Hackers expose 453,000 credentials allegedly taken from Yahoo service
arstechnica.com
arstechnica.com
If it wasn't in such credible news source I would have found the entire thing very hard to believe.
In addition, a little bird told me that these passwords are not being accepted by the yahoo servers. The whole thing doesn't pass the smell test.
That being said, the passwords are NOT stored in plain text. And individual properties don't get direct access to the user database. It's done through libraries and protocols with extremely restrictive ACLs. And one of the options isn't: "give me this user's password in plaintext".
Even if a Yahoo! property wanted to store user passwords, they couldn't. Every Yahoo! user logs in from login.yahoo.com.
Having a good understanding of how Yahoo!'s security is set up, I don't see how any of this is possible.
EDIT: It's starting to look (to me) as if those users got phished.
I would still trust Yahoo! to not leak my password ala LinkedIn.
Is there any possibility of someone someone caching the details for convenience's sake on login, and said service not going through the Paranoid review process? I haven't done this personally, but I have had to work with some absolutely dreadful internal APIs that I needed to cache information from out-of-band to make them usable.
(In all fairness, though, I'm find it hard to believe this report. I'll guess we'll find out the truth pretty soon.)
The secret code for the encryption of the cookies is only installed on the login servers, and without that package installed, there would be no way to generate a valid signed cookie.
In short, there is no 100% guarantee a rouge developer could not do any damage, but it would be pretty hard to go unnoticed.
(An entire acquired company full of rogue developers? :-) )
This is what I got for the top 10:
len(passlist): 342,514 # Amount of unique passwords.
Password, Repetition
'', 10,654 (Apparently, some passwords were blank.)
'123456', 1667
'password', 780
'ninja', 333
'abc123', 250
'123456789', 222
'12345678', 208
'sunshine', 205
'princess', 202
Edit: Source code at https://gist.github.com/3096511 133438:remia.eu@hotmail.com:combinate sort -k1n,1 -k2 cut -d: -f3- | sort | uniq -c | sort -k2 -n
would be sorting the output of uniq(1) by the password, treating them all as numeric. Depending on one's locale that gives results like 1 00auditt
100 babygirl
1 00beetle
or 1 100671105192
1 100997162005jm
2 102030405060
1 102990091404I guess it all started when Arturo left for FB.
http://nakedsecurity.sophos.com/2012/05/24/yahoo-leaks-its-o...
There was an enormously successful phishing attack that had rendered a crapton (more than 450k) users in a compromised state. Their passwords were basically stolen.
The solution was a several month long effort by multiple engineers to get the proper owner to change/reset their password. Remember, their accounts are basically hijacked at this point and they don't even know. It was one of the most involved and complex issues I've ever worked on.
Having gone through that I gained a lot of respect for Yahoo! and how they treat/handle these types of situations. Nowadays everything looks different so I don't know who's doing what.
But the more I read and think about this my guess is that all those users were phished.
In the original SQL dump it also seems that some accounts don't have a password. I'm not sure how this is possible. For example:
334860:cashcratereferer@live.com:
vs. a normal entry 334868:ktomlinson7@yahoo.com:passwordI personally have no sympathy for these "users", as they're professional content spammers :)
Further, this list have Gmail and AOL and other providers on it... I dont get it how they got there. Any clues?
With the amount of compromised sites lately. Isn't it more likely that the credentials from other sites have simply been matched with yahoo services?
"Oh look at all these Linkedin passwords, I wonder which ones works on yahoo as well"
[1] 115 match associated.*content, 104 match yahoo, 25 gmail, 0 ycombinator. I think I saw a 4550c1473dc0n73n7 in there too. Then again, 135 match google. (all case-insensitive matches)