Live data from Hacker News

Yahoo Hacked

webcache.googleusercontent.com

31–40 of 258 posts

Re: Yahoo Hacked

#31
post #23

This guy works in the security industry and yet he couldn't google "yahoo security" to find their security contact email address (second result for me)? He was also unaware that Yahoo runs a Bug Bounty Program?

Well.. you didn't read the first couple lines? Notably: > I’ve notified both Yahoo! and the FBI New Orleans field office of the infiltration, but in my eyes, they really aren’t seeing the severity and danger of this situation, and really are not reacting quick enough. > This document is being released due to several high profile companies being infiltrated using the recent Shellshock vulnerability, and what I have de…

Looks like you only read the first couple lines. What I'm referring to:

> I’ve also emailed Marissa Mayer and contacted her via twitter, both of which yielded zero results and no response. There are no publicly available contact methods for Yahoo! that have yielded any luck with trying to contact them regarding this.

Re: Yahoo Hacked

#32
post #27

This guy works in the security industry and yet he couldn't google "yahoo security" to find their security contact email address (second result for me)? He was also unaware that Yahoo runs a Bug Bounty Program?

According to this[1] article about the current issue: "Before releasing this information, Hall emailed Yahoo and tweeted at its engineering team and CEO Marissa Mayer. It was confirmed to him that its servers had been infiltrated but Yahoo refused to pay him for alerting them as it was not part of the company’s bug bounty programme." [1]: http://www.independent.co.uk/life-style/gadgets-and-tech/new... EDIT: The quote…

Please read the follow up:

http://yahoodevelopers.tumblr.com/post/62953984019/so-im-the...

(and HN discussion: https://news.ycombinator.com/item?id=6488897)

Re: Yahoo Hacked

#33

Am I the only one that thinks this kind of thing would be cool to see? I've seen logs of attacks, but I've never watched a botnet irc live. that would be crazy for me. Not really moving the conversation forward, but is this so commonplace that I'm the odd man for marveling?

To be honest, it's not that interesting. If it's a well configured irc host then you will not be seeing any of the other bots, and all you will occasionally see is a command coming by from a generically named operator. Some botnet irc's are lazily configured, and will let you see all of the other bots as part of the channel, but generally will not let you speak. The bots usually have nicknames built from the host's computer name, username, country, etc.

It's interesting, but in itself is not that exciting in my opinion.

Re: Yahoo Hacked

#34
post #23

Earlier quoted context omitted.

Well.. you didn't read the first couple lines? Notably: > I’ve notified both Yahoo! and the FBI New Orleans field office of the infiltration, but in my eyes, they really aren’t seeing the severity and danger of this situation, and really are not reacting quick enough. > This document is being released due to several high profile companies being infiltrated using the recent Shellshock vulnerability, and what I have de…

Looks like you only read the first couple lines. What I'm referring to: > I’ve also emailed Marissa Mayer and contacted her via twitter, both of which yielded zero results and no response. There are no publicly available contact methods for Yahoo! that have yielded any luck with trying to contact them regarding this.

I think the "that have yielded any luck" part of that quote is pretty important.

Re: Yahoo Hacked

#35
post #27

This guy works in the security industry and yet he couldn't google "yahoo security" to find their security contact email address (second result for me)? He was also unaware that Yahoo runs a Bug Bounty Program?

According to this[1] article about the current issue: "Before releasing this information, Hall emailed Yahoo and tweeted at its engineering team and CEO Marissa Mayer. It was confirmed to him that its servers had been infiltrated but Yahoo refused to pay him for alerting them as it was not part of the company’s bug bounty programme." [1]: http://www.independent.co.uk/life-style/gadgets-and-tech/new... EDIT: The quote…

They keep insulting bounty hunters like that, they'll end up on the wrong side of black market bug trades every time some new exploit comes up. And I won't be defending Yahoo when that happens.

Re: Yahoo Hacked

#36
post #3

This is a courageous disclosure since the OP risks to be in some trouble for his "ethical probing".

In the winzip email, he rambles about his mother.

Which makes his signature line pretty interesting. :)

> A fool learns only from himself. A wise man will learn from the fool.

So he's got this 'honest fool' thing going for him. If he can marry that with meticulous record keeping, maybe he'll be OK.

Of course, IANAL.

But ffs, I'm sick of this world where the defense "Wait, you misunderstand--I'm the GOOD guy!" isn't good enough. Why isn't it?

Re: Yahoo Hacked

#37
post #27

This guy works in the security industry and yet he couldn't google "yahoo security" to find their security contact email address (second result for me)? He was also unaware that Yahoo runs a Bug Bounty Program?

According to this[1] article about the current issue: "Before releasing this information, Hall emailed Yahoo and tweeted at its engineering team and CEO Marissa Mayer. It was confirmed to him that its servers had been infiltrated but Yahoo refused to pay him for alerting them as it was not part of the company’s bug bounty programme." [1]: http://www.independent.co.uk/life-style/gadgets-and-tech/new... EDIT: The quote…

That article is poorly reported. Yahoo didn't have a bug bounty program at all at that time. And their response was blown totally out of proportion.

Re: Yahoo Hacked

#38
post #13

Earlier quoted context omitted.

That's not a Yahoo hack though. When that happens it is almost always your local machine that has been breached by a virus which simply reads the locally stored contact list. And to answer your question, no, it is not a regular occurrence for Yahoo, or any of the major players, to have their servers hacked.

To my knowledge, my machine is secure. It wasn't Windows and I had both anti-virus and a firewall active. For one thing, what made this strange was that I haven't even logged into Yahoo for months (probably close to a year) when this happened, repeatedly.

Could also be password guessing; lots of people use the "common word + number" pattern for their Yahoo! passwords.

Re: Yahoo Hacked

#39
post #23

Earlier quoted context omitted.

Well.. you didn't read the first couple lines? Notably: > I’ve notified both Yahoo! and the FBI New Orleans field office of the infiltration, but in my eyes, they really aren’t seeing the severity and danger of this situation, and really are not reacting quick enough. > This document is being released due to several high profile companies being infiltrated using the recent Shellshock vulnerability, and what I have de…

Looks like you only read the first couple lines. What I'm referring to: > I’ve also emailed Marissa Mayer and contacted her via twitter, both of which yielded zero results and no response. There are no publicly available contact methods for Yahoo! that have yielded any luck with trying to contact them regarding this.

> that have yielded any luck with trying to contact them regarding this

Might be the important part of the quote you missed.

Re: Yahoo Hacked

#40

Earlier quoted context omitted.

Looks like you only read the first couple lines. What I'm referring to: > I’ve also emailed Marissa Mayer and contacted her via twitter, both of which yielded zero results and no response. There are no publicly available contact methods for Yahoo! that have yielded any luck with trying to contact them regarding this.

I think the "that have yielded any luck" part of that quote is pretty important.

The point I'm making is that he didn't do the obvious thing and search for their actual security report address which they have, respond to, and pay people money who report bugs to. He found the hacked servers by doing a search but couldn't do this?
Post reply on HN