Engineer admits hacking Yahoo accounts searching for images
ktvu.com
ktvu.com
Training is important because new employees or new college grads might not be aware of truly how egregious it is to view someone's personal data. It really had to be drilled into the culture. By audits and alerts, I mean that if one employee accesses sensitive information, they know that other teammates are getting an alert about it. People do such things when they think nobody will know.
This is what happens when end-to-end encryption isn't the default in communications software. All email providers are vulnerable to this bar none.
Communication between ProtonMail customers, you still have to trust that their UI hasn't been MiTM'd.
For consumers, owning the encryption keys means account recovery is impossible when they inevitably lose their keys. IM services can get away with it, because losing your IM history is not nearly as serious as losing your inbox.
For businesses, you’re not going to be able to sell a service that makes filtering impossible. This is bad for consumers too, but an absolute deal breaker for most businesses.
... including spam filtering, which matters somewhat for consumers, too.
Then there's the issue of search - with webmail you have no realistic choice but to rely on server-side search, and the same issue likely applies on phones even when using a dedicated mail app. (And indeed ProtonMail currently only offers meta-data search, but no full text body search)
Yes, it would be possible to encrypt email too but it would involve changing every email client and server there is, and there are quite a few of them. And a public key repository for everyone to be able to find the correct key for each receiving adress. Mailing list servers and other group mail would be particularly fun to solve.
"Your private key is encrypted with your password. This way your login password receives the status of the private key."
"Your password is never transmitted to the server in plain text. It is salted and then hashed with bcrypt locally on your device so that neither the server nor we have access to your password."
What's stopping them (or being commandeered) to serve you modified javascript which sends them your password, or this being done via an unsanitised email viewed via their web UI?
Having worked for two email companies for over 10 years, I know not trust email providers for privacy.
Thinking about this more, the threat model here was an insider. This is something that Tutanota wouldn't be able to prevent with its advertised services given the same situation.
Email porn? Child play.
Even if end-to-end encryption would be applied, there will never be 100% security from administrators and developers. You cannot even reasonably audit these systems with current technologies.
And yes, protected HR and user information will regularly leak into IT departments. If the latter is outsourced to third parties, this means data leaks galore.
The strategy positions Yahoo as an “amplification brand,” amplifying the things that matter, helping to “amplify you.”
So, umm, I guess I have no idea what they do.
It actually makes me wonder WTF happened to Google Finance? Why did they essentially abandon it? Charts just show up at the top of the results page but there's no dedicated site anymore.
Does anyone know the inside ballgame on this one?
You are right that simply typing "work" and hitting enter returns no results, though.
Compare Google Street View with Apple's "look around" feature. Night and day. To be fair I haven't looked at street view recently, and Google's coverage is better for now.
Or Gmail spam filtering... I can't even begin to fathom what they are thinking, whoever is in charge of that. I mean really... they have the privilege of working at Google? And... really, that's the level of effort and quality they give us, after 20 years of time with the problem?
Yes I know it can be a hard problem, and an arms race, but the level to which they are utterly falling down with good signals in the data, like the fact that I explicitly signed up for and sometimes read and reply to a mailing list, is mind boggling.
In Google Maps on Android, the status bar is now transparent, and important information like clock, battery status, connection quality and incoming messages are now drawn on top of the map. I'm sure that looks great in a presentation but now those little icons have little, and varying contrast and are hard to decipher.
In Youtube in the browser, I have autoplay disabled. Every time I log into Youtube (after a reboot), autoplay is enabled again.
It's not really clear to me what you are saying exactly.
Spedru posits the covert and exposed deviants within companies, that we've exchanged our data with, are another style of entity (besides state actors) that we ought to strive to deprive of access to that data.
At least, that's as charitably as I can characterize the comment.
That implies there's an uncharitable characterization. What would that be?
This is even more troubling because smart people are less likely to be caught.
At least, like Snowden's leaks, this is proof that privacy extremists aren't conspiracy nuts, and hopefully it will open a few eyes to the real danger of giving up privacy.
Other comments are right: stop using big words and write plain sentences.
The word "engineer" is critical to the first sentence, and your version has no translation of "banal, lascivious panopticon".
The roundabout structure of the sentences is much more relevant than the use of a big word or two.
I removed "engineer" because it's not necessary to the broader premise that more highly skilled people tend to be both more trusted in our society and more likely to know how to get away with a crime.
I didn't translate "banal, lascivious panopticon" because it was it's one of those faux-profound images that adds very little.
It's hardly revelatory to tell HN readers that people are troublingly comfortable with constant tracking by corporations and governments.
That's a very strange interpretation to me. It doesn't look at all profound or faux-profound to me, it's just imagery.
Such a simple point, and look over how many heads it went.
I think it's pretty presumptuous to think a world salad went "over" any of our heads, when a simpler explanation is that the point was obscured by unnecessarily complex language.
That's still assuming your interpretation was what the writer intended. As a native English speaker, I can tell you that it's not 100% clear.
> what necessitates knee-jerk responses or downvotes?
The meaning of a down vote is not defined by HN itself, so it's personal. For me, I use it based on value. I up-vote comments that add to or improve the discussion. I down-vote comments that add nothing.
I did not down-vote the root comment here. I replied because I found the content to be locked away by the presentation, and the content seemed to be a worthwhile part of the discussion of the article.
I think your your summary of the comment doesn't really match the comment.
On the other hand, I was taught early on not to trawl the thesaurus for word substitutions. It’s just pretentious.