Live data from Hacker News

Yahoo Hacked

webcache.googleusercontent.com

231–240 of 258 posts

Re: Yahoo Hacked

#231

Earlier quoted context omitted.

Well, mostly because if it was good enough, it would be the first thing out of the mouth of every blackhat that was caught... Or to put it in a slightly more nuanced fashion, as a blackhat I could compromise your system, and then turn around and inform you that your system was being compromised whilst at the same time profiting from any data I had already stolen . If the company being contacted does not personally kn…

> Or to put it in a slightly more nuanced fashion, as a blackhat I could compromise your system, and then turn around and inform you that your system was being compromised whilst at the same time profiting from any data I had already stolen . Which provides a perfectly reasonable way to distinguish the white hat from the black hat. The black hat is the one making fraudulent charges to stolen credit cards, or selling…

" a perfectly reasonable way to distinguish "

Well no, not really. After all, the blackhat isn't telling you that they're also busy selling your data to someone. And even if you are aware that the data is being sold, the blackhat can claim that it must be another intruder using the same flaw, and geez, you really should fix that!

Re: Yahoo Hacked

#232

Earlier quoted context omitted.

>> Yahoo takes external security reports seriously Few weeks ago, I reported to your team that some of the yahoo servers' SSL cert were expired, acknowledged but no one want to fix it (until I post it here and finally get them updated...your site was showing security warning to your users for 2 weeks) One of your awesome engineers replied the issue with expired SSL cert: "there do not appear to be any security implic…

I appreciate you reporting expired certs, which unfortunately happen from time to time. That canned reply for is not appropriate and not a reflection of how we approach TLS and I will get it changed.

which unfortunately happen from time to time

How on earth do you manage that? Surely you have a process for monitoring and maintaining them?

Re: Yahoo Hacked

#233
post #188

Earlier quoted context omitted.

Before Yahoo poached him to be their CISO, Alex was one of the principals behind iSEC Partners, our former arch-competitor and now sister company. He knows what he's talking about. If he says they're on top of shellshock, my money would be on him being right. His team also recently poached Chris Rohlf, from his own company no less!, and Chris is probably one of the best vulnerability researchers working. (I have no a…

This all sounds good - especially given your reputation for infosec. However, genuine question - how does the laymen (like myself) rate infosec specialists? Imagine for a second I'm a senior exec at Target and IBN (IBM's fake arch-competitor) comes to me and says "no worries about security, we use 256-bit encryption, bank grade security, etc etc". Do I believe him? I feel like infosec is a "I don't know what I don't…

In some organizations, infosec is just for show. They do it because compliance forces them to do so. In those organizations, the senior execs don't care. They only want to keep the cost down and to comply with audits. They hire managers who do that and mostly rely on legal contracts and agreements to enforce security. When they get hacked, they will pull out the report (or whatever) that states that they are XYZ compliant.

Re: Yahoo Hacked

#235

Earlier quoted context omitted.

I appreciate you reporting expired certs, which unfortunately happen from time to time. That canned reply for is not appropriate and not a reflection of how we approach TLS and I will get it changed.

which unfortunately happen from time to time How on earth do you manage that? Surely you have a process for monitoring and maintaining them?

Any real third party certification authority will let you generate emails to an address of your choice 90, 30, 14, and 3 days before your cert expires (or some similar schedule)

Why wouldn't Yahoo set this up to email the group responsible or a ticketing email?

Re: Yahoo Hacked

#236

Earlier quoted context omitted.

I'm a share holder, making me an "owner" of a publicly traded company. And, who are you?

Then raise the issue at a shareholder meeting. Owning 2 shares (or 200) won't get you access to logs.

With proper controls, even having 40% of shares won't get you log files having user information. Those roles should be separated.

Re: Yahoo Hacked

#237

Earlier quoted context omitted.

which unfortunately happen from time to time How on earth do you manage that? Surely you have a process for monitoring and maintaining them?

Any real third party certification authority will let you generate emails to an address of your choice 90, 30, 14, and 3 days before your cert expires (or some similar schedule) Why wouldn't Yahoo set this up to email the group responsible or a ticketing email?

Or you know, create a reminder in Yahoo! Calendar...

Re: Yahoo Hacked

#238

Earlier quoted context omitted.

> Or to put it in a slightly more nuanced fashion, as a blackhat I could compromise your system, and then turn around and inform you that your system was being compromised whilst at the same time profiting from any data I had already stolen . Which provides a perfectly reasonable way to distinguish the white hat from the black hat. The black hat is the one making fraudulent charges to stolen credit cards, or selling…

" a perfectly reasonable way to distinguish " Well no, not really. After all, the blackhat isn't telling you that they're also busy selling your data to someone. And even if you are aware that the data is being sold, the blackhat can claim that it must be another intruder using the same flaw, and geez, you really should fix that!

If the data "is being sold" then go arrest whoever is selling it. This is basic police work. Someone is making fraudulent credit card charges? Go nab the guy when he goes to pick up the merchandize, then turn him against whoever provided the credit card numbers (if it wasn't the same person).

Doesn't that make a lot more sense than charging anyone who cuts across your lawn with grand theft just because someone engaged in grand theft might cut across your lawn?

Re: Yahoo Hacked

#239

Earlier quoted context omitted.

>> Yahoo takes external security reports seriously Few weeks ago, I reported to your team that some of the yahoo servers' SSL cert were expired, acknowledged but no one want to fix it (until I post it here and finally get them updated...your site was showing security warning to your users for 2 weeks) One of your awesome engineers replied the issue with expired SSL cert: "there do not appear to be any security implic…

I appreciate you reporting expired certs, which unfortunately happen from time to time. That canned reply for is not appropriate and not a reflection of how we approach TLS and I will get it changed.

Does your "successful" bug bounty program still only pays $12,50 in store credit per bug? That could explain the lack of interest in contacting you about any bug at all.

Re: Yahoo Hacked

#240

Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…

It looks like the guy who originally posted this has pretty much accused you of flat out lying about this[1]. What do you have to say to his comments, particularly about the sports servers being internal.

[1] - http://www.futuresouth.us/wordpress/?p=25

Post reply on HN