An Important Message About Yahoo User Security
yahoo.tumblr.com
yahoo.tumblr.com
What!? Surely you're being flippant. Alexa currently ranks Yahoo.com as #5 worldwide and in the United States. NUMBER 5! How anyone could think that has zero value makes no sense to me.
The reason I bother coming here to say this is that I think the idea that 4.8 billion dollars "makes sense" to an outsider is endemic of thinking that leads to a dangerous lack of regulation. In other words, I'd be careful not to assume that the left hand always knows what the right hand is doing in companies at this scale.
> it would amass an amazing number of visitors, but would be a worthless business. //
You'd get in serious debt. But the website would still be worth something afterwards, not what you paid, but it would have a significant value. Good marketing could convert some of those repeat visitors looking for free money. Indeed, it actually sounds like not a half bad idea! Give away money via paypal/bitcoin or some such up to a limit for a few days, network effect is going to amplify that, then stop and lay out your stall .. if your stall was using bitcoin/paypal for micro payments then double+plus+good! You'd have stories in press around the world, everyone would be sharing your site ("Hey I got free money 2 days in a row at example.com").
Want to cause a riot? Release $100k in $1 notes in public in a busy, large, public space (Central Park?). Say you'll be back next week ... how many millions of people do you think you could attract, how many the 3rd week!!? How much would the press coverage and whatever brand association you could muster be worth?
Anyway, I digress.
Some hacker might have my password, hopefully they don't pull Aaron Rodgers from my line up this week.
EDIT: just for clarification, this replaces the password entirely. So I never enter a password on the site.
Fortunately iCloud Keychain means my current Y! password is random as hell and not reused anywhere, but I'm slightly nervous wondering what the hell password I had in 2014 or 2012 or whenever this stupid leak happened. :/
Consider that third-party tracking still places Yahoo as one of the top trafficked websites in the world, with only Google, Baidu, and Facebook higher.
Full disclosure: I work for Yahoo.
Naturally, there are areas where we know the algorithms are not translating the inputs to real users with 100% fidelity, but we know that the discount is relatively minor, not nearly as substantial as youre suggesting.
Multiple counter-parties had their teams diligence our user figures and associated algorithms and found them to be generally accurate representations.
Unless you're using a different definition of "active, monthly user" that deviates from the industry norms?
Unique visitors versus active accounts.
Okay that's the disconnect. Monthly uniques typically count is unique accesses of a web page by non-bots / spam. This is how I've seen it defined in every analytics software package I've ever used. Monthly active users is a vastly different concept as it implies repeat access within the month.
Though judging by the downvotes on my parent comment I'm guessing my thinking of the terms is NOT standard? Not going to lie I'm a bit confused around this. I'm going to have to look into it more.
Twitter did this to me right after their last not-so-great quarterly report came out: sent an email saying they have noticed "suspicious activity on my Twitter account and have suspended it. Click this link to reset your password." Which is kinda funny because I never posted one thing to my Twitter account. So locking it for me was the next best thing to deleting it.
When I got the LinkedIn breach email, I too just deleted my account there. Wasn't worth the fretting about security problems.
LinkedIn is like dallisgrass. pesky stuff to get rid of.
Edit: acquisition offer usually priced into share price, harder to calculate in this situation since Verizon isn't buying the whole company and all assets.
It is as much about other investors as it is about the company itself.
The motivation there is pure profit, not some higher moral purpose or justice or "make the world better" idealism.
The stock price indirectly affects the company performance, just as the company performance affects the stock price, so it's a feedback loop (or conflict?) created between the investors and the company.
Apparently, investors think that this hack won't affect yahoo's performance or stock price.
These is just my interpretation of it of course, I guess very few people (if any) actually understand all the forces at play here.
https://www.bloomberg.com/view/articles/2015-12-02/yahoo-is-...
