Earlier quoted context omitted.
Investors are conflicted: on the one hand, Yahoo had a data breach that will cost them trust, but on the other hand, investors are surprised to hear there are still 500 million Yahoo users.
It's because we all keep logging in to change our passwords.
An Important Message About Yahoo User Security
271–280 of 356 posts
Re: An Important Message About Yahoo User Security
#272Earlier quoted context omitted.
Investors are conflicted: on the one hand, Yahoo had a data breach that will cost them trust, but on the other hand, investors are surprised to hear there are still 500 million Yahoo users.
It's because we all keep logging in to change our passwords.
Re: An Important Message About Yahoo User Security
#273"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this. also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.
I think it has to do with the sophistication of the attack. If they used multiple zero-days, multiple pieces of custom coded software, and a team of operators working full time for long periods of time then it can be assumed it's a multi-million dollar effort involving a large team of engineers. In such a case the list of potential adversaries can be reduced to corporate or state actors.
The security team probably sees thousands of attacks every day, mostly automated but probably a dozen a day targeted/custom. If one gets through the security, that is of course more sophisticated than all the other ones, plus it outsmarted the security team and developers, so you'd hardly tell your boss "we were too stupid". Instead, it came from China* so state-sponsored is a good text to write.
*Or something like that. Enough infected computers there to go around (or government cares little enough if you rent a server).
Re: An Important Message About Yahoo User Security
#274Re: An Important Message About Yahoo User Security
#275Earlier quoted context omitted.
So covering up a known in-progress security breach is standard procedure? Instead of telling your users to change their passwords and so on? Personally, I demand criminal investigation and at least a $1000 fine per account breached.
I don't think they actually broke any laws. How do you expect them to be charged for your demands?
http://www.ncsl.org/research/telecommunications-and-informat...
Re: An Important Message About Yahoo User Security
#276You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.
A cluster of security mistakes in other companies does seem to increase the price of stocks like FEYE, CUDA & FTNT.
Re: An Important Message About Yahoo User Security
#277Re: An Important Message About Yahoo User Security
#278You'd think this would affect the stock price, but currently YHOO only trading down 8 cents (-0.18%). I honestly see this all the time. What sounds like really horrible news for a company, does not affect the price. Howerver, some random analyst or reporter who works at the Mercury Star Sun Inquirer writes a negative article or downgrade and the stock tanks. Doesn't make much sense.
1. this leak is old, we found out about it in August
2. Yahoo is already heavily discounted to the point where without BABA they have a negative value.
Re: An Important Message About Yahoo User Security
#279Re: An Important Message About Yahoo User Security
#280It seems bizarre that Yahoo would use a post on tumblr.com to make such an important announcement. From what I've seen Tumblr has become mostly a wasteland of worthless garbage in the past few years and no one takes it seriously any more. Isn't this the sort of thing that ought to be on the yahoo.com home page from a PR crisis management standpoint?