Defending Against Hackers Took a Back Seat at Yahoo, Insiders Say(nytimes.com)
nytimes.com
Defending Against Hackers Took a Back Seat at Yahoo, Insiders Say
http://www.nytimes.com/2016/09/29/technology/yahoo-data-breach-hacking.html?_r=2&mtrref=t.co
319 comments
Funny timing. My in-laws (both 70+) just had to change their passwords (both using @yahoo.de email addresses) and my mother in law probably botched it / managed to type the wrong thing twice or something.
Password reset requires 2 security questions (ugh - already ugly) and while she's 100% certain that she knows the answer to both the second one isn't accepted - probably another spelling issue (think St. Marlo vs. St Marlo vs. Saint Marlo vs. Sankt Marlo vs ..).
All of this is her fault, not yahoo's. But now she's stuck. There are no ways to contact support, at all, and by now her 'resolve this problem' links already contain a "In rare cases like these, we suggest creating a new account" line.
Anecdotal moral of the story: Yahoo has no customer support at all. Migrate your elder family members away while you still can. :)
Password reset requires 2 security questions (ugh - already ugly) and while she's 100% certain that she knows the answer to both the second one isn't accepted - probably another spelling issue (think St. Marlo vs. St Marlo vs. Saint Marlo vs. Sankt Marlo vs ..).
All of this is her fault, not yahoo's. But now she's stuck. There are no ways to contact support, at all, and by now her 'resolve this problem' links already contain a "In rare cases like these, we suggest creating a new account" line.
Anecdotal moral of the story: Yahoo has no customer support at all. Migrate your elder family members away while you still can. :)
I can relate to a company not putting value on security, or thinking the cost of securing systems may be higher than the cost of getting hacked.
I once worked for a company where I inherited a RESTful API. It stored the company's core data, including private customer information. It had no authentication, completely open for anyone on the internet to read or update any of our data.
I alerted my manager about this and that made its way to the highest levels of the company. The decision was to create a backlog item. It took about a year before we got to it.
The reason we ended up finally fixing it was because we were contacted by a security researcher one day. He said he had found a vulnerability in our system, but wouldn't tell us what it was until we disclosed our bug-bounty terms (basically promising to pay him if he had found a real vulnerability). If we wouldn't do this, he was going to write a blog post about it.
My manager used some delay tactics to buy us some time, while we spent the next 24 hours slapping a bandaid on the API. Once we had fixed it and agreed to pay the researcher, he disclosed his vulnerability and it had nothing to do with our API. It was a minor XSS that couldn't leak any sensitive information.
I once worked for a company where I inherited a RESTful API. It stored the company's core data, including private customer information. It had no authentication, completely open for anyone on the internet to read or update any of our data.
I alerted my manager about this and that made its way to the highest levels of the company. The decision was to create a backlog item. It took about a year before we got to it.
The reason we ended up finally fixing it was because we were contacted by a security researcher one day. He said he had found a vulnerability in our system, but wouldn't tell us what it was until we disclosed our bug-bounty terms (basically promising to pay him if he had found a real vulnerability). If we wouldn't do this, he was going to write a blog post about it.
My manager used some delay tactics to buy us some time, while we spent the next 24 hours slapping a bandaid on the API. Once we had fixed it and agreed to pay the researcher, he disclosed his vulnerability and it had nothing to do with our API. It was a minor XSS that couldn't leak any sensitive information.
I wrote a few days ago about how easy it is to compromise your ethics when trying to save a company. The problem is that once you compromise once, its very easy to do it again.
https://news.ycombinator.com/item?id=12557163
The problem is, it's way too easy to look past the action you are taking because you can talk yourself into believing its for the greater good.
And this is a huge ethical breach by Mayer, if she did this way back then, it's pretty reasonable to assume there are some more skeleton's hiding in the closet.
I don't really think I'd be wanting to give Verizon a reason to reconsider the takeover......
https://news.ycombinator.com/item?id=12557163
The problem is, it's way too easy to look past the action you are taking because you can talk yourself into believing its for the greater good.
And this is a huge ethical breach by Mayer, if she did this way back then, it's pretty reasonable to assume there are some more skeleton's hiding in the closet.
I don't really think I'd be wanting to give Verizon a reason to reconsider the takeover......
