Is there a better source? That link just mentions it in the title and then plugs other articles they've posted for the rest of it. EDIT: This seems like a better source: http://www.telegraph.co.uk/technology/2017/02/16/yahoo-hack-...
Yahoo hack warning: What happened and should you be worried?
21–30 of 44 posts
Re: Yahoo hack warning: What happened and should you be worried?
#22Is there a better source? That link just mentions it in the title and then plugs other articles they've posted for the rest of it. EDIT: This seems like a better source: http://www.telegraph.co.uk/technology/2017/02/16/yahoo-hack-...
And it ends in a quick how-to for deleting your Yahoo account! That's surely a death knell for Yahoo, as if it needed another?
Re: Yahoo hack warning: What happened and should you be worried?
#23Earlier quoted context omitted.
And you think those other sites are more secure? The differences are slight. Giant public websites are tricky. It is very hard to deploy real security across such a large team/platform. Even if you make the effort, some security measures simply wont fly, especially in regards to change control or network segmentation. This sort of bug is only one level of the issue. Open up any random NIST, ISO or even PCI doc to see…
I took the OPs comments as referring to the fact that management either: a) didn't know the company was hacked. b) claimed they didn't know they were hacked, c) didn't bother to do proper discovery to quantify the extent of the hack until years later.
Re: Yahoo hack warning: What happened and should you be worried?
#24Earlier quoted context omitted.
I took the OPs comments as referring to the fact that management either: a) didn't know the company was hacked. b) claimed they didn't know they were hacked, c) didn't bother to do proper discovery to quantify the extent of the hack until years later.
And that would have been covered under nist or iso or any other resonable standard. My point is that once you look into these companieas, get beyond the tech stuff, virtually none implement proper security on such large deployments.
Can you provide a citation for this? Otherwise it seems you are suggesting because Yahoo was lacking that this means all SV tech giants are lacking.
Re: Yahoo hack warning: What happened and should you be worried?
#25Earlier quoted context omitted.
And that would have been covered under nist or iso or any other resonable standard. My point is that once you look into these companieas, get beyond the tech stuff, virtually none implement proper security on such large deployments.
>"virtually none implement proper security on such large deployments." Can you provide a citation for this? Otherwise it seems you are suggesting because Yahoo was lacking that this means all SV tech giants are lacking.
Re: Yahoo hack warning: What happened and should you be worried?
#26"After disclosing two distinct hacks late last year, one of which implicated a billion users, Yahoo ..." This is a weird place to use implicated as it makes the reader think those billion users are to blame for the hack. If that's true, it's a human-scale DDOS - no IoT devices needed.
IRS Says More Taxpayers May Have Been Hacked http://time.com/4000659/irs-taxpayer-hacked-cybercrime/
It wasn't the taxpayers that were hacked - it was the IRS.
Hackers stole personal information from 104,000 taxpayers, IRS says https://www.washingtonpost.com/news/federal-eye/wp/2015/05/2...
Hackers did not steal personal information from 104,000 taxpayers - they stole it from the IRS.
Smaller media outlets often get it right:
Over 700,000 People Got Screwed in Last Year's IRS Data Breach http://gizmodo.com/over-700-000-people-got-screwed-in-last-y...
Re: Yahoo hack warning: What happened and should you be worried?
#27Earlier quoted context omitted.
>"virtually none implement proper security on such large deployments." Can you provide a citation for this? Otherwise it seems you are suggesting because Yahoo was lacking that this means all SV tech giants are lacking.
Well, without ndas make it hard to find actual reports, but take ashley-madison. Millions of users, talk of a billion-dollar ipo, and the post-hack report by the canadian and austrailian privacy ministers found they had no formal security plan.
Re: Yahoo hack warning: What happened and should you be worried?
#28"After disclosing two distinct hacks late last year, one of which implicated a billion users, Yahoo ..." This is a weird place to use implicated as it makes the reader think those billion users are to blame for the hack. If that's true, it's a human-scale DDOS - no IoT devices needed.
Re: Yahoo hack warning: What happened and should you be worried?
#29I made that mistake last time, "deleted" my yahoo account when there was a breach, promptly forgot about doing that, then about 75 days later another breach was announced, so I logged in to "delete" my account....now I have to wait another 90 days before it's gone.
Re: Yahoo hack warning: What happened and should you be worried?
#30Remember that if you deleted your account the last time a breach was reported, DO NOT attempt to login to that account to check, as this will reset the decativation window of 90 days before permanent deletion. I made that mistake last time, "deleted" my yahoo account when there was a breach, promptly forgot about doing that, then about 75 days later another breach was announced, so I logged in to "delete" my account.…
I would however never actually delete the account.
My concern with deleting the account is that it exposes you to some really nasty impersonation attacks. It is free to keep. Just keep it.