Live data from Hacker News

An Important Message About Yahoo User Security

yahoo.tumblr.com

291–300 of 356 posts

Re: An Important Message About Yahoo User Security

#291
post #275

Earlier quoted context omitted.

I don't think they actually broke any laws. How do you expect them to be charged for your demands?

You got me, they only broke the law in 47 states. http://www.ncsl.org/research/telecommunications-and-informat...

The California law, for example, just says it needs to be "expedient" without defining time limits. It isn't clear that they violated that law at all. They are disclosing a very large breach and I would assume that if they do see suits here, they will be civil suits.

Re: An Important Message About Yahoo User Security

#292

Earlier quoted context omitted.

It's because we all keep logging in to change our passwords.

I often wonder if there really was a Linkedin breach, or if it was just to force people to remember they had a Linkedin account.

No such thing as bad publicity?

Re: An Important Message About Yahoo User Security

#293

"state sponsored actor". I wonder how they decided that. did the hackers plant a flag inside yahoo's data center? or is any attack originating from outside US now considered state sponsored? of course, we will never see any proof of this. also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.

Yahoo shouldn't be doing the attribution, it's a conflict of interest[0].

At the moment the standard for incident disclosure is "eventually disclose the leak to users", which some companies, like Yahoo in this case, really stretch.

I'd like to see the standard become engaging an outside firm and have them release as much information as possible so that the techniques used, information stolen, potential attribution etc. can be reviewed and benefit everybody.

The statement so far from Yahoo benefit only Yahoo (specifically Yahoo management)

The stolen Yahoo accounts were listed on a DNM market a few months ago. That is how we found out about it (I suspect that is also how Yahoo found out about it). That is one of the only data points we have on the outside and it points away from the attack being state-sponsored.

[0] Some would argue that the research / attribution firms are only a little less conflicted since they sell products that aim to prevent the same state-sponsored attack.

Re: An Important Message About Yahoo User Security

#294
post #231

Earlier quoted context omitted.

Yahoo's been authenticating me nearly every time I try to access the fantasy app on my phone. They've made me change my password 3 times in the past month or so. And the password I set doesn't seem to work, so I keep having to use their phone based authentication. With all the money that they have, it's hard to fathom how Yahoo is so bad at delivering secure identity services.

I started using their "Account Key" process, any time I log in on the site from a computer, I get a notification from my Yahoo sports app (iPhone) asking me if I would like to allow the login attempt. I actually like it better than the two-factor auth I use for other accounts. Whether it's more secure or not, I don't know.. EDIT: just for clarification, this replaces the password entirely. So I never enter a password…

Can you help me understand how it replaces the password entirely? What if I lost my phone, or just deleted their app? Does it basically fall back to letting you click a link in your email to approve logging in? Or, SMS, or...? I've been skeptical of it.

Fortunately iCloud Keychain means my current Y! password is random as hell and not reused anywhere, but I'm slightly nervous wondering what the hell password I had in 2014 or 2012 or whenever this stupid leak happened. :/

Re: An Important Message About Yahoo User Security

#295
post #107

Earlier quoted context omitted.

Investors are conflicted: on the one hand, Yahoo had a data breach that will cost them trust, but on the other hand, investors are surprised to hear there are still 500 million Yahoo users.

I don't think investors are quite that stupid. First that was 500m users in 2014 , not today. It also doesn't say active so it's likely some subset of a total. I wouldn't be surprised if Yahoo had even more than 500m accounts in 2014 and today but I would be SHOCKED if they had nearly that many active users.

Entirely likely it's not 500m, for sure, but i would not be surprised if it's still in the hundred million active email accounts. Lot of elderly folks who got hooked on a yahoo email account, and just won't give it up. I can say based on consumers emails I've seen in some of the systems I've managed, yahoo still clocks in as a pretty solid 15-20% of email addresses of active users, which isn't a small figure (gmail is of course higher, and major isp's round the bases).

