Live data from Hacker News

Yahoo Triples Estimate of Breached Accounts to 3B

wsj.com

241–250 of 311 posts

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#241

Earlier quoted context omitted.

> You really do need user accounts to run an email service Exactly, regardless of that companies keep asking users for a whole collection of personal data, not always making it obvious which fields are actually required because it's good business for them to get as much personal data as possible. Average users are usually unsure about a lot of this stuff and naive enough to enter their real data for fear of getting c…

>> User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service > Exactly, regardless of that companies keep asking users for a whole collection of personal data, not always making it obvious which fields are actually required You literally don't need any user information to run an email service. You only need a means to identify them which could just amount to gi…

> You literally don't need any user information to run an email service.

I know that and you know that the average user does NOT know that and is too good-natured to enter fake information.

There are plenty of email services out there, among them many of largest and most established ones, where the real name is a required field during registration.

Sure you can always argue "Well just enter fake details" but that's missing the point. The point being that once personal information becomes a liability, instead of something you can just haphazardly hoard as an asset, companies would be much more careful about what kind of information they are asking from the users in the very first place.

Companies abuse the goodwill of the average users by asking for more information than they should because it comes at no cost to them while at the same time being a very big asset. Even if they fail to secure these assets and a breach happens, most of the costs of that are externalized onto the users whose data actually got leaked, the consequences for the company are often only cosmetical, some bad PR/stock prices take a little downturn. But the brunt of that will be over after a couple of weeks and after that, it's back to business as usual.

That needs to change, companies need to be held liable for:

A) Needlessly asking for and hoarding personal information B) Sloppy treatment of information resulting in a leak

Yes, this could very well be opening Pandora's box, but something about the current state of things really needs to change.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#242

> A massive data breach at Yahoo in 2013 was far more extensive than previously disclosed, affecting all of its 3 billion user accounts, new parent company Verizon Communications Inc. said on Tuesday. Imagine the buyers remorse

No remorse, VZ got a discount on the purchase price based on this issue.

So the article (and Verizon?) is lying that new evidence has come to light - Verizon and v Yahoo knew when they negotiated the sale?

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#243
post #95
post #75

Earlier quoted context omitted.

Using the black market as a standard, your identity-related information isn't worth enough to be taxable.[0][1][2] The more common data you give away is worth even less. Your "gift" is akin to giving away a few grains of sand to a glassmaker who provides a free grain counting service. Now let's say you dumped a lot sand that we could value at $10K. Any smart sand-counting glassmaker will claim his once "free" sand co…

Value is derived from user data when its used to target ads. Black market data is never used for that purpose, so its value is much lower. (A company would never take the risk of using black market data)

You (and every other responder) miss larger the point of my comment. Let's use Google as an example. Your clicks throughout the internet, like sand, don't amount to much of value. It's a very unrefined, raw material, with limited quantity. Even if Google were forced to value that raw material, they can argue they're trading it in equal exchange for whatever service they offer you, so there would still be no tax.

In any situation, potentially derived value is not taxable. A car is worth whatever a car was bought/sold for, not including some hypothetical such as whatever I could make by driving it for Uber/Lyft. What matter's here is what will actually occur in the transaction. If Equifax chooses to sell its data, that income will be taxed at whatever price Equifax chooses to sell the data.

Note this doesn't change that your "gift" of peanuts of data is not taxable because (a) your data alone isn't worth squat, (b) even if it was, you got something in exchange for it.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#244

Earlier quoted context omitted.

With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header. I’m sure spammers have already figured that out.

What standard is foo+bar@test.com a part of?

It was already a known trick to identify sources of spam when I was student (1990-1993).

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#245
post #169

Earlier quoted context omitted.

You can still show the ads and there are a lot of other signals and context to use. Also other than Facebook or google with strong identity, 3rd party data on the open web is next to useless. If you’re paying $40cpm for data, you’re getting ripped off.

