Live data from Hacker News

Yahoo Triples Estimate of Breached Accounts to 3B

wsj.com

281–290 of 311 posts

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#281
post #75
post #43

Earlier quoted context omitted.

Alternatively, if it's truly an asset, can it be taxed as an asset? If I give a company a car, that is taxed. If I give a company my data which is worth more than a car, it isn't. Is it possible that current accounting/tax law can be interpreted so that these are viewed similarly?

Using the black market as a standard, your identity-related information isn't worth enough to be taxable.[0][1][2] The more common data you give away is worth even less. Your "gift" is akin to giving away a few grains of sand to a glassmaker who provides a free grain counting service. Now let's say you dumped a lot sand that we could value at $10K. Any smart sand-counting glassmaker will claim his once "free" sand co…

I think you have it backwards...

Wouldn't black market identities be worth MORE if they weren't so easy to get?

So the more we tax / regulate it, the harder it is, the more valuable they get. Win-win for everyone.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#282
post #253
post #43

Earlier quoted context omitted.

Alternatively, if it's truly an asset, can it be taxed as an asset? If I give a company a car, that is taxed. If I give a company my data which is worth more than a car, it isn't. Is it possible that current accounting/tax law can be interpreted so that these are viewed similarly?

The problem is you aren't "giving" a company anything. The company is observing how you interact with their products. This is like saying by walking into a store you are "giving" the company your image on their security camera. It would take a very odd definition of "gift" to make that claim.

Sure there is some data companies are collecting of that form but typically it isn't Personally Identifiable Information and even when it is that isn't what people are worried about with the Yahoo breach.

Yahoo was "gifted" data. People explicitly gave them names, email addresses and passwords. That is what Yahoo failed to protect.

> The stolen information included names, email addresses, phone numbers, birthdates and security questions and answers.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#283
post #243
post #95

Earlier quoted context omitted.

Value is derived from user data when its used to target ads. Black market data is never used for that purpose, so its value is much lower. (A company would never take the risk of using black market data)

You (and every other responder) miss larger the point of my comment. Let's use Google as an example. Your clicks throughout the internet, like sand, don't amount to much of value. It's a very unrefined, raw material, with limited quantity. Even if Google were forced to value that raw material, they can argue they're trading it in equal exchange for whatever service they offer you, so there would still be no tax. In a…

I'll go one step further in saying the discussion framed around clicks being interpreted as a product is incorrect altogether. I think user metadata is part of a users identity and the friction we run up against is whether it ought to be legally protected. It's currently not illegal to sit outside a restaurant and records information about all of its patrons. You'd certainly be in hot water if you tried to do that at any federal building. At some level we know collecting that data is wrong because it can be used against us. Even the judicial branch knows this and requires the storage of user data to be encrypted by security agencies. That's not conclusive proof but evidence of our general outlook on the legality of tracking people.

If we agree in a truly free society then collecting and monetizing metadata should be illegal. If we don't mind giving up that freedom then there's nothing wrong with companies creating a profile on you and tracking you no matter where you go and what you do. But the internet has spoken and we're gladly, albeit unknowingly, giving up any right of protection. I find it worrisome to think of what society will be like in another 50 years if nothing is done to curtail the fleecing of user data.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#284
post #3

There never is a break-in where they get 1/3 or 1/2 of the accounts. It has to be nearly all or some much smaller faction. (my own presumption based on the idea nothing large does mere 2 to 3 way replication or partition)

It depends. It's possible a company could catch a breach while the data is being dumped to s3/russia/wherever and cut it off before everything is extracted. Another possibility is that only one particular system is breached, which wouldn't actually affect all users of a given company. If Facebook were hacked, it's possible that only the ad-buy system is compromised and not their entire user store, for example, thus e…

> It depends. It's possible a company could catch a breach while the data is being dumped to s3/russia/wherever and cut it off before everything is extracted.

At that point honest behavior would still assume all accounts were transferred. You don't know that data was not transferred earlier or it's also hard to estimate what part of data was sent successfully.