"Yahoo's actual core business of being Yahoo (and Tumblr and whatever) is worth negative $13 billion"
"Even after deducting 38 percent from the value of [the Alibaba shares] to account for taxes, you get a value for Yahoo's actual business of just $1.7 billion"
Original news: http://www.bbc.com/news/technology-36952257 On that day, the stock dropped 1%
This is correct. For reference, $YHOO, $BABA, and $SPY all one one graph:
https://www.google.com/finance?chdnp=1&chdd=1&chds=1&chdv=1&...
[0] https://hbr.org/2015/03/why-data-breaches-dont-hurt-stock-pr...
Why would the stock be affected? Yahoo emails are free. Even if majority is hacked this won't make dent in their revenue streams coming mostly from advertising.
To make matters worse, YHOO has actually fallen off quite a bit since BABA reached $105/share 1.5 weeks ago, and YHOO corresponded with a high of around $45. If you do the math, with BABA currently nearing $110, YHOO should actually be just north of $46.
tl;dr YHOO shares are actually suffering, but it's harder to see if you're not familiar with the underlying mechanisms at play.
https://hbr.org/2015/03/why-data-breaches-dont-hurt-stock-pr...
A cluster of security mistakes in other companies does seem to increase the price of stocks like FEYE, CUDA & FTNT.
1. this leak is old, we found out about it in August
2. Yahoo is already heavily discounted to the point where without BABA they have a negative value.
also, did it take them 2 years to discover this breach? that's bad. or, do they just announce it now? that's worse.
Seems to give more credence to the viewpoint that the tool doesn't indicate the perpetrator too easily.
[0]:https://www.wired.com/2016/08/hackers-claim-auction-data-sto...
(In military parlance "suppress" usually means not specifically to destroy, but to render ineffective. For example, at the infantry level, "suppressing fire" isn't intended specifically to kill members of an enemy formation, but rather to make them keep their heads down so as not to die, rather than doing something useful like actively opposing a move by another of your fire teams. In the case of anti-air defenses being suppressed to clear the way for an air attack, though, the tool of choice is going to be a standoff anti-radiation missile; see "Wild Weasels" for more detail on how it's done.)
1) careful, narrow targeting 2) sophisticated tools 3) being covert as possible 4) really being covert as possible
Going for account info for 500 million accounts doesn't really fit #1.
Some of the nations that use the F-16 are also capable of the things you say prove US air force involvement. Even then, that's a bit of an extreme analogy.
How about we pull down the analogies to be more in line with what more likely happened? Like, someone used a truck to rob a bank and people think a manufacturer of trucks is somehow responsible?
There's always the more basic:
echo "Russians wuz here!" > /var/tmp/hacker.sig
(Bonus points to readers who understand why /var/tmp instead of /tmp :D)Because many newer Linux distributions mount /tmp as a tmpfs that gets zapped when the system shuts down. Do I get a no-prize?
> echo "Russians wuz here!" > /var/tmp/hacker.sig
Oh, that brings back memories of an incident involving Serbian/Romanian malware at a former employer of mine... when I got into the box to figure out why it was attempting to DoS Caltech, I found a complete set of DoSing tools in /root with comprehensive documentation in Romanian, plus a quick 'who' showed that the attacker was still logged in over SSH, so I looked up his IP and it came up as being somewhere in Serbia. After that, "Serbian Malware" became a meme at that company (and I quickly made sure to patch the hole -- the result of a stupid, stupid mistake that I take responsibility for -- to make sure it couldn't happen again).
My guess is they hired a firm that actually knows security - probably FireEye or Crowdstrike - and their analysts came to that conclusion.
No it's not. It's an entirely vague specification.
Was it the Russians, the Chinese, the NSA?
It's also something they'll never have to prove or verify so from a PR perspective it makes you look far less incompetent if you say 'state sponsored actor' instead of '17 year old high-schooler from Estonia'.
I disagree. In breaches like these, attribution discussion begins pretty quickly after the announcement. If researchers find evidence it was some script kiddie or a black hat group or whatever, that would embarrass Yahoo even more.
