Earlier quoted context omitted.
I don't think they actually broke any laws. How do you expect them to be charged for your demands?
You got me, they only broke the law in 47 states. http://www.ncsl.org/research/telecommunications-and-informat...
An Important Message About Yahoo User Security
291–300 of 356 posts
Re: An Important Message About Yahoo User Security
#292Re: An Important Message About Yahoo User Security
#293"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this. also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.
At the moment the standard for incident disclosure is "eventually disclose the leak to users", which some companies, like Yahoo in this case, really stretch.
I'd like to see the standard become engaging an outside firm and have them release as much information as possible so that the techniques used, information stolen, potential attribution etc. can be reviewed and benefit everybody.
The statement so far from Yahoo benefit only Yahoo (specifically Yahoo management)
The stolen Yahoo accounts were listed on a DNM market a few months ago. That is how we found out about it (I suspect that is also how Yahoo found out about it). That is one of the only data points we have on the outside and it points away from the attack being state-sponsored.
[0] Some would argue that the research / attribution firms are only a little less conflicted since they sell products that aim to prevent the same state-sponsored attack.
Re: An Important Message About Yahoo User Security
#294Earlier quoted context omitted.
Yahoo's been authenticating me nearly every time I try to access the fantasy app on my phone. They've made me change my password 3 times in the past month or so. And the password I set doesn't seem to work, so I keep having to use their phone based authentication. With all the money that they have, it's hard to fathom how Yahoo is so bad at delivering secure identity services.
I started using their "Account Key" process, any time I log in on the site from a computer, I get a notification from my Yahoo sports app (iPhone) asking me if I would like to allow the login attempt. I actually like it better than the two-factor auth I use for other accounts. Whether it's more secure or not, I don't know.. EDIT: just for clarification, this replaces the password entirely. So I never enter a password…
Fortunately iCloud Keychain means my current Y! password is random as hell and not reused anywhere, but I'm slightly nervous wondering what the hell password I had in 2014 or 2012 or whenever this stupid leak happened. :/
Re: An Important Message About Yahoo User Security
#295Earlier quoted context omitted.
Investors are conflicted: on the one hand, Yahoo had a data breach that will cost them trust, but on the other hand, investors are surprised to hear there are still 500 million Yahoo users.
I don't think investors are quite that stupid. First that was 500m users in 2014 , not today. It also doesn't say active so it's likely some subset of a total. I wouldn't be surprised if Yahoo had even more than 500m accounts in 2014 and today but I would be SHOCKED if they had nearly that many active users.
Re: An Important Message About Yahoo User Security
#296Wait, Yahoo believes the data was stolen by a "state-sponsored actor"! If they have such evidence, why don't they explain so? To me it looks like a tactic to put the focus on the "noughty" government instead of themselves. Anyway, it will be an interesting read (if ever written) how Yahoo discovered they had been stolen and by who (what state?). Also, if "the state" is finally behind this, who will they prosecute til…
a) Big US enterprises are under attack from state-sponsored actors on a daily basis, so it's not that weird. It's not like the NSA weren't caught with their hands in the cookie jar either. b) If you name the state you think is behind it, you better be ready for the diplomatic repercussions between the US government and the rogue state, as well as potentially stopping doing business in that state (see Google and China…
http://www.rollingstone.com/feature/the-geeks-on-the-frontli...
http://www.vanityfair.com/news/2013/07/new-cyberwar-victims-...
https://www.technologyreview.com/s/507971/welcome-to-the-mal...
http://www.nytimes.com/2013/01/31/technology/chinese-hackers...
http://www.vanityfair.com/news/2011/09/chinese-hacking-20110...
http://www.bloomberg.com/news/articles/2011-07-20/cyber-weap...
http://fortune.com/sony-hack-part-1/
http://fortune.com/sony-hack-part-two/
http://fortune.com/sony-hack-final-part/
http://www.theverge.com/2015/1/21/7861645/finfisher-spyware-...
http://www.bloomberg.com/news/articles/2014-03-13/target-mis...
http://foreignpolicy.com/2013/11/19/stuxnets-secret-twin/
http://www.cbsnews.com/news/60-minutes-great-brain-robbery-c...
http://www.wsj.com/articles/u-s-steel-accuses-china-of-hacki...
http://www.vanityfair.com/news/2011/09/chinese-hacking-20110...
http://www.vanityfair.com/news/2011/09/operation-shady-rat-2...
Re: An Important Message About Yahoo User Security
#297Moving email addresses out from one provider and creating another one is more difficult than moving phone numbers (in the latter case, number portability could help, if available). What exactly can an average/common end user do for such incidents, even if it is to avoid them in the future? I use different passwords across accounts, with all of them being somewhat complex or very complex. I have looked at a few differ…
Moving to a new email address (and taking all your existing mails with you to the new inbox) is actually far easier than changing phone numbers. Almost all (old) providers let you set up a mail forwarding (to the new provider). But even better, several services let you set up some fetchmail-like program where it imports all the messages from the old provider, e.g. via POP3 or IMAP, and even deletes them with the old…
I went for Mailbox.org, you get 25 GB for email AND 25 GB for documents, all for €4.50/month, about $60 per year. You also get calendar/contacts/tasks with web based apps for all of the above, plus word processor and spreadsheet. They support open standards (CardDav/CalDav/WebDav) so you can choose among several clients on any platform, and they seem to have a good track record with regards to privacy.
This, however, is offset by the fact that my "quality newspaper" subscription is about AUD $350/year, LOL
Disclaimer: I am not associated with Mailbox.org in any way, just a happy customer (at least for now!).
Re: An Important Message About Yahoo User Security
#298Earlier quoted context omitted.
a) Big US enterprises are under attack from state-sponsored actors on a daily basis, so it's not that weird. It's not like the NSA weren't caught with their hands in the cookie jar either. b) If you name the state you think is behind it, you better be ready for the diplomatic repercussions between the US government and the rogue state, as well as potentially stopping doing business in that state (see Google and China…
a) Can you point to an article were I can learn more about examples of big US corps being attacked by US sponsored actors? It's a quite interesting topic indeed.
https://www.washingtonpost.com/world/national-security/nsa-i...
We can assume that the US government is not the state-sponsored actor in the OP, because their attack has already been publicly known for some time. This one is probably China or Russia.
Re: An Important Message About Yahoo User Security
#299Re: An Important Message About Yahoo User Security
#300Earlier quoted context omitted.
I often wonder if there really was a Linkedin breach, or if it was just to force people to remember they had a Linkedin account.
Reminded me to delete my LinkedIn account...
LinkedIn is like dallisgrass. pesky stuff to get rid of.