Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…
>> Yahoo takes external security reports seriously Few weeks ago, I reported to your team that some of the yahoo servers' SSL cert were expired, acknowledged but no one want to fix it (until I post it here and finally get them updated...your site was showing security warning to your users for 2 weeks) One of your awesome engineers replied the issue with expired SSL cert: "there do not appear to be any security implic…
Yahoo Hacked
221–230 of 258 posts
Re: Yahoo Hacked
#222Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…
>> Yahoo takes external security reports seriously Few weeks ago, I reported to your team that some of the yahoo servers' SSL cert were expired, acknowledged but no one want to fix it (until I post it here and finally get them updated...your site was showing security warning to your users for 2 weeks) One of your awesome engineers replied the issue with expired SSL cert: "there do not appear to be any security implic…
Re: Yahoo Hacked
#223Earlier quoted context omitted.
>> Yahoo takes external security reports seriously Few weeks ago, I reported to your team that some of the yahoo servers' SSL cert were expired, acknowledged but no one want to fix it (until I post it here and finally get them updated...your site was showing security warning to your users for 2 weeks) One of your awesome engineers replied the issue with expired SSL cert: "there do not appear to be any security implic…
Admob.com also had an expired ssl cert for a few days recently.
This is not the real issue here, the thing is their engineers think expired SSL cert is okay and no action being done. I told them you are now training your users to `feel` comfortable with browser warnings when they edit their Yahoo profile and risk your users in future's phishing attacks. I asked them why you are not using a self-signed cert if you think expired SSL cert is okay (of coz they didn't reply)
Util I raise this up in another hackernews' thread on their product's announcement and maybe this time it really made them feel embarrassing and finally they fixed it with a day.
The real problem here is actually not on the expired SSL cert, it is their mindset - you should treat every little reports seriously and it is your responsibility, because you are running one of the world's largest web sites.
Re: Yahoo Hacked
#224Re: Yahoo Hacked
#225Earlier quoted context omitted.
If I knew, I'd be a lot wealthier. :|
How much are e.g. SANS certifications worth? I subscribe to their vulnerablity emails but they push the certification programs so hard it smells a little like University of Phoenix.
As far as I can tell the best information provided by a certificate is that you should avoid applicants who brag about them (and for applicants, avoid employers who list them as job qualifications).
Re: Yahoo Hacked
#226Earlier quoted context omitted.
I view bug bounties as more of a conscious nod towards responsible disclosure than anything else. I sincerely doubt anyone could make a competitive living off of bug bounty programs (even accounting for the legal grey area of selling vulnerabilities) so the economic incentive argument seems really silly to me. In contrast, if you've ever tried to responsibly disclose a vulnerability and gotten a threat from the legal…
We have several participants in our program who are making a pretty decent living, especially the ones for whom a US$5000 reward is comparable to their nation's per-capita GDP. We are hoping to highlight some of these people in a future talk. I personally think that the opening created for those without the educational or economic opportunities available to developed world researchers is the best side effects of bug…
Re: Yahoo Hacked
#227Re: Yahoo Hacked
#228Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…
Re: Yahoo Hacked
#229Earlier quoted context omitted.
Can you point me to a description of CCleaner's problems? It's still my go-to tool for cleaning computers, and I've never had a problem or heard of anything major (besides the normal bugs that get fixed). It also isn't a 90s tool, being first released in 2003. What's your idea of a better alternative?
I listed the alternatives already. They're all built in. CCleaner's registry cleaner is the main issue (aside from the fact it makes computers literally slower by clearing every single cache it can find). Some of the issues it has caused: - Registry damage: Windows 8 store was damaged/corrupted by a previous version (you had to run DISM to repair it), Windows uninstaller corruption (this impacted Mcafee anti-virus ar…
Well, shit. I've been using the registry cleaner for years now on Windows 7. I've always liked that it seems to clear certain cruft from my system (unused file extensions, crap left behind by uninstalled programs, etc.), as I have a certain need for digital tidiness. I'm now considering abandoning the feature after these posts.
Thanks for the explanations!
Re: Yahoo Hacked
#230Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…
>> Yahoo takes external security reports seriously Few weeks ago, I reported to your team that some of the yahoo servers' SSL cert were expired, acknowledged but no one want to fix it (until I post it here and finally get them updated...your site was showing security warning to your users for 2 weeks) One of your awesome engineers replied the issue with expired SSL cert: "there do not appear to be any security implic…