If you don't know who the attacker is, you have nothing to lose by saying you were compromised by a sophisticated adversary in a targeted attack. You have more to lose by saying a nation-state attacked you if they actually didn't.
Did you just say it would "look bad"? They just had one of the biggest data breaches in history..
Don't black-hat hacker groups exist?
"Corporate adversaries" are pretty much a myth, or are just a black hat group hired by a company.
The security team probably sees thousands of attacks every day, mostly automated but probably a dozen a day targeted/custom. If one gets through the security, that is of course more sophisticated than all the other ones, plus it outsmarted the security team and developers, so you'd hardly tell your boss "we were too stupid". Instead, it came from China* so state-sponsored is a good text to write.
*Or something like that. Enough infected computers there to go around (or government cares little enough if you rent a server).
- At least this is how I interpreted it. They put in all the right words: "threats, Industry, government, crosshairs, strategic".
Edit: "...by what it believes is a state..."??? Who is IT?
Besides, "they" don't claim anything. "They" cleverly claim that "_it_ believes" it was a state-actor. Who is this _it_ they conveniently hide?
Occam's Razor applies here: the simplest explanation is that they are telling the truth, insofar as they have been able to establish it.
Also, although of course many states could do something with the data... I still wonder why they'd auction it on a marketplace.
We'll later learn that Archive.org bought the data... "to bootstrap their new museum on Internet archeology" /s.
What sounds better?
A) We were hacked by a very powerful state sponsored enemy with an army of experts and a billion dollar budget.
B) We were hacked by bored 18 year old kid from Nova Scotia.
Since it's worked a couple of times, now everyone is going to pile on. I expect every major data breach over the next few years is going to be perpetrated by an ethereal "state-sponsored actor".
At the moment the standard for incident disclosure is "eventually disclose the leak to users", which some companies, like Yahoo in this case, really stretch.
I'd like to see the standard become engaging an outside firm and have them release as much information as possible so that the techniques used, information stolen, potential attribution etc. can be reviewed and benefit everybody.
The statement so far from Yahoo benefit only Yahoo (specifically Yahoo management)
The stolen Yahoo accounts were listed on a DNM market a few months ago. That is how we found out about it (I suspect that is also how Yahoo found out about it). That is one of the only data points we have on the outside and it points away from the attack being state-sponsored.
[0] Some would argue that the research / attribution firms are only a little less conflicted since they sell products that aim to prevent the same state-sponsored attack.
What about that would be a conflict of interest? (Just curious)
What's the difference between "may have" and "may not have" in this context?
It seems like they're saying anything could have been stolen.
Yeah, they shouldn't have unprotected passwords in any way, shape, or form. The statement makes it sound like they do store unprotected passwords, but they don't think those were stolen.
Yahoo is an old company, I'm sure procedures have changed drastically over the years.
UK law requires that personal data is not kept for longer than is necessary and is securely handled and such. So if those passwords in an "ancient DB" had personal data associated with them (real names, say) then they've been breaking the law (for a long time, is the implication).
Surely if you had passwords in old DBs then when you introduce hashing you salt and hash them and sanitise the DB and all backups ... having them still hanging around is a significant failure too. But yes, not as significant as having plaintext passwords in DBs now would be.
Far from an expert, but hasn't flagging an account as needing a password change on next login been used as a way to migrate to properly encrypted passwords in the past?
If they are opting more toward informing users quickly, then their language can't be definitive yet.
IMO this is a good thing--much better to warn people soon, than sit on the news for another month until they've completed the forensics.
If they haven't detected any sign of intrusion on their payment servers, then it would seem those did not get hit. On the other hand, it took them until now to detect the 2014 account intrusion! So it's still possible that they will discover some problem on the payment servers as they dig deeper. Hence the use of "may not" vs. "did not."
> It seems like they're saying anything could have been stolen.
Well yes, once you know the bad guys were inside the perimeter, it's hard to rule anything out. It's possible to construct a network with internal defenses as strong as the external defenses, but most networks are not built that way. Most are still soft on the inside--get root on one server and there are pathways to others.
