Live data from Hacker News

Yahoo Hacked

webcache.googleusercontent.com

221–230 of 258 posts

Re: Yahoo Hacked

#221

Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…

>> Yahoo takes external security reports seriously Few weeks ago, I reported to your team that some of the yahoo servers' SSL cert were expired, acknowledged but no one want to fix it (until I post it here and finally get them updated...your site was showing security warning to your users for 2 weeks) One of your awesome engineers replied the issue with expired SSL cert: "there do not appear to be any security implic…

if that's true then... wow and hopefully there's a new engineering position opening up at Yahoo right now

Re: Yahoo Hacked

#222

Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…

>> Yahoo takes external security reports seriously Few weeks ago, I reported to your team that some of the yahoo servers' SSL cert were expired, acknowledged but no one want to fix it (until I post it here and finally get them updated...your site was showing security warning to your users for 2 weeks) One of your awesome engineers replied the issue with expired SSL cert: "there do not appear to be any security implic…

Responses like this remind me why I fell in love with this site.

Re: Yahoo Hacked

#223

Earlier quoted context omitted.

>> Yahoo takes external security reports seriously Few weeks ago, I reported to your team that some of the yahoo servers' SSL cert were expired, acknowledged but no one want to fix it (until I post it here and finally get them updated...your site was showing security warning to your users for 2 weeks) One of your awesome engineers replied the issue with expired SSL cert: "there do not appear to be any security implic…

Admob.com also had an expired ssl cert for a few days recently.

People make mistake, we all understand. (actually quite surprising as Yahoo does not have a mechanism to scan/monitor expired SSL certs).

This is not the real issue here, the thing is their engineers think expired SSL cert is okay and no action being done. I told them you are now training your users to `feel` comfortable with browser warnings when they edit their Yahoo profile and risk your users in future's phishing attacks. I asked them why you are not using a self-signed cert if you think expired SSL cert is okay (of coz they didn't reply)

Util I raise this up in another hackernews' thread on their product's announcement and maybe this time it really made them feel embarrassing and finally they fixed it with a day.

The real problem here is actually not on the expired SSL cert, it is their mindset - you should treat every little reports seriously and it is your responsibility, because you are running one of the world's largest web sites.

Re: Yahoo Hacked

#224

Why is this a link to a cached version of the website?

Ah nevermind, found the answer below. The site had problems handling HN traffic earlier.

Actually, the site was DDoS'ed profusely, and also slammed with attempts testing it for the Shellshock vulnerabilities.

Re: Yahoo Hacked

#225

Earlier quoted context omitted.

If I knew, I'd be a lot wealthier. :|

How much are e.g. SANS certifications worth? I subscribe to their vulnerablity emails but they push the certification programs so hard it smells a little like University of Phoenix.

I can't comment on SANS in particular, but certifications in general tend to be worthless. Receiving a certification tends to be more a matter of persistence than competence. Worse, because the higher quality applicants generally recognize the futility in it, many of them don't participate, which means you can't even assume that someone without the certificate is unqualified.

As far as I can tell the best information provided by a certificate is that you should avoid applicants who brag about them (and for applicants, avoid employers who list them as job qualifications).

Re: Yahoo Hacked

#226

Earlier quoted context omitted.

I view bug bounties as more of a conscious nod towards responsible disclosure than anything else. I sincerely doubt anyone could make a competitive living off of bug bounty programs (even accounting for the legal grey area of selling vulnerabilities) so the economic incentive argument seems really silly to me. In contrast, if you've ever tried to responsibly disclose a vulnerability and gotten a threat from the legal…

We have several participants in our program who are making a pretty decent living, especially the ones for whom a US$5000 reward is comparable to their nation's per-capita GDP. We are hoping to highlight some of these people in a future talk. I personally think that the opening created for those without the educational or economic opportunities available to developed world researchers is the best side effects of bug…

I bypassed the bounty program because I had better things to do with my time than fill out a form to get a $25 T-shirt, regardless of that shirts worth in GDP... Yahoo! contact information is generally hard to come by, and even when it is used, it's generally ignored. Anyone on NANOG could certainly confirm this. For example, the phone number on your whois information does not even land at a voicemail, and is a business-hours only phone number.

Re: Yahoo Hacked

#228

Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…

Interesting I saw the Y debug tool on sports.yahoo.com . It said Y Confidential and had a web bug on it and something else in red. Also, was on the yahoo.com root domain. I saw this over a few days. Did anyone else see it? I couldn't click on anything and it was on the lower right hand corner of the screen.

Re: Yahoo Hacked

#229

Earlier quoted context omitted.

Can you point me to a description of CCleaner's problems? It's still my go-to tool for cleaning computers, and I've never had a problem or heard of anything major (besides the normal bugs that get fixed). It also isn't a 90s tool, being first released in 2003. What's your idea of a better alternative?

I listed the alternatives already. They're all built in. CCleaner's registry cleaner is the main issue (aside from the fact it makes computers literally slower by clearing every single cache it can find). Some of the issues it has caused: - Registry damage: Windows 8 store was damaged/corrupted by a previous version (you had to run DISM to repair it), Windows uninstaller corruption (this impacted Mcafee anti-virus ar…

>Everyone is saying the same thing. Registry Cleaning is unnecessary, won't improve performance, and really only offers you a chance of doing damage.

Well, shit. I've been using the registry cleaner for years now on Windows 7. I've always liked that it seems to clear certain cruft from my system (unused file extensions, crap left behind by uninstalled programs, etc.), as I have a certain need for digital tidiness. I'm now considering abandoning the feature after these posts.

Thanks for the explanations!

Re: Yahoo Hacked

#230

Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…

>> Yahoo takes external security reports seriously Few weeks ago, I reported to your team that some of the yahoo servers' SSL cert were expired, acknowledged but no one want to fix it (until I post it here and finally get them updated...your site was showing security warning to your users for 2 weeks) One of your awesome engineers replied the issue with expired SSL cert: "there do not appear to be any security implic…

I appreciate you reporting expired certs, which unfortunately happen from time to time. That canned reply for is not appropriate and not a reflection of how we approach TLS and I will get it changed.
Post reply on HN