Live data from Hacker News

Engineer admits hacking Yahoo accounts searching for images

ktvu.com

71–80 of 99 posts

Re: Engineer admits hacking Yahoo accounts searching for images

#71
post #52
post #36

Earlier quoted context omitted.

Honestly I'd like to see one of the webmail providers do a decent attempt at gpg. The web migrated from a primarily unencrypted state to an encrypted one - it's not impossible with the right UX.

The web is encrypted in transit but most data is probably stored in an unencrypted form, much like email.

The web is _partly_ encrypted in transit. To the point where it hits the closest cloudflare (or other edge) server. From then on it's often unencrypted the rest of the way to the real webserver.

Yes, it would be possible to encrypt email too but it would involve changing every email client and server there is, and there are quite a few of them. And a public key repository for everyone to be able to find the correct key for each receiving adress. Mailing list servers and other group mail would be particularly fun to solve.

Re: Engineer admits hacking Yahoo accounts searching for images

#72

Earlier quoted context omitted.

Encryption, in email? lol... This is what happens when end-to-end encryption isn't the default in communications software. All email providers are vulnerable to this bar none.

Not sure why I'm getting downvoted. Prove me wrong.

I don't see how this could happen at Tutanota

Re: Engineer admits hacking Yahoo accounts searching for images

#73
post #36

Earlier quoted context omitted.

Encryption, in email? lol... This is what happens when end-to-end encryption isn't the default in communications software. All email providers are vulnerable to this bar none.

Honestly I'd like to see one of the webmail providers do a decent attempt at gpg. The web migrated from a primarily unencrypted state to an encrypted one - it's not impossible with the right UX.

flowcrypt for gmail is quite good. https://flowcrypt.com/

Re: Engineer admits hacking Yahoo accounts searching for images

#74

End-to-end encryption is the only foolproof was of preventing this. But if that is not possible, training and audit/alerts is the next best thing. Training is important because new employees or new college grads might not be aware of truly how egregious it is to view someone's personal data. It really had to be drilled into the culture. By audits and alerts, I mean that if one employee accesses sensitive information,…

I'd actually love to have this implemented client side - i.e if an employee views accesses your info, the client gets an alert.

Yea, it'll flourish your business.

Re: Engineer admits hacking Yahoo accounts searching for images

#75
post #69

Earlier quoted context omitted.

The fall of Google finance is astounding. You can go to https://finance.google.com and search for "Slack" with no results. You can search for "WORK" (Slack's stock symbol) with no results. You have to actually type "NYSE:Work" to have it show up in the search results. It's astonishing.

Not just finance. Compare Google Street View with Apple's "look around" feature. Night and day. To be fair I haven't looked at street view recently, and Google's coverage is better for now. Or Gmail spam filtering... I can't even begin to fathom what they are thinking, whoever is in charge of that. I mean really... they have the privilege of working at Google? And... really, that's the level of effort and quality the…

With Google in particular, I feel like you can tell when a new lead takes over a product. I imagine leading a product is a career move at Google, people move on and new folks take over, diluting the original vision of simplicity, functionality and magic of early Google products.

In Google Maps on Android, the status bar is now transparent, and important information like clock, battery status, connection quality and incoming messages are now drawn on top of the map. I'm sure that looks great in a presentation but now those little icons have little, and varying contrast and are hard to decipher.

In Youtube in the browser, I have autoplay disabled. Every time I log into Youtube (after a reboot), autoplay is enabled again.

Re: Engineer admits hacking Yahoo accounts searching for images

#76

Earlier quoted context omitted.

The fact that it hasn't happened yet when there are so many Google employees suggests that it's infeasibly difficult.

It's a rare person who throws away millions of dollars of income just for the lulz.

you meant 150k?

Re: Engineer admits hacking Yahoo accounts searching for images

#77
post #71
post #52

Earlier quoted context omitted.

The web is encrypted in transit but most data is probably stored in an unencrypted form, much like email.

The web is _partly_ encrypted in transit. To the point where it hits the closest cloudflare (or other edge) server. From then on it's often unencrypted the rest of the way to the real webserver. Yes, it would be possible to encrypt email too but it would involve changing every email client and server there is, and there are quite a few of them. And a public key repository for everyone to be able to find the correct k…

Given that you mentioned CloudFlare, they actually encourage using Full SSL (Strict), which requires a valid certificate from the origin server to the edge server. You can also get them to issue an SSL cert for you if you don't want to deal with that yourself. It expires in 10 years by default, but can be revoked easily in case of key compromise.

Re: Engineer admits hacking Yahoo accounts searching for images

#78

I truly don't understand how Yahoo still exists. How have they survived this long?

I ask myself the same question, especially when it was announced on HN they just spent cash on a new branding logo https://www.underconsideration.com/brandnew/archives/new_log...

y! upside down. Money well spent.

Re: Engineer admits hacking Yahoo accounts searching for images

#79
This is probably a common occurrence in the industry, especially at companies that make money with user data. This is at the core of the issue why the recommendation has always been to minimize data exposure from industry experts.

Even if end-to-end encryption would be applied, there will never be 100% security from administrators and developers. You cannot even reasonably audit these systems with current technologies.

And yes, protected HR and user information will regularly leak into IT departments. If the latter is outsourced to third parties, this means data leaks galore.

Re: Engineer admits hacking Yahoo accounts searching for images

#80
post #45

Earlier quoted context omitted.

Let me try to rephrase this in a simpler way: This is even more troubling because smart people are less likely to be caught. At least, like Snowden's leaks, this is proof that privacy extremists aren't conspiracy nuts, and hopefully it will open a few eyes to the real danger of giving up privacy. Other comments are right: stop using big words and write plain sentences.

"Some rando engineer stealing private images elicits a real disgust response that might be moving, as opposed to talk of the NSA" Such a simple point, and look over how many heads it went.

Sure, if that's what it's saying.

I think it's pretty presumptuous to think a world salad went "over" any of our heads, when a simpler explanation is that the point was obscured by unnecessarily complex language.

Post reply on HN