Live data from Hacker News

Verizon just raised a big warning flag for Yahoo

washingtonpost.com

31–40 of 57 posts

Re: Verizon just raised a big warning flag for Yahoo

#32
post #10

While I suspect some of this is posturing for a better price, I'm certain from some past experience that Verizon is very serious about security. A lot of large enterprise take an approach my colleagues have referred to as 'rubber stamp security', that checks boxes in a compliance report while still remaining largely ineffective. For example, these companies buy tools and install them, but then never configure them pr…

this... is certainly not my experience. However, they're a large organisation so they're most likely schizophrenic.

It's certainly not a lot of people's experience. Youtuber boogie2988 (3.5m subscribers) had his accounts hacked and his channel deleted (his primary source of income) via a Verizon social engineering hack. The hack via Verizon gained the hackers access to his Twitter, YouTube/Google accounts, even his PayPal account.

Re: Verizon just raised a big warning flag for Yahoo

#33
post #10

Earlier quoted context omitted.

this... is certainly not my experience. However, they're a large organisation so they're most likely schizophrenic.

It's certainly not a lot of people's experience. Youtuber boogie2988 (3.5m subscribers) had his accounts hacked and his channel deleted (his primary source of income) via a Verizon social engineering hack. The hack via Verizon gained the hackers access to his Twitter, YouTube/Google accounts, even his PayPal account.

Here are more details about that[1]. I'm still surprised how they could have gained access to his Youtube and Twitter just by using his phone number.

[1] https://www.reddit.com/r/boogie2988/comments/4psg4x/i_was_ha...

Re: Verizon just raised a big warning flag for Yahoo

#34
post #10

Earlier quoted context omitted.

this... is certainly not my experience. However, they're a large organisation so they're most likely schizophrenic.

It's certainly not a lot of people's experience. Youtuber boogie2988 (3.5m subscribers) had his accounts hacked and his channel deleted (his primary source of income) via a Verizon social engineering hack. The hack via Verizon gained the hackers access to his Twitter, YouTube/Google accounts, even his PayPal account.

Verizon may be quite serious about protecting Verizon and its infrastructure, while still indifferent to retail subscriber account takeovers.

Re: Verizon just raised a big warning flag for Yahoo

#36

While I suspect some of this is posturing for a better price, I'm certain from some past experience that Verizon is very serious about security. A lot of large enterprise take an approach my colleagues have referred to as 'rubber stamp security', that checks boxes in a compliance report while still remaining largely ineffective. For example, these companies buy tools and install them, but then never configure them pr…

Given that not too long ago they were publicly shamed for implementing an invasive tracking system that completely undermines their customers' privacy, [1] you'll have to do a little better than "some past experience" and "from what I've seen" if you want your assertion that "Verizon is very serious about security" to be taken seriously.

[1] https://www.wired.com/2014/10/verizons-perma-cookie/amp/

Re: Verizon just raised a big warning flag for Yahoo

#37

While I suspect some of this is posturing for a better price, I'm certain from some past experience that Verizon is very serious about security. A lot of large enterprise take an approach my colleagues have referred to as 'rubber stamp security', that checks boxes in a compliance report while still remaining largely ineffective. For example, these companies buy tools and install them, but then never configure them pr…

Just don't rely on Verizon for your own 2FA security, partly because the phone system is too easy to redirect and spoof in various ways, and partly because Verizon is too easy to social-engineer.

https://medium.com/the-coinbase-blog/on-phone-numbers-and-id...

Re: Verizon just raised a big warning flag for Yahoo

#39

But Silliman made clear on Thursday that the “state-sponsored” nature of the breach would have no bearing on the analysis of materiality. “From a legal perspective,” he said, “the question . . . ‘is it a state-sponsored attack?’ isn't really relevant in terms of what we're looking at. The question is whether this [had] a material or an adverse effect on the asset we are buying.” One can see why he didn't want to call…

It really doesn't matter what Verizon believes about who did the breach. Say you want to buy my car, but then it gets destroyed, and I say Superman did it. Whether you believe me or not, it doesn't matter, you still won't buy a destroyed car.

This is somewhat different from Yahoo users' perspective: in their case, as well, the point is not if the breach was state-sponsored, the point is: did it take mass destruction weapons and hundreds of spies coordinated for months, or did it take five minutes and a hairpin?

Re: Verizon just raised a big warning flag for Yahoo

#40
post #36

While I suspect some of this is posturing for a better price, I'm certain from some past experience that Verizon is very serious about security. A lot of large enterprise take an approach my colleagues have referred to as 'rubber stamp security', that checks boxes in a compliance report while still remaining largely ineffective. For example, these companies buy tools and install them, but then never configure them pr…

Given that not too long ago they were publicly shamed for implementing an invasive tracking system that completely undermines their customers' privacy, [1] you'll have to do a little better than "some past experience" and "from what I've seen" if you want your assertion that "Verizon is very serious about security" to be taken seriously. [1] https://www.wired.com/2014/10/verizons-perma-cookie/amp/

One has nothing to do with the other

You can be VERY good at systems security, while simultaneously wanting to violate your customers privacy....

Post reply on HN