Live data from Hacker News

Yahoo Triples Estimate of Breached Accounts to 3B

wsj.com

81–90 of 311 posts

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#81

I know many mention facebook or google being hacked will be an even bigger deal. But I wonder, with all the online spaces google/facebook has under control (ads, analytics, cdns, dns, crawlers, your phone, etc.) if they suspect a breach, they could literally disable any website or device that tries to share that information. If it happened in the past, well, who will know?

A government hack would be even worse and, IMO, far more likely.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#82
post #75
post #43

Earlier quoted context omitted.

Alternatively, if it's truly an asset, can it be taxed as an asset? If I give a company a car, that is taxed. If I give a company my data which is worth more than a car, it isn't. Is it possible that current accounting/tax law can be interpreted so that these are viewed similarly?

Using the black market as a standard, your identity-related information isn't worth enough to be taxable.[0][1][2] The more common data you give away is worth even less. Your "gift" is akin to giving away a few grains of sand to a glassmaker who provides a free grain counting service. Now let's say you dumped a lot sand that we could value at $10K. Any smart sand-counting glassmaker will claim his once "free" sand co…

It is when you have 3B records

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#83

Earlier quoted context omitted.

Hundreds? Are you sure?

I know a guy who uses a service that creates a unique email account for every service he signs up for. That way, he tells me, if he ever gets any spam, he can delete the account and it doesn't affect any of his other email accounts.

tell him 'bout mailinator

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#84

I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.

User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service

A free email service.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#85
post #82
post #75

Earlier quoted context omitted.

Using the black market as a standard, your identity-related information isn't worth enough to be taxable.[0][1][2] The more common data you give away is worth even less. Your "gift" is akin to giving away a few grains of sand to a glassmaker who provides a free grain counting service. Now let's say you dumped a lot sand that we could value at $10K. Any smart sand-counting glassmaker will claim his once "free" sand co…

It is when you have 3B records

If one company sells anything to another company, that sale is taxed as income like any other sale. So yes, if Yahoo sold 3B records, that would be taxed, and the recipient company can choose to book that purchase as an asset on their balance sheet and will likely expense the purchase. Hell they could even choose to depreciate the value too for as long as they follow GAAP.

OP mentioned his data alone, which isn't worth squat unless the transaction says otherwise. Meaning, if OP sold his data to a company for a taxable amount, he would be taxed on that income.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#86
post #75
post #43

Earlier quoted context omitted.

Alternatively, if it's truly an asset, can it be taxed as an asset? If I give a company a car, that is taxed. If I give a company my data which is worth more than a car, it isn't. Is it possible that current accounting/tax law can be interpreted so that these are viewed similarly?

Using the black market as a standard, your identity-related information isn't worth enough to be taxable.[0][1][2] The more common data you give away is worth even less. Your "gift" is akin to giving away a few grains of sand to a glassmaker who provides a free grain counting service. Now let's say you dumped a lot sand that we could value at $10K. Any smart sand-counting glassmaker will claim his once "free" sand co…

[deleted]

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#87

Earlier quoted context omitted.

Nobody ever said they are active users or unique individuals. I know for example I personally created hundreds of accounts on Yahoo! over the years.

Why make hundreds of accounts?

Test accounts.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#88

Earlier quoted context omitted.

Hundreds? Are you sure?

With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header. I’m sure spammers have already figured that out.

Lots of programmers haven't, though.

I get addresses rejected as invalid when signing up for some service at least once a month.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#89

Earlier quoted context omitted.

Nobody ever said they are active users or unique individuals. I know for example I personally created hundreds of accounts on Yahoo! over the years.

Hundreds? Are you sure?

Yes, positive. They were test accounts, but still in the production namespace.

Re: Yahoo Triples Estimate of Breached Accounts to 3B

#90

> A massive data breach at Yahoo in 2013 was far more extensive than previously disclosed, affecting all of its 3 billion user accounts, new parent company Verizon Communications Inc. said on Tuesday. Imagine the buyers remorse

Does anyone have insight on how this works? Do you just sue the pants off of the execs, or the lawyers who did due diligence, or the SREs maybe? Do the clawback the difference in goodwill + legal costs from the selling investors? Is there recourse at all? It'll probably the some poor schmuck SRE getting the blame, like always, right?

It works like this: lawyers come up with a security checklist. Managers make sure the checkboxes are checked. Engineers are all ignored because fuck you, your opinion isn’t on the checklist.

It’s security theatrics, not actual security. And if you stand up for something more, get ready to quit because you won’t be listened to.

Post reply on HN