Live data from Hacker News

Yahoo Hacked

webcache.googleusercontent.com

171–180 of 258 posts

Re: Yahoo Hacked

#171

Earlier quoted context omitted.

In the winzip email, he rambles about his mother. Which makes his signature line pretty interesting. :) > A fool learns only from himself. A wise man will learn from the fool. So he's got this 'honest fool' thing going for him. If he can marry that with meticulous record keeping, maybe he'll be OK. Of course, IANAL. But ffs, I'm sick of this world where the defense "Wait, you misunderstand--I'm the GOOD guy!" isn't g…

Well, mostly because if it was good enough, it would be the first thing out of the mouth of every blackhat that was caught... Or to put it in a slightly more nuanced fashion, as a blackhat I could compromise your system, and then turn around and inform you that your system was being compromised whilst at the same time profiting from any data I had already stolen . If the company being contacted does not personally kn…

> Or to put it in a slightly more nuanced fashion, as a blackhat I could compromise your system, and then turn around and inform you that your system was being compromised whilst at the same time profiting from any data I had already stolen.

Which provides a perfectly reasonable way to distinguish the white hat from the black hat. The black hat is the one making fraudulent charges to stolen credit cards, or selling social security numbers, etc.

Re: Yahoo Hacked

#172
post #132

Earlier quoted context omitted.

It doesn't sound like this person trespassed at all, but merely traversed your land during his investigation. He didn't do any damage or remove anything, so what was the trespass?

Trespass to land doesn't require damage, all it requires is the willful, unauthorized, entry onto land in another's exclusive possession. Vandalism requires that there by some property damage.

This isn't true. You're overestimating the strength of property rights to land. You should follow the link provided elsewhere in this branch of the discussion - http://www.shouselaw.com/trespass.html

Re: Yahoo Hacked

#173
post #93

Earlier quoted context omitted.

You seem to be missing my point. I've repeated it in a bunch of other comments but I'll do it again here: You don't get points for "reaching out" when you don't spend a second to search for the right address to reach out to. Yahoo has a page dedicated to reporting bugs. If he had used that page he would have gotten a response. Yahoo has paid dozens of people for doing this https://hackerone.com/yahoo?show_all=true .

I'm not quite sure why you seem so sure he didn't also send an email to that address (or use that form)? I didn't read the article thoroughly, did he enumerate somewhere which ways of contacting Y! he tried?

if he had sent it to the other address, why would the person who responded pointed it out as the email to contact? If he had already sent an email to the Yahoo Security contact, why would he then be told to do the same thing twice?

Re: Yahoo Hacked

#174
post #160

Earlier quoted context omitted.

I have mixed feelings about this. I think you're probably right that he did this with altruistic intent (or, at worst, just to satisfy his curiosity), and I hope he hasn't gotten himself into serious trouble. (Though I fear he may have.) But I hasten to add that intent is clearly not dispositive of whether it was OK for him to infiltrate someone else's system. Certainly ordinary physical property law makes is an offe…

If you walk by a house seeing someone crack a window and crawl in, do you think it's morally acceptable to trespass on the property to ascertain whether this is a burglary in progress or someone who forgot their key? (This case seems somewhere between my and your example.)

Stop the allegories already. This is unlawful computer access, not burglary. There is nothing to be gained from comparing with unrelated crimes, neither moral understanding nor any understanding of judicial consequences.

Re: Yahoo Hacked

#175
post #83
post #30

Frick. A .pl CGI script on a production box? All the yapache & yphp security fixes and is all undone by a a .pl with +ExeCGI. They used to run "crack days" where all of us used to get kicks out of breaking & entering prod, whatever means available. Was a fun way to weed through such low-hanging issues, by a highly motivated (i.e otherwise bored) crowd. I wonder if they still have them.

Golly. Who was this "they" and "all of us"?

People who use the word "frick" or "frickin'".

Re: Yahoo Hacked

#176
post #20

"Though the FBI seemed intrigued by this, in my opinion, they aren’t moving with any form of haste." I am doubtful that FBI would share their plans and/or actions with OP.

