Live data from Hacker News

An Important Message About Yahoo User Security

yahoo.tumblr.com

111–120 of 356 posts

Re: An Important Message About Yahoo User Security

#111
post #12

Moving email addresses out from one provider and creating another one is more difficult than moving phone numbers (in the latter case, number portability could help, if available). What exactly can an average/common end user do for such incidents, even if it is to avoid them in the future? I use different passwords across accounts, with all of them being somewhat complex or very complex. I have looked at a few differ…

Zoho has a free, ad-free service¹ that allows: 1 domain, 5GB per user e-mail hosting, and 5GB per user document storage for up to 25 users. Pricing seems reasonable beyond that. They provide incentives in the form of additional users for referrals (my referral code: WX7yxEKy). They also support 2-factor authentication. ¹ https://www.zoho.com/mail/zohomail-pricing.html

I love how every time a company is compromised, everyone pops with their own "uncompromised" service offer.

As if, this one would never get compromised and they were much better at it. Except they probably aren't. Bet the devs have all keys on their "work" laptop (you know, the one with stickers that they take home, to starbucks, on vacations, watch their movies on, etc.) (like everyone elses is doing)

Sooo narrow-sighted.

Re: An Important Message About Yahoo User Security

#112
post #12

Moving email addresses out from one provider and creating another one is more difficult than moving phone numbers (in the latter case, number portability could help, if available). What exactly can an average/common end user do for such incidents, even if it is to avoid them in the future? I use different passwords across accounts, with all of them being somewhat complex or very complex. I have looked at a few differ…

Zoho has a free, ad-free service¹ that allows: 1 domain, 5GB per user e-mail hosting, and 5GB per user document storage for up to 25 users. Pricing seems reasonable beyond that. They provide incentives in the form of additional users for referrals (my referral code: WX7yxEKy). They also support 2-factor authentication. ¹ https://www.zoho.com/mail/zohomail-pricing.html

[deleted]

Re: An Important Message About Yahoo User Security

#113
post #64

"by what it believed was a "state-sponsored actor.""

I don't understand what difference it makes if it's state-sponsored or not. It seems like Yahoo's PR wants to switch focus to state-sponsored hacking and form a narrative around what's been in the news lately as opposed to Yahoo's incompetence. Also it's less embarrassing to get hacked by a whole nation than a few nerds in their basement.

IMO:

State attack = a state steals the access and keep the breach secret for as long as they can [or until they get hacked themselves]. They use it for espionage and similar purposes

Evil bad guy = all accounts and passwords are already available on blackmarket.com since Day+1 after the breach. They'll probably end up in a torrent within the next month.

Evil bad guy sponsored by a state = Well, somewhere between the two. Hopefully the state ensures they get exclusive access and non disclosure.

Re: An Important Message About Yahoo User Security

#114

"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this. also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.

all hacks have signatures.. usually the tools used by the hackers to compromise the system.

Attribution is hard.

Re: An Important Message About Yahoo User Security

#115

"The data stolen may have included names, email addresses, telephone numbers, dates of birth and hashed passwords but may not have included unprotected passwords, payment card data or bank account information, the company said." What's the difference between "may have" and "may not have" in this context? It seems like they're saying anything could have been stolen.

Well, "anything could have been stolen" is always true of all data stored anywhere.

Re: An Important Message About Yahoo User Security

#116

Yahoo will survive this regardless of their 'state sponsored' hand waving or not. The day the same happens to Google or Facebook will be very different.

Will it? Why? If anything, Google and Facebook seem to be more firmly entrenched in everyone's day-to-day lives and are more likely to get the "too big to fail" treatment.

Re: An Important Message About Yahoo User Security

#117
post #97

Sometimes I play with the notion of a future without asymmetric information. If it is to be known it is known by all.

The trouble is that confidentiality and integrity play against each other in useful ways. For instance, even if I have nothing private to say in my email, if you want to authenticate messages as coming from me, I need a private key to sign my email so that nobody else does.

Even in a hypothetical future where, say, two employees in a company couldn't communicate privately without the entire rest of the company knowing (and I question whether that would be a good future), you still want the ability for one employee to communicate and certify the message as coming from them. Otherwise I could give myself bonuses. That requires some password or key known to me and only to me; that requires that cookies and other session state on my computer are only accessible to me.

Re: An Important Message About Yahoo User Security

#120
Wait, Yahoo believes the data was stolen by a "state-sponsored actor"!

If they have such evidence, why don't they explain so? To me it looks like a tactic to put the focus on the "noughty" government instead of themselves.

Anyway, it will be an interesting read (if ever written) how Yahoo discovered they had been stolen and by who (what state?).

Also, if "the state" is finally behind this, who will they prosecute till death? I bet it's the hacker :(

Post reply on HN