Earlier quoted context omitted.
If that's the case, I think the bigger news then is that yahoo actually had 3B users!
Nobody ever said they are active users or unique individuals. I know for example I personally created hundreds of accounts on Yahoo! over the years.
Yahoo Triples Estimate of Breached Accounts to 3B
41–50 of 311 posts
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#42Earlier quoted context omitted.
Nobody ever said they are active users or unique individuals. I know for example I personally created hundreds of accounts on Yahoo! over the years.
Hundreds? Are you sure?
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#43I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.
Is it possible that current accounting/tax law can be interpreted so that these are viewed similarly?
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#44Earlier quoted context omitted.
Hundreds? Are you sure?
I know a guy who uses a service that creates a unique email account for every service he signs up for. That way, he tells me, if he ever gets any spam, he can delete the account and it doesn't affect any of his other email accounts.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#45Their MFA is still SMS-based, which I’m pretty sure is a bad thing. They don’t allow an app like Duo (although they do reject VOIP numbers which I guess is good).
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#46There never is a break-in where they get 1/3 or 1/2 of the accounts. It has to be nearly all or some much smaller faction. (my own presumption based on the idea nothing large does mere 2 to 3 way replication or partition)
It depends. It's possible a company could catch a breach while the data is being dumped to s3/russia/wherever and cut it off before everything is extracted. Another possibility is that only one particular system is breached, which wouldn't actually affect all users of a given company. If Facebook were hacked, it's possible that only the ad-buy system is compromised and not their entire user store, for example, thus e…
And a third possibility, especially given today's trend to distributed systems, is that the attacker gains access to one shard (or its dump) only.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#47I feel a little sad that pay-walled articles make it to the top of HN. I'm sure the article is interesting, but a lot of us can't actually read it.
Here's a bookmarklet I use sometimes: javascript:window.location.href='https://m.facebook.com/l.php?u='+encodeURIComponent(window.location.href);
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#48Earlier quoted context omitted.
Hundreds? Are you sure?
I know a guy who uses a service that creates a unique email account for every service he signs up for. That way, he tells me, if he ever gets any spam, he can delete the account and it doesn't affect any of his other email accounts.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#49Earlier quoted context omitted.
Nobody ever said they are active users or unique individuals. I know for example I personally created hundreds of accounts on Yahoo! over the years.
Hundreds? Are you sure?
I’m sure spammers have already figured that out.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#50Earlier quoted context omitted.
I know a guy who uses a service that creates a unique email account for every service he signs up for. That way, he tells me, if he ever gets any spam, he can delete the account and it doesn't affect any of his other email accounts.
With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header.