Yahoo hack warning: What happened and should you be worried?
telegraph.co.uk
Yahoo hack warning: What happened and should you be worried?
1–10 of 44 posts
Re: Yahoo hack warning: What happened and should you be worried?
#2EDIT: This seems like a better source: http://www.telegraph.co.uk/technology/2017/02/16/yahoo-hack-...
Re: Yahoo hack warning: What happened and should you be worried?
#3This is just a case of poor management, if Google, Facebook, Twitter and others can figure out how to secure their sites, Yahoo can.
Re: Yahoo hack warning: What happened and should you be worried?
#4Re: Yahoo hack warning: What happened and should you be worried?
#5Re: Yahoo hack warning: What happened and should you be worried?
#6Re: Yahoo hack warning: What happened and should you be worried?
#7How could someone forge a cookie after stealing the source code? Did yahoo use a hardcoded private key in the code? Then any developer at yahoo could have broken into an account. That cannot be right.
Re: Yahoo hack warning: What happened and should you be worried?
#8Jeez, how do they still have a positive net worth? Like seriously, obviously their users & user data is worthless, they don't care about it getting stolen, nor do they seem serious about fixing their dilapidated, insecure systems. This is just a case of poor management, if Google, Facebook, Twitter and others can figure out how to secure their sites, Yahoo can.
Open up any random NIST, ISO or even PCI doc to see what is involved above and beyond bug squashing.
Re: Yahoo hack warning: What happened and should you be worried?
#9Has anybody ever seen Y! Confidential link pop-up in the bottom right corner of some Yahoo! articles which seemed to redirect to an internal corporate site? It came and went away at least a dozen times and in some instances it stayed for days.
Certainly lots of very confused people keep seeing it.
Re: Yahoo hack warning: What happened and should you be worried?
#10This is a weird place to use implicated as it makes the reader think those billion users are to blame for the hack. If that's true, it's a human-scale DDOS - no IoT devices needed.