Live data from Hacker News

An Important Message About Yahoo User Security

yahoo.tumblr.com

211–220 of 356 posts

Re: An Important Message About Yahoo User Security

#211

Moving email addresses out from one provider and creating another one is more difficult than moving phone numbers (in the latter case, number portability could help, if available). What exactly can an average/common end user do for such incidents, even if it is to avoid them in the future? I use different passwords across accounts, with all of them being somewhat complex or very complex. I have looked at a few differ…

Number portability helps you keep your same number with a different provider, I don't think it's relevant when you're talking about switching numbers. Also, email forwarding is easier to set up than call forwarding, and just overall I think switching email addresses is easier.

Re: An Important Message About Yahoo User Security

#212
post #107

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

Investors are conflicted: on the one hand, Yahoo had a data breach that will cost them trust, but on the other hand, investors are surprised to hear there are still 500 million Yahoo users.

500m users is different than 500m active users, plus I wonder how many people use yahoo for fantasy sports and nothing else

Re: An Important Message About Yahoo User Security

#214

"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this. also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.

"I mean, look at this: it was a STATE-sponsored-entity that did that to us! We were overwhelmed... Did not stand a chance... I need a hug..." - At least this is how I interpreted it. They put in all the right words: "threats, Industry, government, crosshairs, strategic". Edit: "...by what it believes is a state..."??? Who is IT?

If they claim it was a state-sponsored attack and then a non-state-sponsored hacking group makes a credible claim to have been the perpetrators, Yahoo will look even worse than they do now. I doubt Yahoo is saying 'state-sponsored' just for PR.

Re: An Important Message About Yahoo User Security

#215

"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this. also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.

Yeah, unfortunately I think this has become a trend. If a big company gets hacked, they can just say "Well, this sucks, but what could innocent helpless little us have done against a whole country like [Russia, NK, Iran, other stereotypical boogeyman to American audiences]?" It's quite transparent BS in every case I've seen thus far (prominently, Sony and the DNC), but it definitely earns the hacked company some sympathy, and it allows them to feel more important and make others think they're important enough for a nation-state to try to steal from them.

Since it's worked a couple of times, now everyone is going to pile on. I expect every major data breach over the next few years is going to be perpetrated by an ethereal "state-sponsored actor".

Re: An Important Message About Yahoo User Security

#216

Earlier quoted context omitted.

Yes. It's now $5/month/user. (plans are grandfathered however)

You also get 1TB of storage with that, and unlimited storage with 5+ accounts. I do this for my family, and we all have unlimited backups and custom domain email.

What client software do you use to access the storage and to backup to it? Is it reliable and cross-platform, by any chance? =)

Re: An Important Message About Yahoo User Security

#217

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

It makes a lot of sense if you consider that most users don't give a damn about security.

Re: An Important Message About Yahoo User Security

#218
post #107

Earlier quoted context omitted.

Investors are conflicted: on the one hand, Yahoo had a data breach that will cost them trust, but on the other hand, investors are surprised to hear there are still 500 million Yahoo users.

Conflicted?

sure. but somehow, among a sea of replies that either don't care for my joke, or who just don't understand that it is a joke, yours manages to be the most off putting.

Re: An Important Message About Yahoo User Security

#219

"The data stolen may have included names, email addresses, telephone numbers, dates of birth and hashed passwords but may not have included unprotected passwords, payment card data or bank account information, the company said." What's the difference between "may have" and "may not have" in this context? It seems like they're saying anything could have been stolen.

> may not have included unprotected passwords Yeah, they shouldn't have unprotected passwords in any way, shape, or form. The statement makes it sound like they do store unprotected passwords, but they don't think those were stolen.

I read it as perhaps some old dormant accounts never got migrated out of an ancient DB, and may have been picked up with the rest of the data.

Yahoo is an old company, I'm sure procedures have changed drastically over the years.

Re: An Important Message About Yahoo User Security

#220

Yahoo has recommended that users "check their accounts". What exactly would they be checking? Doesn't a compromised account look the same as an uncompromised account from a user perspective?

Potentially, you could have weird locations signing in, emails you didn't send in your sent items. But yeah, seems unlikely that a 'state-sponsored attack' on this scale wouldn't be able to cover their tracks in the eyes of Yahoo Mail users.
Post reply on HN