Live data from Hacker News

An Important Message About Yahoo User Security

yahoo.tumblr.com

271–280 of 356 posts

Re: An Important Message About Yahoo User Security

#271
post #107

Earlier quoted context omitted.

Investors are conflicted: on the one hand, Yahoo had a data breach that will cost them trust, but on the other hand, investors are surprised to hear there are still 500 million Yahoo users.

It's because we all keep logging in to change our passwords.

I often wonder if there really was a Linkedin breach, or if it was just to force people to remember they had a Linkedin account.

Re: An Important Message About Yahoo User Security

#272
post #107

Earlier quoted context omitted.

Investors are conflicted: on the one hand, Yahoo had a data breach that will cost them trust, but on the other hand, investors are surprised to hear there are still 500 million Yahoo users.

It's because we all keep logging in to change our passwords.

Right, I feel like my Yahoo! account has been in a perpetual state of compromise since, oh, about 2000.

Re: An Important Message About Yahoo User Security

#273
post #177

"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this. also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.

I think it has to do with the sophistication of the attack. If they used multiple zero-days, multiple pieces of custom coded software, and a team of operators working full time for long periods of time then it can be assumed it's a multi-million dollar effort involving a large team of engineers. In such a case the list of potential adversaries can be reduced to corporate or state actors.

> I think it has to do with the sophistication of the attack.

The security team probably sees thousands of attacks every day, mostly automated but probably a dozen a day targeted/custom. If one gets through the security, that is of course more sophisticated than all the other ones, plus it outsmarted the security team and developers, so you'd hardly tell your boss "we were too stupid". Instead, it came from China* so state-sponsored is a good text to write.

*Or something like that. Enough infected computers there to go around (or government cares little enough if you rent a server).

Re: An Important Message About Yahoo User Security

#275
post #137

Earlier quoted context omitted.

So covering up a known in-progress security breach is standard procedure? Instead of telling your users to change their passwords and so on? Personally, I demand criminal investigation and at least a $1000 fine per account breached.

I don't think they actually broke any laws. How do you expect them to be charged for your demands?

You got me, they only broke the law in 47 states.

http://www.ncsl.org/research/telecommunications-and-informat...

Re: An Important Message About Yahoo User Security

#276

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

Security mistakes do not make lasting impacts on stock prices in my experience. They tend to be a little hiccup, but afterwards things keep moving along on the existing trend.

A cluster of security mistakes in other companies does seem to increase the price of stocks like FEYE, CUDA & FTNT.

Re: An Important Message About Yahoo User Security

#277
Interestingly my account is not part of the compromise and my friends are; I can confirm this because they received a message about the compromise and I did not. . .I asked them how long they've had their accounts and they said for about a year; where as I have had my account for about 5 years. Interesting no?

Re: An Important Message About Yahoo User Security

#278

You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.

Two reasons:

1. this leak is old, we found out about it in August

2. Yahoo is already heavily discounted to the point where without BABA they have a negative value.

Re: An Important Message About Yahoo User Security

#280
post #168

It seems bizarre that Yahoo would use a post on tumblr.com to make such an important announcement. From what I've seen Tumblr has become mostly a wasteland of worthless garbage in the past few years and no one takes it seriously any more. Isn't this the sort of thing that ought to be on the yahoo.com home page from a PR crisis management standpoint?

Tumblr lost 65 million accounts "recently" too - maybe they're just reusing their "we've been hacked" account?
Post reply on HN