What exactly can an average/common end user do for such incidents, even if it is to avoid them in the future? I use different passwords across accounts, with all of them being somewhat complex or very complex.
I have looked at a few different paid service providers before, but they're all very expensive. Expensive for me is anything that charges more than $20 per year, or worse, charges that amount or higher for every single email address/alias on a domain. My use of email for personal purposes is writing about a handful of emails in an entire year, but on the receiving side, I get a lot of emails - most of them somewhat commercial in nature (like online orders, bank statement notifications, marketing newsletters I've explicitly signed up for, etc.). I also have several email addresses, each one used for a different purpose and with some overlap across them.
It seems like web hosting has become extremely cheap over time whereas email hosting has stagnated on the price front for a long time.
Two-factor identification on any account that involves your money is a good idea, too.
For a dedicated service with keen developers and ongoing product development (yay U2F support), great and accessible support, reasonable expectations of privacy, it has been well worth it. YMMV, of course.
I've seen Fastmail recommended multiple times and have looked at it. Considering that I would actually want at least three or four "users" (access wise), the plans are quite expensive. The fact that each user can have up to 600 aliases (which sounds great and is useful) doesn't matter much to me since the billing is per user (as opposed to some kind of mix and match of users and aliases). This makes their business model not suitable for my needs.
My fallback were I to move my group off Zoho to something paid would probably be Rackspace. ymmv
As if, this one would never get compromised and they were much better at it. Except they probably aren't. Bet the devs have all keys on their "work" laptop (you know, the one with stickers that they take home, to starbucks, on vacations, watch their movies on, etc.) (like everyone elses is doing)
Sooo narrow-sighted.
Plus, it would be better for all concerned to have 25 smaller companies with 20M accounts each than one company with 500M accounts. Less of a security monoculture, and fewer eggs in a single basket when it does get compromised.
From a user's perspective, although it may be less convenient, it's probably healthier to use a bunch of services offered by a bunch of different companies than to work with a single company for all digital needs.
In addition to securing access to your email provider (Gmail for example), you now have to secure access to your domain provider too. And even if you do your best, they might fall for social engineering because they take phone calls--like in the famous @N hack:
https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...
I definitely took for granted how easy it is to say to someone "first initial + last name at major email provider . com", instead of "really easy first part at custom domain, wait let me give you the phonetic alphabet equivalent, no just the letter b, not actually the word bravo... . io - yes io, item oscar, it's the indian ocean. Yeah I'm sure it works"
Then pray you actually get the email.
When I first went to get the domain for my main/personal email address, the .COM wasn't available...And I just didn't have an interest in the .NET or .ORG. So I went with .CC. I thought, "Hey it seems neat, slightly different (at the time) but not too weird, and its one letter shorter for people to type!" ...Or so I thought. Boy, has it been annoying with some people. Admittedly over the years it has become slightly easier, though there is the occasional exercise almost exactly as you described above, spelling it out as if to an infant.
I supposed the audience on HN is likely tech-focused, but even today (september 2016), there are so many "civilians" out there who are NOT exposed to non-.COM domains, its quite surprising. So many people that you would think have by now been exposed to some technology - hey they use advanced mobile phones, "smart tvs", etc. - and they look at you stunned if you bring up an email address with a TLD from outside the U.S. I'm living here in U.S., but if you want to really stump some people give them email addresses like the following:
* joe@smith.DE * jane@doe.FR * fred@johnson.CH
Its quite interesting!
"Hi, my name is Kate", "How do you spell that?". WTF!
And they get it wrong anyway. My partner's name is "Andreea", with a double 'e', and she always makes this fact very explicit, but in 95% of cases they will input it in their systems with a single 'e'.
My name is unusual, but it's one letter off from a usual name in my country. The bank has my correct name in their record, of course. But each time they email me, they use the wrong name. They sometimes even emit me new cards in the wrong name! When I complain, they ask very surprised and say that they are aware that the name in the system is what it is, but they thought it was a mistake, so they decided to emit the card in a different name! Unbelievable! This has happened with multiple banks.
