Earlier quoted context omitted.
So Yahoo would have been insured for somewhere between $30 Billion and $3 Trillion in this scheme? That seems untenable. Good luck collecting from the bankrupt insurer.
Good point, although the report states 3 billion user accounts were breached but this doesn't mean 3 billion people. I am guessing the vast majority of accounts did not contain any sensitive information. And maybe insurance isn't the right word; the risk should probably fall to the company holding the data, not a third party who would never be able to audit every single step to ensure there is no weak link.
Yahoo Triples Estimate of Breached Accounts to 3B
171–180 of 311 posts
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#172I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.
My personal data is an asset. And it belongs to me. Anyone who has my data for any purpose owes me my cut. Making this a property rights issue solves all the privacy & identity issues.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#173The IP address is in the 200 range. I used to remember the IP address for many years due to photographic memory even though I had only seen it briefly once. But I just cannot dig up that memory anymore.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#174Earlier quoted context omitted.
This can be done easily if you own a domain and use a service that lets you specify a catch-all address. I do this with my own domain and G Suite. Then, you don't even need to do any preparation before giving out the address. It does sound weird to the person writing it down and I've had more than one person say something like "well, if you're just going to give me a fake address, then don't bother" before I explaine…
Go into Gmail settings and add aliases there for each “account” you want to add to the catch-all. Actual separate accounts costs you $5+/month each. (I do similar on my domains and the Gmail alias is easier to do than logging into Admin CP and adding aliases there)
username+anything@mydomain.com is also a useful feature (as well as u.s.er.nam.e@mydomain.com – dots are all ignored in GMail; some services don't allow "+" in email address field, so you can use finite number of variants with ".").
These little tricks make GMail convenient for geeks :)
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#175Earlier quoted context omitted.
It also works with foo.bar which is a little harder to filter.
Well, not exactly. That would only work if your address was registered as foobar@gmail.com but not if it was registered as foo@gmail.com. Essentially, periods don't matter in gmail addresses. Adding a . in between any of the characters (or removing, if you registered the account to have .'s included) will still go to the same email address. But you can't add .anystring to your address and still receive the message as…
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#176Earlier quoted context omitted.
How much do you actually need to know about someone to serve up email to them?
For a consumer mail service, you to need to know enough to let them recover their account, possibly with decades of un-backed-up correspondence with and photos of since-deceased friends and relatives, when they’ve forgotten their password, and without letting someone else recover their account. This is a hard problem. (I’m expecting some idealized “solutions” from people with idealized beliefs about mass market tech…
i.e. when I sign up with you, I can choose my own preferred vendor to handle identity recovery.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#177Earlier quoted context omitted.
You agree to give up your data in return for services. Yahoo mail, or gmail for that matter aren't actually free. You are trading your data for a service.
No contract may take away a person's rights.
A common example is an arbitration clause, where you sign away your rights to use the courts to resolve disputes.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#178Earlier quoted context omitted.
Personal information is less valuable on the black market due to the difficulty in monetising and extracting the cash. If I have your bank account login details I can move cash out of your bank, but almost no hope of sending cash from a U.K. Domestic savings account to my friendly philapines bank over the web UI. That's why Nigerian Princes still send out emails - the find the one idiot willing to walk into his bank…
I guess we have nothing to worry about with all these data breaches then, right? Might as well tell equifax that it’s no big deal too. These criminals trade data because it makes them money, otherwise there wouldn’t be much of a makrket.
Sensitive personal data is necessary but not sufficient to rip someone off. And if you want to try to make a living ripping people off, there is even more business overhead, making the cost of sensitive personal data an even smaller portion of overall operational costs.
From the point of view of the thief, our personal data is a vital but cheap input into an operation that tends to have very high security costs, viciously expensive liquidity issues and terrible personnel problems, among other more quotidian business headaches.[1]
I suggest trying to think like a crook now and then. Trying to try on other people's lives is a useful way of shaking up one's thinking habits, empathy (don't confuse with sympathy) is always useful, and it can help you keep yourself more secure.
[1] I am leaving out things like several potential fates far worse than bankruptcy and related issues because they aren't opex-related, but they probably do effect retirement planning.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#179Re: Yahoo Triples Estimate of Breached Accounts to 3B
#180Earlier quoted context omitted.
With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header. I’m sure spammers have already figured that out.
Lots of programmers haven't, though. I get addresses rejected as invalid when signing up for some service at least once a month.