Maybe it's implied due to the lack of correspondence (follow up questions)

Re: Yahoo Hacked

#177
Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions.

Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock.

Three of our Sports API servers had malicious code executed on them this weekend by attackers looking for vulnerable Shellshock servers. These attackers had mutated their exploit, likely with the goal of bypassing IDS/IDP or WAF filters. This mutation happened to exactly fit a command injection bug in a monitoring script our Sports team was using at that moment to parse and debug their web logs.

Regardless of the cause our course of action remained the same: to isolate the servers at risk and protect our users' data. The affected API servers are used to provide live game streaming data to our Sports front-end and do not store user data. At this time we have found no evidence that the attackers compromised any other machines or that any user data was affected. This flaw was specific to a small number of machines and has been fixed, and we have added this pattern to our CI/CD code scanners to catch future issues.

As you can imagine this episode caused some confusion in our team, since the servers in question had been successfully patched (twice!!) immediately after the Bash issue became public. Once we ensured that the impacted servers were isolated from the network, we conducted a comprehensive trace of the attack code through our entire stack which revealed the root cause: not Shellshock. Let this be a lesson to defenders and attackers alike: just because exploit code works doesn’t mean it triggered the bug you expected!

I also want to address another issue: Yahoo takes external security reports seriously and we strive to respond immediately to credible tips. We monitor our Bug Bounty (bugbounty.yahoo.com) and security aliases (security@yahoo.com) 24x7, and our records show no attempt by this researcher to contact us using those means. Within an hour of our CEO being emailed directly we had isolated these systems and begun our investigation. We run one of the most successful Bug Bounty programs in the world and I hope everybody here will participate and help us keep our users safe.

We’re always looking for people who want to keep nearly a billion users safe at scale. paranoids-hiring@yahoo-inc.com

Re: Yahoo Hacked

#178
post #151

Earlier quoted context omitted.

I wouldn't be happy at all if someone went into my cellar without my permission and told me that my gas line was weakening. Despite good intentions, trespass is trespass.

What if his house was next to yours and he smelled a gas leak but wasn't sure, so his investigation led him to your cellar?

If he can smell it from outside my cellar, then why isn't he able to knock on my door? Or call the cops if I'm not home. Even for actual extremis (such as a fire) I'd generally expect people to call the fire department instead of breaking into my house to put a blanket over a kitchen fire.

With that said I'm sympathetic to this guy's intent. If I were Yahoo or the FBI and he can prove that innocuous access is all he was doing, let's just say I wouldn't go out of my way to throw the book at him.

Because (going back to IRL analogies again), the authorities writ large have the authority to do an exigent search of my home if there's probable cause of a disaster of some sort going on, but local and Federal LE don't exactly have the same right to go around pwning the entire Internet to look for sites that have already been rooted, so in a sense leaving this issue to the authorities is simply leaving it to no one except the criminals, which is also unsatisfactory.

If the right answer to widespread problems like these is supposed to be law enforcement "patrolling the Internet" in some fashion, then we'd need to have way different legal authorities to allow for that. Until then I'm not sure that "only the criminals can search for burning buildings on the Internet" is really the most pragmatic answer.

In any event we obviously can't rely on each and every single important web site's system administration teams. If even Yahoo can be caught, who can you trust?

Re: Yahoo Hacked

#179

Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…

I've long had experience with: exploits working for the wrong reason, and also the reverse, failing for the wrong reason.

For example, way back in the day before ISS bought my company, somebody claimed their IDS was vulnerable to an IMAP evasion. They actually weren't, but that specific test triggered a wholly separate (and much worse) bug that made it look like it was evadable. I laughed and laughed.

Re: Yahoo Hacked

#180
post #99

Earlier quoted context omitted.

That would imply OP had malicious intentions, which he apparently did not.

If you walk into my house through the backdoor you're trespassing. Your intentions are irrelevant.

Intention is relevant. What if I was mentally ill and mistaken your backdoor for my own? Or it was was the only feasible escape route from a murderer that was in pursuit of me? Of course this doesn't apply directly to the OP, because this house analogy doesn't hold water. BUT, intent is very relevant when it comes to law.
Post reply on HN