I personally use Gmail as an IMAP client for my domain's mailbox. I get the convenience of webmail + the ability to move my data elsewhere if I wish to.
Almost all (old) providers let you set up a mail forwarding (to the new provider). But even better, several services let you set up some fetchmail-like program where it imports all the messages from the old provider, e.g. via POP3 or IMAP, and even deletes them with the old provider, if you want.
Nevertheless, I fully agree with you that email services are much too expensive. Given the current market prices, Fastmail, for example, is great and worth its money.
We're told to spend some money on good quality software and services.
But: If I (and even more so the average non-technical user) pay 99 USD/year for Dropbox, 50 USD/year for Fastmail (because you want your own domain), 10 USD/year for the actual domain (separately), 100 USD/year for my quality newspaper subscription, etc. -- and all this is just for one person in my famile (i.e. me) -- you soon end up not having enough money for the "real" things in life.
It's better than Office365 support though.
Problem is they couldn't help me much when I had problems. Google Apps has serious limits and contacting support won't help you get around those limits. Most of the time support just tells you what you can already find in their online docs.
They only solved two issues for me: (1) when I wanted to change my primary domain, after 2-3 months of asking them repeatedly, they finally enrolled me into this beta programming and finally changed my primary domain. And (2) when I upgraded to the annual subscription and then changed my mind, they reverted me to the flexible pricing. On the other hand they couldn't even help with with an import gone wrong.
With FastMail I have had a good experience thus far.
Were you on the grandfathered free tier? It seems to be quite trivial to change the primary domain if you're on a paid tier.
And had fewer issues in general with FastMail. Google Apps has some crazy limits, like on the number of IMAP connections or email aliases, you can't normally change the primary domain, you can't setup an abuse@ alias, etc, etc. and contacting Google Apps support doesn't do more than for them to tell what's already written in the docs.
And I mentioned in another mail, but FastMail's IMAP import and POP3 links work, whereas this functionality is broken for Gmail and Google's support won't help you ;-)
The tech support rep who answered barely understood their platform and kept giving me incorrect instructions. It took a long while on the phone with that rep to get the account moved to a business account.
Unless customer service means something different than customer support. What does it mean?
Personally, I use Google Apps for Business and since a few months ago Hangouts doesn't work correctly any more. It's almost unusable at times.
What can I do? Who can I complain to? How can I escalate this? Absolutely nobody can help me.
Once I figure out a feasible transition plan from Hangouts, I'm done with doing business with Google.
I went for Mailbox.org, you get 25 GB for email AND 25 GB for documents, all for €4.50/month, about $60 per year. You also get calendar/contacts/tasks with web based apps for all of the above, plus word processor and spreadsheet. They support open standards (CardDav/CalDav/WebDav) so you can choose among several clients on any platform, and they seem to have a good track record with regards to privacy.
This, however, is offset by the fact that my "quality newspaper" subscription is about AUD $350/year, LOL
Disclaimer: I am not associated with Mailbox.org in any way, just a happy customer (at least for now!).
Unfortunately, it does not support IMAP or POP, which I prefer just to have local copies of mails as a backup.
A paid account looks appropriate (and would help the company stays in business), but it's a bit pricey for my needs (though not as much as other providers who don't have a lot of flexibility on users/storage/aliases).
I will try the free account to experience it firsthand.
* The folks behind Protonmail are also heavily involved in the OpenPGP.js project. Interop with plain PGP from non-Protonmail accounts is on their roadmap and a feasible future feature. AFAIK that's not on tutanota's roadmap and they use a different customized crypto library, so all you'll ever get is e2e encryption with other tutanota users.
* Proton's mobile app is a top-rated android mail app, and pretty good even compared to iOS's Mail app.
* IMAP support is also on Protonmail's roadmap, but not something I miss due to the good mobile app.
* The tutanota.com and tuta.io domains are dorky and hard for other people to remember.
Encrypts everything, and manages the revisions. Available for Mac and Windows. I use for Mac.
