Live data from Hacker News

Engineer admits hacking Yahoo accounts searching for images

ktvu.com

81–90 of 99 posts

Re: Engineer admits hacking Yahoo accounts searching for images

#81
post #45

Earlier quoted context omitted.

Let me try to rephrase this in a simpler way: This is even more troubling because smart people are less likely to be caught. At least, like Snowden's leaks, this is proof that privacy extremists aren't conspiracy nuts, and hopefully it will open a few eyes to the real danger of giving up privacy. Other comments are right: stop using big words and write plain sentences.

You removed some of the most important parts. The word "engineer" is critical to the first sentence, and your version has no translation of "banal, lascivious panopticon". The roundabout structure of the sentences is much more relevant than the use of a big word or two.

You got me. It wasn't a 100% faithful translation.

I removed "engineer" because it's not necessary to the broader premise that more highly skilled people tend to be both more trusted in our society and more likely to know how to get away with a crime.

I didn't translate "banal, lascivious panopticon" because it was it's one of those faux-profound images that adds very little.

It's hardly revelatory to tell HN readers that people are troublingly comfortable with constant tracking by corporations and governments.

Re: Engineer admits hacking Yahoo accounts searching for images

#82

Earlier quoted context omitted.

Not sure why I'm getting downvoted. Prove me wrong.

I don't see how this could happen at Tutanota

From https://tutanota.com/faq

"Your private key is encrypted with your password. This way your login password receives the status of the private key."

"Your password is never transmitted to the server in plain text. It is salted and then hashed with bcrypt locally on your device so that neither the server nor we have access to your password."

What's stopping them (or being commandeered) to serve you modified javascript which sends them your password, or this being done via an unsanitised email viewed via their web UI?

Having worked for two email companies for over 10 years, I know not trust email providers for privacy.

Re: Engineer admits hacking Yahoo accounts searching for images

#83

Earlier quoted context omitted.

I don't see how this could happen at Tutanota

From https://tutanota.com/faq "Your private key is encrypted with your password. This way your login password receives the status of the private key." "Your password is never transmitted to the server in plain text. It is salted and then hashed with bcrypt locally on your device so that neither the server nor we have access to your password." What's stopping them (or being commandeered) to serve you modified javascri…

> What's stopping them (or being commandeered) to serve you modified javascript which sends them your password, or this being done via an unsanitised email viewed via their web UI?

Thinking about this more, the threat model here was an insider. This is something that Tutanota wouldn't be able to prevent with its advertised services given the same situation.

Re: Engineer admits hacking Yahoo accounts searching for images

#84
post #36

Earlier quoted context omitted.

Honestly I'd like to see one of the webmail providers do a decent attempt at gpg. The web migrated from a primarily unencrypted state to an encrypted one - it's not impossible with the right UX.

This is never going to happen because it doesn’t work very well for consumers, and works even less well for businesses. For consumers, owning the encryption keys means account recovery is impossible when they inevitably lose their keys. IM services can get away with it, because losing your IM history is not nearly as serious as losing your inbox. For businesses, you’re not going to be able to sell a service that make…

> that makes filtering impossible

... including spam filtering, which matters somewhat for consumers, too.

Then there's the issue of search - with webmail you have no realistic choice but to rely on server-side search, and the same issue likely applies on phones even when using a dedicated mail app. (And indeed ProtonMail currently only offers meta-data search, but no full text body search)

Re: Engineer admits hacking Yahoo accounts searching for images

#85
post #80

Earlier quoted context omitted.

"Some rando engineer stealing private images elicits a real disgust response that might be moving, as opposed to talk of the NSA" Such a simple point, and look over how many heads it went.

Sure, if that's what it's saying. I think it's pretty presumptuous to think a world salad went "over" any of our heads, when a simpler explanation is that the point was obscured by unnecessarily complex language.

English isn't even my first language, so if I have no problem parsing that, it's possible. Even if something is "unnecessarily" complex, what necessitates knee-jerk responses or downvotes?

Re: Engineer admits hacking Yahoo accounts searching for images

#86
post #80

Earlier quoted context omitted.

Sure, if that's what it's saying. I think it's pretty presumptuous to think a world salad went "over" any of our heads, when a simpler explanation is that the point was obscured by unnecessarily complex language.

English isn't even my first language, so if I have no problem parsing that, it's possible. Even if something is "unnecessarily" complex, what necessitates knee-jerk responses or downvotes?

> so if I have no problem parsing that, it's possible

That's still assuming your interpretation was what the writer intended. As a native English speaker, I can tell you that it's not 100% clear.

> what necessitates knee-jerk responses or downvotes?

The meaning of a down vote is not defined by HN itself, so it's personal. For me, I use it based on value. I up-vote comments that add to or improve the discussion. I down-vote comments that add nothing.

I did not down-vote the root comment here. I replied because I found the content to be locked away by the presentation, and the content seemed to be a worthwhile part of the discussion of the article.

Re: Engineer admits hacking Yahoo accounts searching for images

#87

Earlier quoted context omitted.

This is never going to happen because it doesn’t work very well for consumers, and works even less well for businesses. For consumers, owning the encryption keys means account recovery is impossible when they inevitably lose their keys. IM services can get away with it, because losing your IM history is not nearly as serious as losing your inbox. For businesses, you’re not going to be able to sell a service that make…

> that makes filtering impossible ... including spam filtering, which matters somewhat for consumers, too. Then there's the issue of search - with webmail you have no realistic choice but to rely on server-side search, and the same issue likely applies on phones even when using a dedicated mail app. (And indeed ProtonMail currently only offers meta-data search, but no full text body search)

I didn’t specifically say spam filtering, because there’s technically lots of spam filtering you can do with only metadata. But yeah you’re right, any form of server side content filtering (including search) would be impossible.

Re: Engineer admits hacking Yahoo accounts searching for images

#88
post #80

Earlier quoted context omitted.

Sure, if that's what it's saying. I think it's pretty presumptuous to think a world salad went "over" any of our heads, when a simpler explanation is that the point was obscured by unnecessarily complex language.

English isn't even my first language, so if I have no problem parsing that, it's possible. Even if something is "unnecessarily" complex, what necessitates knee-jerk responses or downvotes?

English is my third language and I had no problem parsing that either.

On the other hand, I was taught early on not to trawl the thesaurus for word substitutions. It’s just pretentious.

Re: Engineer admits hacking Yahoo accounts searching for images

#89
post #45

Earlier quoted context omitted.

Let me try to rephrase this in a simpler way: This is even more troubling because smart people are less likely to be caught. At least, like Snowden's leaks, this is proof that privacy extremists aren't conspiracy nuts, and hopefully it will open a few eyes to the real danger of giving up privacy. Other comments are right: stop using big words and write plain sentences.

"Some rando engineer stealing private images elicits a real disgust response that might be moving, as opposed to talk of the NSA" Such a simple point, and look over how many heads it went.

In response to the point - a random person isn't a concentrated menacing agency that can be politically targeted, so isn't that demotivating?

Re: Engineer admits hacking Yahoo accounts searching for images

#90

I had a YouTube employee login to my account, defaced my video titles and description. And Google wouldn’t do a thing about it. Don’t trust FAANGs and other ‘wangs’ with your private content !

How do you know it was an inside job?

Because I used an extremely long password and I used the same password for my gmail and iCloud. And none of them were touched or accessed based on ip access history.
Post reply on HN