If data could be accessed it should be treated as compromised.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#286

Why is it that when a disaster happens numbers are gradually revised upward?

In case of hurricanes and other natural disasters most people die later due to lack of water, electricity etc.

In case of Equifax, Yahoo etc it is because they simply lied to not look as bad, but then they need to provide accurate information.

IMO if someone broke to a database it should be considered that all data was accessed and all data should be treated as compromised.

Unless break in was to a subsystem and just that subsystem then all data in it should be considered compromised.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#287
post #271

Earlier quoted context omitted.

Are you suggesting some corporations have become more powerful than our lawfully elected governments?

I’m suggesting that “data about you” is not the same as “your data” and never has been.

I honestly don't know how to distinguish between "me" and "about me".

These discussions always go full meta. Makes my head hurt.

Being a simple bear, I try to distill these paradoxes (freewill, love, death, what is art) down to something actionable. Hence my conclusion, after much thought and effort (eg securing medical records), that "I am my data, my data is me." and therefore I own it.

If privacy is the ability to control what is publicly known about yourself, the best (practical, prescriptive) way I can think to do that is via property rights.

---

I appreciate your reply. I'm going to revisit my beliefs, conclusions. Starting with the currently generally accepted definitions.

https://en.wikipedia.org/wiki/Privacy

https://en.wikipedia.org/wiki/Personal_identity

https://en.wikipedia.org/wiki/Authentication

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#288

Earlier quoted context omitted.

Sure, but you don't need first name, last name, phone number, birth date or gender. All of which are asked on the signup and of which only Gender is specified as optional: https://login.yahoo.com/account/create On my small business we ask only for an email address, password and confirm password. Everything else is excessive. Tax obligations can be another problem which may require an address, but often have a simpler…

First and last name at least needed for meet the email protocol. Emails shouldn't be addressed to handles/nicknames

How would you handle all the people with identical names? Even if you used DoB, there is a chance for a duplicate.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#289
post #182
post #160

Earlier quoted context omitted.

Indirectly, they are. Governments don't let you blow all your profits on assets that are as-good-as-cash, and then claim you didn't make any taxable profits. So if you make $X in profit and then use it to buy a tractor, then (from the government's perspective), you've just swapped $X for an asset worth $X. No change in book value, no reduction in profit, no reduction in tax liability. You are, however, allowed to tre…

> Indirectly, they are. Governments don't let you blow all your profits on assets that are as-good-as-cash, and then claim you didn't make any taxable profits. Similar experience here: In an earlier career my company reinvested all profits back into growth, only to learn that the taxman didn't care about such silly things. The IRS demanded the tax from the profits that had been reinvested and were no longer available…

That sounds like a bug. File a report and maybe a pull request. If only it were that easy.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#290
post #271

Earlier quoted context omitted.

I’m suggesting that “data about you” is not the same as “your data” and never has been.

I honestly don't know how to distinguish between "me" and "about me". These discussions always go full meta. Makes my head hurt. Being a simple bear, I try to distill these paradoxes (freewill, love, death, what is art) down to something actionable. Hence my conclusion, after much thought and effort (eg securing medical records), that "I am my data, my data is me." and therefore I own it. If privacy is the ability to…

> I honestly don't know how to distinguish between "me" and "about me".

> These discussions always go full meta. Makes my head hurt.

You go to the store to buy a carton of eggs. The store now has data about you and your purchase. If you pay with credit card, they have a record tied to your identity. If you pay with cash, they still have a record of what you bought with your eggs, and nothing stops them from scribbling your name on the copy of the receipt they keep.

You have no right to demand that the store cease possession of this data. They might use this data (in aggregate) to determine when they need to restock eggs. They might use this data (along with other purchase records) to determine that butter should be stocked next to the eggs. They might discard this data as soon as books are reconciled or they might retain this data in perpetuity. This was the case is 1920 and it's the case now. We like to talk about "big data" as if it changed the fundamentals, but all it actually changed was the scale.

Post reply on HN