By audits and alerts, I mean that if one employee accesses sensitive information, they know that other teammates are getting an alert about it. People do such things when they think nobody will know.

Post reply on HN