Perhaps the benefit of being at a paid email provider is that they have a much smaller number of accounts, so they are a less attractive target for hackers.
Also, in case you have problems, it's impossible to reach Google's support, unless you're a Google Apps customer. It's also near impossible to reach Yahoo's support too. I know because I've been there. If you don't pay, you don't get any support.
"Better protection" is a fairy tail if you can't talk with somebody in case your email goes missing or in case you suspect you've been hacked.
Password managers have made this somewhat less painful, at least on the Web, as opposed to "Apps" which refuse to implement the API for using the password -- and username -- stored in your keychain.
Personally I find email to be the most important online service. Everything depends on email. While I can live a non luddite life without Netflix and Dropbox and cloud VMs, and Facebooks, I quite literally can't live my normal life without email.
For me, it's more important than a phone. Because of this, I would expect to pay less for a mobile plan than for email, but even with "expensive" email service, the situation seem reversed.
If the idea of paying for online services were more entranced in people's mind, there would be more competition and there would be email providers offering services at any price point. Now we only have free email, and "expensive" email, for "those" people.
Or is there some group that is trading breach data privately that have themselves been compromised so that data coming from them is finally leaking out?
I'm now more worried about the 4 year delay in these things coming to light than the effect of the breaches themselves given how many times I now show up on haveibeenpwned.
I just want to know if the same exploits were used in all of these instances. Or maybe they have just found backups for all these companies this year from 2012 and are using those. I don't even how that would happen.
"Hackers who used an employee’s password, re-used from the LinkedIn breach, to access Dropbox’s corporate network and steal the user credentials" - from a unnamed source quoted in a techcrunch article.
So maybe they also managed to traverse from linkedin to Yahoo or Yahoo to linkedin through similar password re-use.
Maybe they're trying to devalue their stock prior to the merger? Similar to what Caris did: http://www.law360.com/articles/684195/caris-employees-get-16...
Besides the 'kill all ads' talk which isn't very helpful, there really needs to be some serious conversation about how this particular issue with the internet is addressed.
If they have such evidence, why don't they explain so? To me it looks like a tactic to put the focus on the "noughty" government instead of themselves.
Anyway, it will be an interesting read (if ever written) how Yahoo discovered they had been stolen and by who (what state?).
Also, if "the state" is finally behind this, who will they prosecute till death? I bet it's the hacker :(
b) If you name the state you think is behind it, you better be ready for the diplomatic repercussions between the US government and the rogue state, as well as potentially stopping doing business in that state (see Google and China)
It's a quite interesting topic indeed.
Buy a beer for someone who has worked security for a big firm and they can tell you all about it.
https://www.washingtonpost.com/world/national-security/nsa-i...
We can assume that the US government is not the state-sponsored actor in the OP, because their attack has already been publicly known for some time. This one is probably China or Russia.
http://www.rollingstone.com/feature/the-geeks-on-the-frontli...
http://www.vanityfair.com/news/2013/07/new-cyberwar-victims-...
https://www.technologyreview.com/s/507971/welcome-to-the-mal...
http://www.nytimes.com/2013/01/31/technology/chinese-hackers...
http://www.vanityfair.com/news/2011/09/chinese-hacking-20110...
http://www.bloomberg.com/news/articles/2011-07-20/cyber-weap...
http://fortune.com/sony-hack-part-1/
http://fortune.com/sony-hack-part-two/
http://fortune.com/sony-hack-final-part/
http://www.theverge.com/2015/1/21/7861645/finfisher-spyware-...
http://www.bloomberg.com/news/articles/2014-03-13/target-mis...
http://foreignpolicy.com/2013/11/19/stuxnets-secret-twin/
http://www.cbsnews.com/news/60-minutes-great-brain-robbery-c...
http://www.wsj.com/articles/u-s-steel-accuses-china-of-hacki...
http://www.vanityfair.com/news/2011/09/chinese-hacking-20110...
http://www.vanityfair.com/news/2011/09/operation-shady-rat-2...
