Earlier quoted context omitted.
How much do you actually need to know about someone to serve up email to them?
For a consumer mail service, you to need to know enough to let them recover their account, possibly with decades of un-backed-up correspondence with and photos of since-deceased friends and relatives, when they’ve forgotten their password, and without letting someone else recover their account. This is a hard problem. (I’m expecting some idealized “solutions” from people with idealized beliefs about mass market tech…
Yahoo Triples Estimate of Breached Accounts to 3B
91–100 of 311 posts
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#92> A massive data breach at Yahoo in 2013 was far more extensive than previously disclosed, affecting all of its 3 billion user accounts, new parent company Verizon Communications Inc. said on Tuesday. Imagine the buyers remorse
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#93Earlier quoted context omitted.
User accounts? Really? This is Yahoo we’re talking about. You really do need user accounts to run an email service
> You really do need user accounts to run an email service Exactly, regardless of that companies keep asking users for a whole collection of personal data, not always making it obvious which fields are actually required because it's good business for them to get as much personal data as possible. Average users are usually unsure about a lot of this stuff and naive enough to enter their real data for fear of getting c…
> Exactly, regardless of that companies keep asking users for a whole collection of personal data, not always making it obvious which fields are actually required
You literally don't need any user information to run an email service. You only need a means to identify them which could just amount to giving them a long, randomly generated password. Even the username is only necessary for the purpose of being able to identify them as a recipient, not for login itself.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#94A spokesman for Oath, the new name of Verizon’s Yahoo unit, said the company determined last week that the break-in was much worse than thought, after it received new information from outside the company. Can they claw back money from Yahoo shareholders because of this?
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#95Earlier quoted context omitted.
Alternatively, if it's truly an asset, can it be taxed as an asset? If I give a company a car, that is taxed. If I give a company my data which is worth more than a car, it isn't. Is it possible that current accounting/tax law can be interpreted so that these are viewed similarly?
Using the black market as a standard, your identity-related information isn't worth enough to be taxable.[0][1][2] The more common data you give away is worth even less. Your "gift" is akin to giving away a few grains of sand to a glassmaker who provides a free grain counting service. Now let's say you dumped a lot sand that we could value at $10K. Any smart sand-counting glassmaker will claim his once "free" sand co…
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#96I think the issue right now is that private user information is viewed as an asset, not a liability. If we could find a way to make it more of a liability, companies would be less likely to collect it just for the sake of having it, and they would be more proactive in securing it.
I believe EU's GDPR made some efforts in that direction, but I'm not sure it went far enough. We need laws that give companies incentive to store very little data on us outside of what's absolutely required for the functioning of the service. And if they do store additional info, and their servers are breached, then automatic hefty fines should be paid (right after the mandatory notification to authorities and the pu…
> if they do store additional info, and their servers are breached, then automatic hefty fines should be paid (right after the mandatory notification to authorities and the public).
This is already in the GDPR - you have to notify everyone affected about breaches, and the fines can go up to 20 million or 4% of annual turnover, whichever is greater.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#97Earlier quoted context omitted.
With gmail, you don't need it - foo+bar@gmail.com will end up as foo@gmail.com and you can filter by To: header.
I’ve run a fair amount of email campaigns where we strip out the + if gmail is the domain to ensure it doesn’t end up in some weird filter. Dick move, I know. Tell marketing that though. I personally use gmail through a vanity domain and have a catch all rule, so I end up signing up with a fake email account for every domain (hn@mydomain.com) and then the catch all forwards it to my real account (me@mydomain.com).
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#98Earlier quoted context omitted.
Hundreds? Are you sure?
I know a guy who uses a service that creates a unique email account for every service he signs up for. That way, he tells me, if he ever gets any spam, he can delete the account and it doesn't affect any of his other email accounts.
It does sound weird to the person writing it down and I've had more than one person say something like "well, if you're just going to give me a fake address, then don't bother" before I explained myself.
One other down side is that it is not as easy to reply to mail as the other, generated identity (in gsuite, you need to create a new account in the domain to write as that username and also maybe jump through a hoop or two). Replying casually can often reveal your main identity, which is often the one you are trying to strongly protect.
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#99On a related note Equifax stated yesterday that they identified an additional 2.5 million accounts that were breached: https://www.nytimes.com/2017/10/02/business/equifax-breach.h... Is proper audit capability just not seen as important at these companies?
Re: Yahoo Triples Estimate of Breached Accounts to 3B
#100I feel a little sad that pay-walled articles make it to the top of HN. I'm sure the article is interesting, but a lot of us can't actually read it.
There's a workaround: submit the article to archive.is. http://archive.is/d8LTZ I didn't come up with this trick, but unfortunately I forgot who donated it.
It seems likely that they know about this backdoor and have opted to allow it. They must surely know the IO addresses associated with archive.is and have yet to make any effort to block then.