Live data from Hacker News

An Important Message About Yahoo User Security

yahoo.tumblr.com

241–250 of 356 posts

Re: An Important Message About Yahoo User Security

#242
post #219

Earlier quoted context omitted.

I read it as perhaps some old dormant accounts never got migrated out of an ancient DB, and may have been picked up with the rest of the data. Yahoo is an old company, I'm sure procedures have changed drastically over the years.

Is that good? They have poor data handling and sunsetting protocols is what you're saying. UK law requires that personal data is not kept for longer than is necessary and is securely handled and such. So if those passwords in an "ancient DB" had personal data associated with them (real names, say) then they've been breaking the law (for a long time, is the implication). Surely if you had passwords in old DBs then whe…

Interesting point on the UK laws, but I doubt PII is kept alongside login data, just referenced, and removed as needed without removing a user's login credentials.

Far from an expert, but hasn't flagging an account as needing a password change on next login been used as a way to migrate to properly encrypted passwords in the past?

Re: An Important Message About Yahoo User Security

#243

"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this. also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.

While attribution is difficult and sometimes impossible, if you find that the attacker used custom malware/infrastructure also seen in other attacks, it is likely that it's the same attacker group. And in some cases, it's known that certain groups work for certain governments.

Re: An Important Message About Yahoo User Security

#244

Earlier quoted context omitted.

That is an incredibly deceptive sentence. They should have listed everything under "may have", unless I'm misunderstanding because they used some convoluted English.

The way I read it is that the stolen data has a relatively high probability of including the first set of things, but a relatively low probability of including the second set of things. They don't want to say definitively for whatever reason.

Possibly, although they may have phrased it that way precisely to elicit your generous interpretation. Even in the scenario that they knew unprotected passwords were just as likely to have been stolen as properly protected ones.

Re: An Important Message About Yahoo User Security

#245

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

> You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%).

Why would the stock be affected? Yahoo emails are free. Even if majority is hacked this won't make dent in their revenue streams coming mostly from advertising.

Re: An Important Message About Yahoo User Security

#246
post #67
post #14

Earlier quoted context omitted.

Buying a domain name is the equivalent of number portability. Recommended for everyone.

On the flip side, I did that and while generally it's been a positive experience, providing your email address over the phone has become huge pain! I definitely took for granted how easy it is to say to someone "first initial + last name at major email provider . com", instead of "really easy first part at custom domain, wait let me give you the phonetic alphabet equivalent, no just the letter b, not actually the wor…

Never use a domain for email or a business that you can't say clearly over the phone without spelling it.

Re: An Important Message About Yahoo User Security

#247
post #231

Earlier quoted context omitted.

I started using their "Account Key" process, any time I log in on the site from a computer, I get a notification from my Yahoo sports app (iPhone) asking me if I would like to allow the login attempt. I actually like it better than the two-factor auth I use for other accounts. Whether it's more secure or not, I don't know.. EDIT: just for clarification, this replaces the password entirely. So I never enter a password…

If you don't enter a password, then it isn't two factor auth at all. It just swapping one-factor (something you know) for another (something you have).

if something you have requires a password, you still have two-factor. Kind of.

Re: An Important Message About Yahoo User Security

#248

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

It doesn't affect stock price because it doesn't really affect the money being made. There aren't going to be any huge fines that need to be paid, they aren't really going to lose customers explicitly due to this. After all, it was _hackers_ that broke in and did bad things, you can't completely protect yourself from hackers. If the difference between having a secure company and an insecure company were cut and dry, then it might have an affect. But the entire security landscape is so nuanced and complicated that the average person watching/reading the news isn't going to know the difference between 2 different companies (one with good security practices and one without).

Re: An Important Message About Yahoo User Security

#249

Earlier quoted context omitted.

I'm not sure what you're trying to say. The algorithms adjust for bots, spam, cross-platform duplication, etc. 900M - 1B is defined as the Monthly Active Users figure. Naturally, there are areas where we know the algorithms are not translating the inputs to real users with 100% fidelity, but we know that the discount is relatively minor, not nearly as substantial as youre suggesting. Multiple counter-parties had thei…

Maybe the parent would define a "user" as someone with an email and password in a users table?

Exactly.

Unique visitors versus active accounts.

Re: An Important Message About Yahoo User Security

#250
post #184

Earlier quoted context omitted.

a) Big US enterprises are under attack from state-sponsored actors on a daily basis, so it's not that weird. It's not like the NSA weren't caught with their hands in the cookie jar either. b) If you name the state you think is behind it, you better be ready for the diplomatic repercussions between the US government and the rogue state, as well as potentially stopping doing business in that state (see Google and China…

a) Can you point to an article were I can learn more about examples of big US corps being attacked by US sponsored actors? It's a quite interesting topic indeed.

Does NSA tapping Google's fiber count: http://www.bbc.com/news/world-us-canada-24751821
Post reply on HN