This is bad right? Like, worse than your hashed password and your mailing address.
The only good thing is that if I ever implement security questions, I'll remember Yahoo! and how it could end up in the wrong hands.
Just make it something reasonably short as you might have to repeat it to a live customer service agent.
I was born in 1990, and my insecure online behavior from 2000-2005 scare me. Hopefully HaveIBeenPwned gets their hands on this so I can scan for my teenage usernames.
Personally, I demand criminal investigation and at least a $1000 fine per account breached.
And something's changed with their biz accounts anyway- it's been sold/rebranded or something and I'm not sure where the future lays... :[
http://www.ncsl.org/research/telecommunications-and-informat...
That tops the HIBP list for the most stolen.[1]
GCHQ? Although GCHQ seems to have hacked them even earlier than that.
https://www.theguardian.com/world/2014/feb/27/gchq-nsa-webca...
#!/bin/bash
EADDRESS=$([[ "$1" == "" ]] && echo "noreply@example.com" || echo "$1")
EADDRESS=$(echo "$EADDRESS" | sed 's;@;%40;')
RESPONSE=$(
curl "https://heroic.com/wp-admin/admin-ajax.php" \
-H "accept-language: en-US,en;q=0.8" \
-H "accept-encoding: gzip, deflate, br" \
-H "user-agent: Mozilla/5.0 (KHTML, like Gecko) Safari/537.36" \
-H "content-type: application/x-www-form-urlencoded; charset=UTF-8" \
-H "referer: https://heroic.com/email-security/" \
-H "x-requested-with: XMLHttpRequest" \
-H "origin: https://heroic.com" \
-H "authority: heroic.com" \
--data "action=heroic_scan_email" \
--data "data[email]=${EADDRESS}" \
--compressed --silent
)
if command -v php &> /dev/null; then
php -r "print(json_encode(unserialize(urldecode('${RESPONSE}'))));"
fi
PS: Using serialized data is a bad idea: https://www.owasp.org/index.php/PHP_Object_InjectionHTTP parsing is notoriously difficult and I'd rather trust cURL (which is battle-tested in a load of environments) than a PHP userspace library.
I primarily write JS for a living but because I freelance I often have to work with wordpress. After spending a few weeks digging into the internals I soon realized that every single wordpress project I've inherited–paid themes included–were horrendous and failed to utilize the most basic facilities provided by core.
In most of these projects a quick turnaround was more important than clean code (probably the cause of the aforementioned horrendous codebases), so I always just hacked away at the templates without every trying to gain a deep understanding of PHP, its recommended best practices, and security gotchas.
My question is, can you point me towards something like "PHP, the good parts"? I would like to know how to write well architected, performant, and secure PHP on the occasions I need to use it professionally. I know that PHP has a reputation as being dangerous by default, so knowing what not to do would be reassuring. So far all of the PHP books I've found have been fairly disappointing; covering all of the features without really detailing any best practices or opinions.
EADDRESS=$([[ "$1" == "" ]] && echo "noreply@example.com" || echo "$1")
could be replaced with: EADDRESS={$1:-noreply@example.com}
From the man page: ${parameter:-word}
Use Default Values. If parameter is unset or null, the expansion of word is substituted. Otherwise, the value of parameter is substituted.
For: EADDRESS=$(echo "$EADDRESS" | sed 's;@;%40;')
you could use: EADDRESS=${EADDRESS/@/%40}And then don't include an easy link to where users can do that? Great work yahoo.
I found my way to http://profile.yahoo.com but apparently from my machine at an AU University: "profile.yahoo.com’s server DNS address could not be found"
BTW, I don’t know if it’s coincidental but just yesterday I received a notification from Yahoo to disable access to Mail from third party apps.
At this point, it should at least be considered. There's obviously quite a bit of incompetence at Yahoo, but still...
The day the same happens to Google or Facebook will be very different.
It could be entirely unrelated.
More relevant than ever.
