Live data from Hacker News

Yahoo Triples Estimate of Breached Accounts to 3B

wsj.com

161–170 of 311 posts

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#161
post #150
post #141

Earlier quoted context omitted.

Pretty sure it's the same across the world, really. Try getting your medical records expunged in Cuba or your search records expunged in China. I bet you have the same success as in the US.

Maybe you should look at free people in mostly free countries, instead of dictatorships. For instance, the EU and Switzerland.

Have you successfully gotten Google or Facebook or your doctor to purge your records in Switzerland?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#162
post #144

Earlier quoted context omitted.

Value is derived from the potential application of data. Ads as an application isn't worth much since you can still be shown ads just fine without any personal data targeting. Black market data is worth way more because it's often more personal than just demographic markers and interests, and can potentially lead to large sums of money.

Well no that's incorrect. A targeted ad is worth significantly more than one without targeting. I buy ads at a $0.25 cpm and a $40 cpm, the only difference is targeting data.

You can still show the ads and there are a lot of other signals and context to use. Also other than Facebook or google with strong identity, 3rd party data on the open web is next to useless. If you’re paying $40cpm for data, you’re getting ripped off.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#164

Earlier quoted context omitted.

Value is derived from the potential application of data. Ads as an application isn't worth much since you can still be shown ads just fine without any personal data targeting. Black market data is worth way more because it's often more personal than just demographic markers and interests, and can potentially lead to large sums of money.

Personal information is less valuable on the black market due to the difficulty in monetising and extracting the cash. If I have your bank account login details I can move cash out of your bank, but almost no hope of sending cash from a U.K. Domestic savings account to my friendly philapines bank over the web UI. That's why Nigerian Princes still send out emails - the find the one idiot willing to walk into his bank…

I guess we have nothing to worry about with all these data breaches then, right? Might as well tell equifax that it’s no big deal too.

These criminals trade data because it makes them money, otherwise there wouldn’t be much of a makrket.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#165
post #12

Earlier quoted context omitted.

Wait for the day that Facebook is hacked.

I'd be pretty surprised if an attacker could actually get away with a lot of sensitive, actionable bulk user data from Facebook. DMs would probably be way too big in total, unless they just looked for DMs of high-profile people. As for passwords, they're probably not stored in a very crackable format (probably some kind of super-bcrypt-esque algorithm with a pepper). Of course, they could hijack the login procedure a…

> Of course, they could hijack the login procedure and harvest passwords in real-time until they're detected.

Facebook makes it really hard for people to log off. Unless one is using a shared computer, I doubt she types her password more than a couple times a year.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#166

Earlier quoted context omitted.

It depends. It's possible a company could catch a breach while the data is being dumped to s3/russia/wherever and cut it off before everything is extracted. Another possibility is that only one particular system is breached, which wouldn't actually affect all users of a given company. If Facebook were hacked, it's possible that only the ad-buy system is compromised and not their entire user store, for example, thus e…

> Another possibility is that only one particular system is breached, which wouldn't actually affect all users of a given company And a third possibility, especially given today's trend to distributed systems, is that the attacker gains access to one shard (or its dump) only.

I am assuming shards are much smaller than 1/3rd of all the data.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#167
post #43

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

Alternatively, if it's truly an asset, can it be taxed as an asset? If I give a company a car, that is taxed. If I give a company my data which is worth more than a car, it isn't. Is it possible that current accounting/tax law can be interpreted so that these are viewed similarly?

The asset concept is interesting. If you introduce taxes into the mix then you will also need to value your asset. If you sell your asset then you need to record a fair value price for which you bought it and when... that way you can record a short or long term capital gain. The problem with digital assets is that you can easily copy them. So what does it mean to sell an asset which you actually still own/have a copy of. Its a bit tough to conceptualize - but I think there's something there... requires a bit more brainstorming.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#168

3 billion - we live in an age where half the population of the earth can exist on a service, and everyone is vulnerable. Yes, a good chunk of these are probably duplicates for business / spam / anon accounts, but this is where the world is trending. How long is it until facebook or google have a massive breach?

I'm not being snarky, but do you think they would tell us if they did? We have to assume they are prime targets. They might have slightly better personnel, but is that enough to out do the nefarious and the determined? And can we discount a rouge employee?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#169
post #144

Earlier quoted context omitted.

Well no that's incorrect. A targeted ad is worth significantly more than one without targeting. I buy ads at a $0.25 cpm and a $40 cpm, the only difference is targeting data.

You can still show the ads and there are a lot of other signals and context to use. Also other than Facebook or google with strong identity, 3rd party data on the open web is next to useless. If you’re paying $40cpm for data, you’re getting ripped off.

Sorry to be that guy, but: I spend over $5m a year on rtb ads. I literally spend 50 hours a week doing this. If the money I spend doesn't produce verifiable results, I lose it.

For example, that 40cpm is to reach a pool of <1000 users who are in charge of purchasing for networks of hospitals, and my ads are for MRI machines. 3rd party data is unbelievably valuable, probably $1.5 million of my budget goes to data costs alone.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#170

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

This is how the civil legal system is supposed to function. There needs to be some very large class action lawsuits brought against these companies, and huge awards need to be extracted in order increase the financial risk of having shitty infosec.
Post reply on HN