I am not sure what end-to-end encryption would have done to defend Yahoo's users against the entity that broke in and hoovered up its databases. Similarly: the password reset situation is sad (understandable --- it would have cost them millions of users at a point where their declining user base was being carefully watched by the market --- but infuriating) but again, what difference would it have made with respect to the most recent breach?
There are just a few companies in the whole world who both run tens of thousands of servers and are equipped to go head to head with serious attackers. Yahoo isn't one of them. Has it ever been? No.
There are just a few companies in the whole world who both run tens of thousands of servers and are equipped to go head to head with serious attackers. Yahoo isn't one of them. Has it ever been? No.
Can I just inject some perspective and say that the question would (should?) have gone something like this?:
"So we got 500 million passwords stolen. We're using bcrypt with an adequate number of rounds, so we only anticipate 1000 of those passwords ever being broken. Should we issue a mass reset?"
It's never black and white, you have to weigh things against each other.
"So we got 500 million passwords stolen. We're using bcrypt with an adequate number of rounds, so we only anticipate 1000 of those passwords ever being broken. Should we issue a mass reset?"
It's never black and white, you have to weigh things against each other.
Referring to the infosec team as "paranoids" is a really bad idea. I have our infosec team report into me and they terrify me on a regular basis but they are not paranoid. They worry, the poke around, they find stuff and they fix it.
“At Yahoo, we have a deep understanding of the threats facing our users and continuously strive to stay ahead of these threats to keep our users and our platforms secure,”
Why do I always get the almost unresistable urge to yell at my flat screen whenever a corporate spokesdrone opens his or her mouth?Is the ability to talk plattitude-gibberish a requirement for such a job?
>>"...said the company spent $10 million on encryption technology in early 2014..."
What does that mean, exactly? Is it really possible to spend $10 million on encryption or is that some kind of marketing spin on things? I'm genuinely curious about this.
What does that mean, exactly? Is it really possible to spend $10 million on encryption or is that some kind of marketing spin on things? I'm genuinely curious about this.
Its the same issue since Grog tried to hide the first rock from Og:
The “Paranoids,” the internal name for Yahoo’s security team, often clashed with other parts of the business over security costs. And their requests were often overridden because of concerns that the inconvenience of added protection would make people stop using the company’s products.
Infosec is never easy, and part of making things secure is that you give up conveniences for peace of mind. It's 2016 and I'm still a but surprised that people willingly open themselves and their data to hackers in lieu of stock holders and customer retention. It's unreal when you stop and think about it.
The “Paranoids,” the internal name for Yahoo’s security team, often clashed with other parts of the business over security costs. And their requests were often overridden because of concerns that the inconvenience of added protection would make people stop using the company’s products.
Infosec is never easy, and part of making things secure is that you give up conveniences for peace of mind. It's 2016 and I'm still a but surprised that people willingly open themselves and their data to hackers in lieu of stock holders and customer retention. It's unreal when you stop and think about it.
If Yahoo end up being successful like, for example, Slack or Dropbox these security issues will not be at all discussed here.
I did not see any outrage when Slack security issues back in May 2105 [1]: majority of people were saying "but it is great software". Dropbox the same.
So Yahoo did a similar bet as all other companies (focus on features - we will fix security latter) but they lost that bet.
[1] http://www.makeuseof.com/tag/slack-hack-need-know-collaborat...
I did not see any outrage when Slack security issues back in May 2105 [1]: majority of people were saying "but it is great software". Dropbox the same.
So Yahoo did a similar bet as all other companies (focus on features - we will fix security latter) but they lost that bet.
[1] http://www.makeuseof.com/tag/slack-hack-need-know-collaborat...
Perlroth is gawker themed Krebs wannabe. Everyone involved in this story should be ashamed for helping fuel an unsourced article that is purely CYA for the former security team. Shame.
The iron cliches:
- Security is a process, not a product.
- You always pay for security. Up front, after the compromise, or both, if you're unlucky or bad at your job.
- Security is a process, not a product.
- You always pay for security. Up front, after the compromise, or both, if you're unlucky or bad at your job.
If Yahoo had indeed positively identified the breach to have originated from a 'state-sponsored actor', it is possible that their thinking was something along the lines of "Resetting the passwords wouldn't help us much anyway against someone with so many resources."
Of course, I'm just speculating based on what I see in news reports. Perhaps the 'state-sponsored' actor was just PR spin to save face? I really just don't know what to think.
