Live data from Hacker News

Yahoo Hacked

webcache.googleusercontent.com

241–250 of 258 posts

Re: Yahoo Hacked

#241
post #233
post #188

Earlier quoted context omitted.

This all sounds good - especially given your reputation for infosec. However, genuine question - how does the laymen (like myself) rate infosec specialists? Imagine for a second I'm a senior exec at Target and IBN (IBM's fake arch-competitor) comes to me and says "no worries about security, we use 256-bit encryption, bank grade security, etc etc". Do I believe him? I feel like infosec is a "I don't know what I don't…

In some organizations, infosec is just for show. They do it because compliance forces them to do so. In those organizations, the senior execs don't care. They only want to keep the cost down and to comply with audits. They hire managers who do that and mostly rely on legal contracts and agreements to enforce security. When they get hacked, they will pull out the report (or whatever) that states that they are XYZ comp…

While I don't doubt that infosec is just for show in some places, you can't just say that when they get hacked, they'll just say "We're XYZ compliant" and do nothing else.

The whole point of those audits is to show that, while every company of any importance will eventually have some sort of breach/break-in/hack, the company takes all reasonable steps to prevent it and mitigate the possible effects of such an event.

Infosec isn't a fool-proof thing. There's no way to prevent everything, and all you can do is keep on top of things and take steps to ensure you're doing everything you can to protect your systems.

You WILL get hacked eventually.

Re: Yahoo Hacked

#242

Earlier quoted context omitted.

If I knew, I'd be a lot wealthier. :|

How much are e.g. SANS certifications worth? I subscribe to their vulnerablity emails but they push the certification programs so hard it smells a little like University of Phoenix.

I'm not a fan of any security certification.

Re: Yahoo Hacked

#243

Earlier quoted context omitted.

Any real third party certification authority will let you generate emails to an address of your choice 90, 30, 14, and 3 days before your cert expires (or some similar schedule) Why wouldn't Yahoo set this up to email the group responsible or a ticketing email?

Or you know, create a reminder in Yahoo! Calendar...

People use that??

Re: Yahoo Hacked

#244
post #152

Earlier quoted context omitted.

This thread has a lot of shaky analogies with physical trespassing. Here's an article on trespass laws (in California) - the article is more interesting than you would expect and the trespass laws are more complicated than you'd expect. http://www.shouselaw.com/trespass.html

California law is not typical is this regard (or in very many others).

It looks quite similar to Washington State trespass law in practice. If anything it might actually be broader, our criminal trespass statute up here tends to be interpreted rather narrowly because it's somewhat lacking in detail.

Re: Yahoo Hacked

#245
post #240

Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…

It looks like the guy who originally posted this has pretty much accused you of flat out lying about this[1]. What do you have to say to his comments, particularly about the sports servers being internal. [1] - http://www.futuresouth.us/wordpress/?p=25

That fact that the API hosts are internal seems to be the bulk of the argument against the validity of the claims here. However, internally accessible application servers behind public proxy/proxies is a fairly common pattern...

Re: Yahoo Hacked

#246

Earlier quoted context omitted.

I have mixed feelings about this. I think you're probably right that he did this with altruistic intent (or, at worst, just to satisfy his curiosity), and I hope he hasn't gotten himself into serious trouble. (Though I fear he may have.) But I hasten to add that intent is clearly not dispositive of whether it was OK for him to infiltrate someone else's system. Certainly ordinary physical property law makes is an offe…

> Certainly ordinary physical property law makes is an offense to trespass regardless of whether you are trespassing with malicious intent. In the case of physical property the most common remedies for trespassing are either an injunction prohibiting future trespassing on the same property or a modest fine (e.g. $100). Applying the same penalties to the equivalent behavior in the computer context would be completely…

I basically agree - though I hasten to add that I never said anything about what penalty a person would actually receive or whether it is appropriate. I do think that it makes sense for "computer tresspass" to be punished more harshly than tresspass to physical property. It takes a lot more effort to break into a server than it does to walk through someone's door (or into their yard), so I think the baseline level of culpability is higher (though bear in mind that these are generalizations). There is also a lot more risk involved in a "casual" computer tresspass. But I agree with you that this doesn't gets us to the maximum CFAA sentence.