Re: An Important Message About Yahoo User Security

#296
post #120

Wait, Yahoo believes the data was stolen by a "state-sponsored actor"! If they have such evidence, why don't they explain so? To me it looks like a tactic to put the focus on the "noughty" government instead of themselves. Anyway, it will be an interesting read (if ever written) how Yahoo discovered they had been stolen and by who (what state?). Also, if "the state" is finally behind this, who will they prosecute til…

a) Big US enterprises are under attack from state-sponsored actors on a daily basis, so it's not that weird. It's not like the NSA weren't caught with their hands in the cookie jar either. b) If you name the state you think is behind it, you better be ready for the diplomatic repercussions between the US government and the rogue state, as well as potentially stopping doing business in that state (see Google and China…

Here is my bookmarks folder for corporate hacks:

http://www.rollingstone.com/feature/the-geeks-on-the-frontli...

http://www.vanityfair.com/news/2013/07/new-cyberwar-victims-...

https://www.technologyreview.com/s/507971/welcome-to-the-mal...

http://www.nytimes.com/2013/01/31/technology/chinese-hackers...

http://www.vanityfair.com/news/2011/09/chinese-hacking-20110...

http://www.bloomberg.com/news/articles/2011-07-20/cyber-weap...

http://fortune.com/sony-hack-part-1/

http://fortune.com/sony-hack-part-two/

http://fortune.com/sony-hack-final-part/

http://www.theverge.com/2015/1/21/7861645/finfisher-spyware-...

http://www.bloomberg.com/news/articles/2014-03-13/target-mis...

http://foreignpolicy.com/2013/11/19/stuxnets-secret-twin/

http://www.cbsnews.com/news/60-minutes-great-brain-robbery-c...

http://www.wsj.com/articles/u-s-steel-accuses-china-of-hacki...

http://www.vanityfair.com/news/2011/09/chinese-hacking-20110...

http://www.vanityfair.com/news/2011/09/operation-shady-rat-2...

Re: An Important Message About Yahoo User Security

#297
post #18

Moving email addresses out from one provider and creating another one is more difficult than moving phone numbers (in the latter case, number portability could help, if available). What exactly can an average/common end user do for such incidents, even if it is to avoid them in the future? I use different passwords across accounts, with all of them being somewhat complex or very complex. I have looked at a few differ…

Moving to a new email address (and taking all your existing mails with you to the new inbox) is actually far easier than changing phone numbers. Almost all (old) providers let you set up a mail forwarding (to the new provider). But even better, several services let you set up some fetchmail-like program where it imports all the messages from the old provider, e.g. via POP3 or IMAP, and even deletes them with the old…

> [...] pay 99 USD/year for Dropbox, 50 USD/year for Fastmail (because you want your own domain), 10 USD/year for the actual domain (separately), 100 USD/year for my quality newspaper subscription, etc.

I went for Mailbox.org, you get 25 GB for email AND 25 GB for documents, all for €4.50/month, about $60 per year. You also get calendar/contacts/tasks with web based apps for all of the above, plus word processor and spreadsheet. They support open standards (CardDav/CalDav/WebDav) so you can choose among several clients on any platform, and they seem to have a good track record with regards to privacy.

This, however, is offset by the fact that my "quality newspaper" subscription is about AUD $350/year, LOL

Disclaimer: I am not associated with Mailbox.org in any way, just a happy customer (at least for now!).

Re: An Important Message About Yahoo User Security

#298
post #184

Earlier quoted context omitted.

a) Big US enterprises are under attack from state-sponsored actors on a daily basis, so it's not that weird. It's not like the NSA weren't caught with their hands in the cookie jar either. b) If you name the state you think is behind it, you better be ready for the diplomatic repercussions between the US government and the rogue state, as well as potentially stopping doing business in that state (see Google and China…

a) Can you point to an article were I can learn more about examples of big US corps being attacked by US sponsored actors? It's a quite interesting topic indeed.

NSA infiltrates links to Yahoo, Google data centers worldwide, Snowden documents say

https://www.washingtonpost.com/world/national-security/nsa-i...

We can assume that the US government is not the state-sponsored actor in the OP, because their attack has already been publicly known for some time. This one is probably China or Russia.

Re: An Important Message About Yahoo User Security

#299

Earlier quoted context omitted.

It's because we all keep logging in to change our passwords.

I often wonder if there really was a Linkedin breach, or if it was just to force people to remember they had a Linkedin account.

Reminded me to delete my LinkedIn account...

Re: An Important Message About Yahoo User Security

#300
post #299

Earlier quoted context omitted.

I often wonder if there really was a Linkedin breach, or if it was just to force people to remember they had a Linkedin account.

Reminded me to delete my LinkedIn account...

Is that even possible? I got a password reset email for a LinkedIn account that I thought I had deleted years ago. I know that sometimes logging in can reactivate an account, but it's been YEARS now. And it was like I was always there.

LinkedIn is like dallisgrass. pesky stuff to get rid of.

Post reply on HN