Live data from Hacker News

Yahoo Triples Estimate of Breached Accounts to 3B

wsj.com

101–110 of 311 posts

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#101
post #43

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

Alternatively, if it's truly an asset, can it be taxed as an asset? If I give a company a car, that is taxed. If I give a company my data which is worth more than a car, it isn't. Is it possible that current accounting/tax law can be interpreted so that these are viewed similarly?

Does that mean that your ID number (social security for U.S. readers) is taxable upon receipt (birth or immigration)? Also we will need a birthday tax as your age (a key demographic data point) changes then. A marriage tax, moving (address change) tax, employment change tax etc. Tax law will have a concept of taxable data event much like a liquidity event.

Obviously this is a silly thought exercise but it is fun to think about.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#102

Earlier quoted context omitted.

With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header.

It really baffles me that people are still suggesting this as advice for spam reduction. All it takes is a third of a brain and a couple seconds of thought to realize that spammers know this is a thing and can adapt.

They can, but in practice, they don't.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#103

On a related note Equifax stated yesterday that they identified an additional 2.5 million accounts that were breached: https://www.nytimes.com/2017/10/02/business/equifax-breach.h... Is proper audit capability just not seen as important at these companies?

To be fair Equifax's adjustment was relatively minor, and they did disclose that they were still investigating the matter.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#105

3 billion - we live in an age where half the population of the earth can exist on a service, and everyone is vulnerable. Yes, a good chunk of these are probably duplicates for business / spam / anon accounts, but this is where the world is trending. How long is it until facebook or google have a massive breach?

If that's the case, I think the bigger news then is that yahoo actually had 3B users!

Search Google for this phrase:

verified Yahoo accounts Fiverr

You'll get a sense for how many people generate these for resale to spammers and other shady purposes.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#106
post #75
post #43

Earlier quoted context omitted.

Alternatively, if it's truly an asset, can it be taxed as an asset? If I give a company a car, that is taxed. If I give a company my data which is worth more than a car, it isn't. Is it possible that current accounting/tax law can be interpreted so that these are viewed similarly?

Using the black market as a standard, your identity-related information isn't worth enough to be taxable.[0][1][2] The more common data you give away is worth even less. Your "gift" is akin to giving away a few grains of sand to a glassmaker who provides a free grain counting service. Now let's say you dumped a lot sand that we could value at $10K. Any smart sand-counting glassmaker will claim his once "free" sand co…

"None of us is as [valuable] as all of us," is a saying that has been around for decades, surely there are business rules that have cropped up to support a valuation of this scenario in the meantime.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#107

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

I reached this same conclusion from a very different angle. If you're seriously worried about the unchecked power of monopolies, and understand the effects of Metcalfe's law, we should measure the degree of monopolization of tech companies differently than we do traditional industries. Businesses are locked in to Facebook and Google the same way that businesses were locked in to doing business with Standard Oil in the gilded age. The impossibility for regular users to leave the network makes competition de facto impossible, even if the company does not actively engage in anti-competitive behavior (in many cases, they do anyway).

A tax on social software companies proportional to their network size would be an interesting proposal to solve both of these issues. It would also greatly increase the ability for 100,000 - 1,000,000 person "decentralized" social networks (like Mastodon or other competing networks) to thrive.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#108

> A massive data breach at Yahoo in 2013 was far more extensive than previously disclosed, affecting all of its 3 billion user accounts, new parent company Verizon Communications Inc. said on Tuesday. Imagine the buyers remorse

No remorse, VZ got a discount on the purchase price based on this issue.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#109
post #60

Earlier quoted context omitted.

With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header.

It also works with foo.bar which is a little harder to filter.

Well, not exactly. That would only work if your address was registered as foobar@gmail.com but not if it was registered as foo@gmail.com. Essentially, periods don't matter in gmail addresses.

Adding a . in between any of the characters (or removing, if you registered the account to have .'s included) will still go to the same email address.

But you can't add .anystring to your address and still receive the message as you can with +anystring.

This always blows the mind of the average gmail user who thinks they registered first.last@gmail.com when they find out that firstlast@gmail.com also works.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#110

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

My personal data is an asset. And it belongs to me.

Anyone who has my data for any purpose owes me my cut.

Making this a property rights issue solves all the privacy & identity issues.

Post reply on HN