Live data from Hacker News

Yahoo Triples Estimate of Breached Accounts to 3B

wsj.com

221–230 of 311 posts

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#221

Earlier quoted context omitted.

You agree to give up your data in return for services. Yahoo mail, or gmail for that matter aren't actually free. You are trading your data for a service.

No contract may take away a person's rights.

I don't understand. You believe you have the right to have no records of yourself written anywhere. You believe it is impossible to contract away this right. You've given HN an individual identifier for yourself, and also furnished your political views (a specially protected category under the GDPR) to its database.

Aren't all your comments proof of Y Combinator's human rights violation against you? Shall we have HN shut down and its operators jailed? Obviously this isn't the world we live in, but isn't it the one you're arguing for?

Maybe you can't give permission to have data treated carelessly, but it seems absurd to say you can't give permission to have data collected at all. Opening an account with Yahoo is surely consent to let Yahoo have a record of that account.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#222
post #169

Earlier quoted context omitted.

Sorry to be that guy, but: I spend over $5m a year on rtb ads. I literally spend 50 hours a week doing this. If the money I spend doesn't produce verifiable results, I lose it. For example, that 40cpm is to reach a pool of <1000 users who are in charge of purchasing for networks of hospitals, and my ads are for MRI machines. 3rd party data is unbelievably valuable, probably $1.5 million of my budget goes to data cost…

They're swayed by ads? I'm surprised they don't need to do a formal RFP among the handful of companies who can make an MRI certified for medical use.

The targeted viewer may see the ad and start thinking "we need a better modern MRI with whatever fancy feature I read about here" or "we could hire a new MRI from xyz cheaper than our current contract!".

Sometimes you can prod your potential customers into action.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#223

Earlier quoted context omitted.

Test accounts.

+1. I did the same. At the time I had to do this (around 2015), Yahoo was the least concerned about identifying duplicate accounts. I was testing for an actual paying job, not some side interest investigation, mind you. Some of the services I had to test were clever enough to reject fakeinbox accounts so I used Yahoo.

> I was testing for an actual paying job, not some side interest investigation

What difference would it make?

Do you mean to imply that creating test accounts is a little bit "wrong", and would be wrong for an individual to do at home, but it's OK to do it if someone else is paying you for it?

If so, I disagree on both counts: it's not wrong to create test accounts, but if it was, it would still be wrong even if someone is paying you to do it.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#224
post #43

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

Alternatively, if it's truly an asset, can it be taxed as an asset? If I give a company a car, that is taxed. If I give a company my data which is worth more than a car, it isn't. Is it possible that current accounting/tax law can be interpreted so that these are viewed similarly?

> Is it possible that current accounting/tax law can be interpreted so that these are viewed similarly?

Yes, that actually happens to be the status quo.

A collection of data is an intellectual property asset just like a patent, or movie rights, or your brand.

If you buy a database, you will, depending on the costs, have to deprecate it over its useful lifetime. That means your tax burden in the first year will be higher than if you blew the money on the company Christmas party. That's the same as if you bought a software license, or Coca Cola Co.

If you collect the data yourself, that mechanism doesn't kick in. The reason is that it's difficult to value intellectual properties' value unless they're traded, and it would allow for too much manipulation of a company's profits.

Now these assets aren't taxed on an ongoing basis in the way you imply. That's because no assets are, except real estate in some jurisdictions.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#225

Earlier quoted context omitted.

Test accounts.

+1. I did the same. At the time I had to do this (around 2015), Yahoo was the least concerned about identifying duplicate accounts. I was testing for an actual paying job, not some side interest investigation, mind you. Some of the services I had to test were clever enough to reject fakeinbox accounts so I used Yahoo.

We've created a catch-all *@test.company.com with AWS SES & Lambda, all forwarded to a single test@company.com (a GApps group where the QA staff had access). Took a few tries to get right, but worked flawlessly from then on, saving testers' time every single day.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#226

Earlier quoted context omitted.

I know a guy who uses a service that creates a unique email account for every service he signs up for. That way, he tells me, if he ever gets any spam, he can delete the account and it doesn't affect any of his other email accounts.

With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header.

Independent of the concept's wisdom or implementation, Yahoo! introduced disposable addresses (originally marketed as 'Address Guard') back in 2003: http://web.archive.org/web/20031023014724/http://biz.yahoo.c...

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#227
post #69

Earlier quoted context omitted.

I believe EU's GDPR made some efforts in that direction, but I'm not sure it went far enough. We need laws that give companies incentive to store very little data on us outside of what's absolutely required for the functioning of the service. And if they do store additional info, and their servers are breached, then automatic hefty fines should be paid (right after the mandatory notification to authorities and the pu…

I was about to mention the GDPR - it definitely is a step in the right direction. I don't think that it doesn't go far enough - compared to previous regulations, it is quite severe, and it already is a pain to implement as it is. If it went any further, many companies would probably not even bother and somehow do their business outside the EU, or just prepare to be fined > if they do store additional info, and their…

GDPR already does more than any existing law in either US or Europe (not sure about other countries). As every law it will be reviewed and can be made stricter. Changes are likely needed anyway as companies try to circumvent the directive with "creative" ways or incentives for users to give up privacy.

But it's a huge step forward compared to the existing situation.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#228
post #207

Earlier quoted context omitted.

Might be better off spending £5k+ on personal gifts for each decision maker than bothering with Web advertising if it's that few people you're targeting :-)

I may not be a lawyer, but gifts of $5k to induce someone to purchase a thing for their workplace feels like it should count as corruption and bribery. If someone tried to do that to me, I’d report the attempt to the company lawyer, and I’d doubt the quality of the thing they were selling was as good as the quality of the thing the other poster was advertising.

5k+ per person would be bribery. I hope he meant 5k in total..., 1000 gifts of 5$ would be ok

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#229

Earlier quoted context omitted.

Hundreds? Are you sure?

With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header. I’m sure spammers have already figured that out.

A lot of services don't allow + in email addresses. With gmail you can also insert a . anywhere you like which works more often. But sometimes, catch all addresses really help to test.
Post reply on HN