Earlier quoted context omitted.
You can still show the ads and there are a lot of other signals and context to use. Also other than Facebook or google with strong identity, 3rd party data on the open web is next to useless. If you’re paying $40cpm for data, you’re getting ripped off.
Sorry to be that guy, but: I spend over $5m a year on rtb ads. I literally spend 50 hours a week doing this. If the money I spend doesn't produce verifiable results, I lose it. For example, that 40cpm is to reach a pool of <1000 users who are in charge of purchasing for networks of hospitals, and my ads are for MRI machines. 3rd party data is unbelievably valuable, probably $1.5 million of my budget goes to data cost…
Yahoo Triples Estimate of Breached Accounts to 3B
301–310 of 311 posts
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#302Earlier quoted context omitted.
Sales tax isn't paid on trades. When you trade in a car for $2k off a $10k car, you only pay taxes on the difference: $8k. And if you grow oranges on your property that you never sell, you never pay taxes on those oranges.
Not in California. If you accept a trade-in on the sale of a vehicle, the allowance for the trade-in cannot be excluded from the amount on which tax is based. For example, if you sell a car for $20,000 and accept a trade-in valued at $4,000 as partial payment, tax is based on the $20,000 selling price. Source: http://www.boe.ca.gov/pdf/pub34.pdf
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#303Earlier quoted context omitted.
Using the black market as a standard, your identity-related information isn't worth enough to be taxable.[0][1][2] The more common data you give away is worth even less. Your "gift" is akin to giving away a few grains of sand to a glassmaker who provides a free grain counting service. Now let's say you dumped a lot sand that we could value at $10K. Any smart sand-counting glassmaker will claim his once "free" sand co…
Value is derived from user data when its used to target ads. Black market data is never used for that purpose, so its value is much lower. (A company would never take the risk of using black market data)
I bet LinkedIn does.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#304Earlier quoted context omitted.
You (and every other responder) miss larger the point of my comment. Let's use Google as an example. Your clicks throughout the internet, like sand, don't amount to much of value. It's a very unrefined, raw material, with limited quantity. Even if Google were forced to value that raw material, they can argue they're trading it in equal exchange for whatever service they offer you, so there would still be no tax. In a…
I'll go one step further in saying the discussion framed around clicks being interpreted as a product is incorrect altogether. I think user metadata is part of a users identity and the friction we run up against is whether it ought to be legally protected. It's currently not illegal to sit outside a restaurant and records information about all of its patrons. You'd certainly be in hot water if you tried to do that at…
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#305Earlier quoted context omitted.
+1. I did the same. At the time I had to do this (around 2015), Yahoo was the least concerned about identifying duplicate accounts. I was testing for an actual paying job, not some side interest investigation, mind you. Some of the services I had to test were clever enough to reject fakeinbox accounts so I used Yahoo.
> I was testing for an actual paying job, not some side interest investigation What difference would it make? Do you mean to imply that creating test accounts is a little bit "wrong", and would be wrong for an individual to do at home, but it's OK to do it if someone else is paying you for it? If so, I disagree on both counts: it's not wrong to create test accounts, but if it was, it would still be wrong even if some…
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#306Earlier quoted context omitted.
With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header.
I’ve run a fair amount of email campaigns where we strip out the + if gmail is the domain to ensure it doesn’t end up in some weird filter. Dick move, I know. Tell marketing that though. I personally use gmail through a vanity domain and have a catch all rule, so I end up signing up with a fake email account for every domain (hn@mydomain.com) and then the catch all forwards it to my real account (me@mydomain.com).
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#307Earlier quoted context omitted.
This is how the civil legal system is supposed to function. There needs to be some very large class action lawsuits brought against these companies, and huge awards need to be extracted in order increase the financial risk of having shitty infosec.
For PCI Compliance purposes, at least, holding user credit card information is already seen as a liability because maintaining compliance is a cost center. That's why there's been some shift towards tokenizing transactions on the fly and directly submitting to the CC company via javascript so that shopping websites never see your CC number even when you enter it on their website - even if you're scheduling future pay…
Other impacts may not have direct monetary damages, but could be even more devastating (ie Ashley Madison).
Until the courts start clamping down on negligent handling of personal data, firms will continue to cheap out on infosec.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#308Earlier quoted context omitted.
I don't understand. You believe you have the right to have no records of yourself written anywhere. You believe it is impossible to contract away this right. You've given HN an individual identifier for yourself, and also furnished your political views (a specially protected category under the GDPR) to its database. Aren't all your comments proof of Y Combinator's human rights violation against you? Shall we have HN…
Guessing you don't support the right to be forgotten.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#309Earlier quoted context omitted.
Nobody ever said they are active users or unique individuals. I know for example I personally created hundreds of accounts on Yahoo! over the years.
I worked with someone at yahoo that had a name very similar to your handle. He'd have reason to create 100s of accounts.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#310Earlier quoted context omitted.
My memory of implementing COPPA compliance a decade ago was that DOB was an implicit requirement, the explicit requirement being “confirm they’re over 13; a checkbox isn’t good enough because they’ll clearly just lie.” (paraphrased, not quoted).
Does that mean you have to retain it beyond the initial check?