Sorry to be that guy, but: I spend over $5m a year on rtb ads. I literally spend 50 hours a week doing this. If the money I spend doesn't produce verifiable results, I lose it. For example, that 40cpm is to reach a pool of <1000 users who are in charge of purchasing for networks of hospitals, and my ads are for MRI machines. 3rd party data is unbelievably valuable, probably $1.5 million of my budget goes to data cost…

That doesn't add up. I've managed budgets a magnitude higher, know the founders of every major SSP and DMP, and now specialize in B2B marketing for F1000 companies with long sales cycles. If you're really trying to reach a pool that small, open web advertising is incredibly inefficient.

This is well understood by the adtech community and even the flashy new "ABM" companies will tell you the same. 3rd party data is universally terrible. At best, it'll work at scale (of millions) on general demographic details but will definitely not recognize 1000 people on the open web.

That kind of list might work on Linkedin or Facebook with email targeting but it would be easier to focus on niche trade sites without any data, or just use a direct sales team. That $1.5M in data you're paying for would have much better ROI with a good VP of sales.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#246
post #144

Earlier quoted context omitted.

Value is derived from the potential application of data. Ads as an application isn't worth much since you can still be shown ads just fine without any personal data targeting. Black market data is worth way more because it's often more personal than just demographic markers and interests, and can potentially lead to large sums of money.

Well no that's incorrect. A targeted ad is worth significantly more than one without targeting. I buy ads at a $0.25 cpm and a $40 cpm, the only difference is targeting data.

It still holds the data alone isn't worth much. If you've built an ad platform with customers, reach, and the ability to target people given data, then sure, you can convert that raw material into something more valuable. And once you sell the derived product (ads), you'll be taxed on your income.

I feel like you're arguing that dirt is worth as much as the farm that one could build with it.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#247

Earlier quoted context omitted.

Sure, but you don't need first name, last name, phone number, birth date or gender. All of which are asked on the signup and of which only Gender is specified as optional: https://login.yahoo.com/account/create On my small business we ask only for an email address, password and confirm password. Everything else is excessive. Tax obligations can be another problem which may require an address, but often have a simpler…

First and last name at least needed for meet the email protocol. Emails shouldn't be addressed to handles/nicknames

The irony of that comment being made from an account with a username that doesn't clearly identify a person..

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#248
post #183

Earlier quoted context omitted.

Wouldn't the emails themselves count as user information?

No. User information here means information denoting a user not information from a user.

That's dangerous schematic games along the same lines of "Metadata is harmless and can't identify anybody".

Emails can sometimes contain very detailed and very denoting user information. Trying to differentiate between users "personal information" and users "personal content" is imho a rather dangerous thing to do because who decides where to draw the lines between the two?

As a user, I expect my data, regardless of which data, to stay private unless I explicitly intent to publish it to the public or somebody else. I most certainly do not expect some employees reading through my private emails for their lunch-break entertainment.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#249
post #207

Earlier quoted context omitted.

Might be better off spending £5k+ on personal gifts for each decision maker than bothering with Web advertising if it's that few people you're targeting :-)

I may not be a lawyer, but gifts of $5k to induce someone to purchase a thing for their workplace feels like it should count as corruption and bribery. If someone tried to do that to me, I’d report the attempt to the company lawyer, and I’d doubt the quality of the thing they were selling was as good as the quality of the thing the other poster was advertising.

Oh my God. Seriously? You'd report them? Snitches get stitches. Jam up one of my guys, you'll wish you hadn't. If he's starting with 5k you could easily get a lot more. That is the price for suckers. Course you don't have to take anything but that could be hazardous to yous health. I'm just saying. Take the fucking gift.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#250
post #207

Earlier quoted context omitted.

I may not be a lawyer, but gifts of $5k to induce someone to purchase a thing for their workplace feels like it should count as corruption and bribery. If someone tried to do that to me, I’d report the attempt to the company lawyer, and I’d doubt the quality of the thing they were selling was as good as the quality of the thing the other poster was advertising.

5k+ per person would be bribery. I hope he meant 5k in total..., 1000 gifts of 5$ would be ok

I'm sure he meant what he said. Do the math. He was trying to point out that it would cost the same either way. But if you give the mark the money, it would have a much greater effect than 5k on silly web adds.
Post reply on HN