Here's the magic link: https://edit.yahoo.com/config/delete_user
Whoever the "state-sponsored" hacker is probably has lost interest in that access.
Even in a hypothetical future where, say, two employees in a company couldn't communicate privately without the entire rest of the company knowing (and I question whether that would be a good future), you still want the ability for one employee to communicate and certify the message as coming from them. Otherwise I could give myself bonuses. That requires some password or key known to me and only to me; that requires that cookies and other session state on my computer are only accessible to me.
As for personal info, don't give it to them. Anyone who doesn't require it by law gets mis-info, this has served my privacy & security since the turn of the century. EVERYONE wants your phone number "for security" these days* , and yet, when they bungle their security yours goes out the window with a million+ others'.
*Your phone number is marketing gold to those who believe they value your personal, identifiable data more than you do.
edit: more asterisks, less italics
I logged in from my only computer, they presented my recovery email addresses with check boxes. I didn't read the prompt, but I selected the one I still use (one was so freaking old--a netzero address). It seemed to remove it from the list, which was the opposite of the behavior I'd expect. I literally didn't care enough to add it back. If I get locked out of my yahoo account...so?
Anyway, then they sent me a "new device" email that said I should login from one of my normal devices. It was my normal device, I just hadn't logged in for maybe...years? Surely they can alter the logic to not say something so stupid.
On the other hand, my LinkedIn password was 15 base-64 characters, poorly hashed with just SHA-1. As a rough ballpark, cracking it on average comes out to about 500 times all of the work that has ever been put into BitCoin mining. I still changed my password after the breach. Why not?
However, the specifics of the hash only make a difference if your password is weak. As long as the hash is non-invertible, use passwords containing at least 96 bits of entropy, and you're fine.
I use https://github.com/kmag/store_password_gpg , which is a 200-line Python script I wrote a while ago to generate a random password and encrypt it using gpg. Any decent password manager should allow you to generate unique, random, per-site passwords.
The went on to say they have unactivated all clear text security questions.
Really, WTF Yahoo. Why bother hashing a pw if you are going to have plaintext security questions.
Though at least they were not using MD5
If they had not hashed the passwords you would be able to login to millions of Yahoo accounts with this leaked data.
Regarding your last sentence, I think other comments have chimed in on what they believe the pre-bcrypt hashes were made with.
I've been getting an "Unexpected sign-in attempt" email from Yahoo every day for the last couple of weeks, but I don't see any evidence that the attempts were successful.
[0] http://www.informationisbeautiful.net/visualizations/worlds-... [1] https://docs.google.com/spreadsheets/d/1Je-YUdnhjQJO_13r8iTe...
what to do if one had an ancient account that was abandoned but has one's name on it?
[p.s. forgot password, etc.]
Not really even saying this in a mean way. Almost all top CS programs in the US have assignments on writing buffer overflow attacks and reverse engineering in their mandatory intro to systems course. But I don't seem to see them going off on their own to learn more sophisticated attacks and acutally using it in the real world.
Why does russia seem to foster so many blackhats? Or is it just the proxies that are hosted there?
It seems like Yahoo's PR wants to switch focus to state-sponsored hacking and form a narrative around what's been in the news lately as opposed to Yahoo's incompetence.
Also it's less embarrassing to get hacked by a whole nation than a few nerds in their basement.
State attack = a state steals the access and keep the breach secret for as long as they can [or until they get hacked themselves]. They use it for espionage and similar purposes
Evil bad guy = all accounts and passwords are already available on blackmarket.com since Day+1 after the breach. They'll probably end up in a torrent within the next month.
Evil bad guy sponsored by a state = Well, somewhere between the two. Hopefully the state ensures they get exclusive access and non disclosure.
> Also it's less embarrassing to get hacked by a whole nation than a few nerds in their basement.
Seems like you understand just fine.
Like showing up on the doorstep of a CA and asking them to issue forged SSL certificates.
This was relevant for the pinning bug that was just fixed in Firefox 49: normal users shouldn't care about it, but it's very dangerous for Tor users.