Live data from Hacker News

Yahoo Triples Estimate of Breached Accounts to 3B

wsj.com

171–180 of 311 posts

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#171
post #139
post #121

Earlier quoted context omitted.

So Yahoo would have been insured for somewhere between $30 Billion and $3 Trillion in this scheme? That seems untenable. Good luck collecting from the bankrupt insurer.

Good point, although the report states 3 billion user accounts were breached but this doesn't mean 3 billion people. I am guessing the vast majority of accounts did not contain any sensitive information. And maybe insurance isn't the right word; the risk should probably fall to the company holding the data, not a third party who would never be able to audit every single step to ensure there is no weak link.

The first step towards this is having useful industry standards for auditing and certification that actually work... then you can think about an insurance market where insurers force certification.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#172

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

My personal data is an asset. And it belongs to me. Anyone who has my data for any purpose owes me my cut. Making this a property rights issue solves all the privacy & identity issues.

I'm torn between liking this view of personal data as property and also liking the view of Richard Stallman and the FSF that "intellectual property" is a legal fiction that we ought to resist. What does it actually mean to "own" data, and is "property" the best metaphor to represent a set of personal data control rights?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#173
There is an unpatched server at some IP address long forgotten and no longer used by Yahoo but still nevertheless works. The page still shows the Yahoo portal with news on the front page from when Yasser Arafat was alive. I believe the page has not been updated since 2003.

The IP address is in the 200 range. I used to remember the IP address for many years due to photographic memory even though I had only seen it briefly once. But I just cannot dig up that memory anymore.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#174

Earlier quoted context omitted.

This can be done easily if you own a domain and use a service that lets you specify a catch-all address. I do this with my own domain and G Suite. Then, you don't even need to do any preparation before giving out the address. It does sound weird to the person writing it down and I've had more than one person say something like "well, if you're just going to give me a fake address, then don't bother" before I explaine…

Go into Gmail settings and add aliases there for each “account” you want to add to the catch-all. Actual separate accounts costs you $5+/month each. (I do similar on my domains and the Gmail alias is easier to do than logging into Admin CP and adding aliases there)

+1. I also use *@mydomain.com feature in G Suite, and it's very convenient to understand which companies sell/pass email databases to others w/o my permission. In some cases, you need to reply from that "aliased" address -- in this case, I do go to the Settings, add an alias, got a confirmation code, and confirm it. Then this new "address" is available in GMail in drop-down "From:" menu when you write a new email.

username+anything@mydomain.com is also a useful feature (as well as u.s.er.nam.e@mydomain.com – dots are all ignored in GMail; some services don't allow "+" in email address field, so you can use finite number of variants with ".").

These little tricks make GMail convenient for geeks :)

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#175
post #109
post #60

Earlier quoted context omitted.

It also works with foo.bar which is a little harder to filter.

Well, not exactly. That would only work if your address was registered as foobar@gmail.com but not if it was registered as foo@gmail.com. Essentially, periods don't matter in gmail addresses. Adding a . in between any of the characters (or removing, if you registered the account to have .'s included) will still go to the same email address. But you can't add .anystring to your address and still receive the message as…

[deleted]

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#176
post #73

Earlier quoted context omitted.

How much do you actually need to know about someone to serve up email to them?

For a consumer mail service, you to need to know enough to let them recover their account, possibly with decades of un-backed-up correspondence with and photos of since-deceased friends and relatives, when they’ve forgotten their password, and without letting someone else recover their account. This is a hard problem. (I’m expecting some idealized “solutions” from people with idealized beliefs about mass market tech…

This is such a nasty area, with such crappy solutions (name of your first pet), that it should become a service all of its own.

i.e. when I sign up with you, I can choose my own preferred vendor to handle identity recovery.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#177

Earlier quoted context omitted.

You agree to give up your data in return for services. Yahoo mail, or gmail for that matter aren't actually free. You are trading your data for a service.

No contract may take away a person's rights.

On the contrary, it is commonplace for contracts to take away your rights.

A common example is an arbitration clause, where you sign away your rights to use the courts to resolve disputes.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#178

Earlier quoted context omitted.

Personal information is less valuable on the black market due to the difficulty in monetising and extracting the cash. If I have your bank account login details I can move cash out of your bank, but almost no hope of sending cash from a U.K. Domestic savings account to my friendly philapines bank over the web UI. That's why Nigerian Princes still send out emails - the find the one idiot willing to walk into his bank…

I guess we have nothing to worry about with all these data breaches then, right? Might as well tell equifax that it’s no big deal too. These criminals trade data because it makes them money, otherwise there wouldn’t be much of a makrket.

You're correct, of course, but missing the implications raised by the parent poster, and they are important.

Sensitive personal data is necessary but not sufficient to rip someone off. And if you want to try to make a living ripping people off, there is even more business overhead, making the cost of sensitive personal data an even smaller portion of overall operational costs.

From the point of view of the thief, our personal data is a vital but cheap input into an operation that tends to have very high security costs, viciously expensive liquidity issues and terrible personnel problems, among other more quotidian business headaches.[1]

I suggest trying to think like a crook now and then. Trying to try on other people's lives is a useful way of shaking up one's thinking habits, empathy (don't confuse with sympathy) is always useful, and it can help you keep yourself more secure.

[1] I am leaving out things like several potential fates far worse than bankruptcy and related issues because they aren't opex-related, but they probably do effect retirement planning.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#179

Earlier quoted context omitted.

Nobody ever said they are active users or unique individuals. I know for example I personally created hundreds of accounts on Yahoo! over the years.

Why make hundreds of accounts?

Russians.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#180
post #88

Earlier quoted context omitted.

With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header. I’m sure spammers have already figured that out.

Lots of programmers haven't, though. I get addresses rejected as invalid when signing up for some service at least once a month.

My favorite is one site I encountered that let you create and login with such an email address, but the forgot password form couldn’t handle it and would 500.
Post reply on HN