This gets us into complicated territory, though. There are very few people who have ever actually been sentenced to the maximum CFAA penalty. (I'm actually aware of none.) The actual punishments actually imposed are often, I think, fairly reasonable.

Of course, there are plenty who have been threatened with the huge maximum by federal prosecutors, but this is no different from any other crime. Of course federal prosecutors will menace defendants with the maximum possible penalty. They want to extract a guilty plea, and it would also be dangerous for them to claim that any shorter penalty than the maximum applied, since they do no actually control sentencing. (Imagine the controversy if the U.S. Attorney told a defendant that he was only realistically looking at 6 months but the judge gave him 2 years.) It's the defense attorney's role to make sure that her client has a realistic understanding of the likely punishment, not the government's.

What's really needed is a replacement for CFAA (and, for that matter, most other criminal statutes) with more carefully graded maximum sentences, but I've never heard a realistic proposal about how such a law would work.

Re: Yahoo Hacked

#247
post #240

Howdy, Hacker News. I’m the CISO of Yahoo and I wanted to clear up some misconceptions. Earlier today, we reported that we isolated a handful of servers that were detected to have been impacted by a security flaw. After investigating the situation fully, it turns out that the servers were in fact not affected by Shellshock. Three of our Sports API servers had malicious code executed on them this weekend by attackers…

It looks like the guy who originally posted this has pretty much accused you of flat out lying about this[1]. What do you have to say to his comments, particularly about the sports servers being internal. [1] - http://www.futuresouth.us/wordpress/?p=25

Yes, the systems with the log parsing bug are part of an internal subnet. As with most web scale companies HTTPS requests are terminated on a unified edge and load-balanced to web service hosts in internal clusters. In this case the malicious header was maintained in the backend requests and ended up in the application log, which triggered the command injection. Everything I wrote above is correct and is in no way incompatible with the fact that the affected machines have RFC1918 addresses.

Re: Yahoo Hacked

#248
post #197

Earlier quoted context omitted.

Second datapoint. In FI everyone who did not use IRC used ICQ and then switched to MSN.

Also AU and used ICQ; then MSN. Note there was a strong anti-AOL sentiment throughout the 90's.

I used MSN. Now I use XMPP 'cause they wanted me to use skype instead... pffff...

Re: Yahoo Hacked

#249

Earlier quoted context omitted.

His actions enabled him to cause damage if he chose , but it would be disingenuous for us to avoid examining his intent. The only evidence we have of his intent is that he warned the hosts who were vulnerable, and also warned the customers whose personal information and private emails may no longer be safe. If he had malicious intent as you imply, then I believe he would not have disclosed anything, let alone under h…

I have mixed feelings about this. I think you're probably right that he did this with altruistic intent (or, at worst, just to satisfy his curiosity), and I hope he hasn't gotten himself into serious trouble. (Though I fear he may have.) But I hasten to add that intent is clearly not dispositive of whether it was OK for him to infiltrate someone else's system. Certainly ordinary physical property law makes is an offe…

The Law should have a case for the need to ignore some rights in order to protect other rights, given that any damage will be compensated. E.g. break a window to get someone out of a car crash. Seeing that he didn't do any damage, it should be fine. I know that's the case in German civic law. Intent is regularly a deciding factor in measure of punishment. This may as well go without a warning.

Re: Yahoo Hacked

#250
post #178
post #151

Earlier quoted context omitted.

What if his house was next to yours and he smelled a gas leak but wasn't sure, so his investigation led him to your cellar?

If he can smell it from outside my cellar, then why isn't he able to knock on my door? Or call the cops if I'm not home. Even for actual extremis (such as a fire) I'd generally expect people to call the fire department instead of breaking into my house to put a blanket over a kitchen fire. With that said I'm sympathetic to this guy's intent. If I were Yahoo or the FBI and he can prove that innocuous access is all he…

call the cops if I'm not home

yeah right, they'll fix your KDE 2 install on freebsd in a jiffy as well

Until then I'm not sure that "only the criminals can search for burning buildings on the Internet" is really the most pragmatic answer.

It's not a pragmatic answer, it's a matter of fact. NSCIA are busy collecting phone calls and developing backdoors. I'd be careful calling anyone criminal.

Post reply on HN