Of course, I'm just speculating based on what I see in news reports. Perhaps the 'state-sponsored' actor was just PR spin to save face? I really just don't know what to think.
[deleted]
[deleted]
"Mr. Bonforte said he resisted the request because it would have hurt Yahoo’s ability to index and search message data to provide new user services. 'I’m not particularly thrilled with building an apartment building which has the biggest bars on every window,' he said."
How about an apartment building where everybody's shit keeps gets stolen then? Everybody tries like hell to move out, and the only tenants left are those with no place else to go. Which on the internet is nobody.
How about an apartment building where everybody's shit keeps gets stolen then? Everybody tries like hell to move out, and the only tenants left are those with no place else to go. Which on the internet is nobody.
If this is true it taints Marissa and any business that hires her in the future, because it's hard to think of a more stark example of putting the interests of the user last.
I stopped using Yahoo the first time I setup an account for a friend and they were already on Yahoo's spam email reseller list faster than I could disable the opt-out setting. There was spam waiting in the inbox on an email account less than 5 minutes old.
I appreciate some of what they've done for the larger community, but decisions like that which make users take such a distant backseat to the bottom line make me not want to be a yahoo user ever again.
I appreciate some of what they've done for the larger community, but decisions like that which make users take such a distant backseat to the bottom line make me not want to be a yahoo user ever again.
See also: https://news.ycombinator.com/item?id=12563798
Quote:
> Whenever mega-hacks like the Yahoo! fiasco hit the news, inevitably the question gets asked as to why the IT security systems weren't good enough. The answer could be that it's not in a company's financial interest to be secure.
Quote:
> Whenever mega-hacks like the Yahoo! fiasco hit the news, inevitably the question gets asked as to why the IT security systems weren't good enough. The answer could be that it's not in a company's financial interest to be secure.
Reality check: Security (especially IT security) takes a back seat in 90% of businesses. The only exceptions are corps who gain significant power over govs and users by being secure (I think Google and Facebook here), and when regulations require a corp to do some kind of security fundamentals then these are applied as necessary to avoid fines.
Google hired hundreds of security engineers with six-figure signing bonuses, invested hundreds of millions of dollars in security infrastructure and adopted a new internal motto, “Never again,” to signal that it would never again allow anyone — be they spies or criminals — to hack into Google customers’ accounts.
Wow! Security starts at the top!
Wow! Security starts at the top!
That begs the question; what was in the front seat? Has Yahoo achieved anything of note since the 90's?
Things are not going so well for Marissa. She's a technical person and should have known better.
I'm not a big fan of regulation, but it feels like there is very little _internal_ motivation for a place like Yahoo to take security seriously.
Not sure what the solution is, but unless there is a financial reason to create, I don't think we'll see much change.
Not sure what the solution is, but unless there is a financial reason to create, I don't think we'll see much change.
Keep in mind shit like this is what happens when people get fired and blame management, rumors & shit get started like this. We don't know the real story.
Companies should have a Chief Risk Officer who have a big component of their bonus based upon the success of their risk management strategies.
I just returned from DerbyCon. An amazing security conference that covers both attack and defense. All talks are on youtube. Here is a good summary of the powershell talks. Really good stuff.
https://blogs.msdn.microsoft.com/powershell/2016/09/27/power...
https://blogs.msdn.microsoft.com/powershell/2016/09/27/power...
Newsflash: struggling company doesn't spend time and effort on things that don't directly make them money.
Google hired hundreds of security experts with 6 figure bonus... Is this kind of bonus norm in the Valley?
> The "Paranoids," the internal name for Yahoo’s security team, often clashed with other parts of the business over security costs. And their requests were often overridden because of concerns that the inconvenience of added protection would make people stop using the company’s products.
That's the best summary of the problem for the industry as a whole, not only tech but any industry where failures are uncommon but with grave consequences.
A quote from Fight Club that illustrates that problem:
> Narrator: A new car built by my company leaves somewhere traveling at 60 mph. The rear differential locks up. The car crashes and burns with everyone trapped inside. Now, should we initiate a recall?
> Take the number of vehicles in the field, A, multiply by the probable rate of failure, B, multiply by the average out-of-court settlement, C. A times B times C equals X.
> If X is less than the cost of a recall, we don't do one.
That's the current mindset of the technological world, estimating whether the cost of atoning for the problem is lower than the cost of securing the systems.