{"id":15845,"date":"2016-09-28T16:10:55","date_gmt":"2016-09-28T20:10:55","guid":{"rendered":"http:\/\/mjtsai.com\/blog\/?p=15845"},"modified":"2018-11-26T14:09:18","modified_gmt":"2018-11-26T19:09:18","slug":"yahoo-says-hackers-stole-data-on-500-million-users-in-2014","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2016\/09\/28\/yahoo-says-hackers-stole-data-on-500-million-users-in-2014\/","title":{"rendered":"Yahoo Says Hackers Stole Data on 500 Million Users in 2014"},"content":{"rendered":"<p><a href=\"https:\/\/yahoo.tumblr.com\/post\/150781911849\/an-important-message-about-yahoo-user-security\">Bob Lord<\/a> (via <a href=\"https:\/\/news.ycombinator.com\/item?id=12559006\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/yahoo.tumblr.com\/post\/150781911849\/an-important-message-about-yahoo-user-security\"><p>A recent investigation by Yahoo has confirmed that a copy of certain user account information was stolen from the company&rsquo;s network in late 2014 by what it believes is a state-sponsored actor. The account information may have included names, email addresses, telephone numbers, dates of birth, hashed passwords (the vast majority with bcrypt) and, in some cases, encrypted or unencrypted security questions and answers.<\/p><\/blockquote>\n\n<p><a href=\"http:\/\/www.nytimes.com\/2016\/09\/23\/technology\/yahoo-hackers.html\">Nicole Perlroth<\/a>:<\/p>\n<blockquote cite=\"http:\/\/www.nytimes.com\/2016\/09\/23\/technology\/yahoo-hackers.html\"><p>Yahoo announced on Thursday that the account information of at least 500 million users was stolen by hackers two years ago, in the biggest known intrusion of one company&rsquo;s computer network.<\/p>\n<p>[&#8230;]<\/p>\n<p>Two years is an unusually long time to identify a hacking incident. According to the Ponemon Institute, which tracks data breaches, the average time it takes organizations to identify such an attack is 191 days, and the average time to contain a breach is 58 days after discovery.<\/p><\/blockquote>\n<p>Via <a href=\"http:\/\/daringfireball.net\/linked\/2016\/09\/22\/yahoo-500m-users-hacked\">John Gruber<\/a>:<\/p>\n<blockquote cite=\"http:\/\/daringfireball.net\/linked\/2016\/09\/22\/yahoo-500m-users-hacked\">\n<p>Verizon, in midst of acquiring Yahoo, <a href=\"http:\/\/www.recode.net\/2016\/9\/22\/13021300\/yahoo-hack-data-breach-500-million-accounts-stolen\">only found out about this two days ago<\/a>.<\/p>\n<\/blockquote>\n\n<p><a href=\"http:\/\/pxlnv.com\/linklog\/yahoo-three-hacks\/\">Nick Heer<\/a>:<\/p>\n<blockquote cite=\"http:\/\/pxlnv.com\/linklog\/yahoo-three-hacks\/\"><p>The massive 2014 breach disclosed today by Yahoo is just one of three reported hacks from the past four years. As <a href=\"http:\/\/pxlnv.com\/linklog\/yahoo-leak\/\">noted previously<\/a>, there was also a 2012 breach of 200 million accounts, and <em>Emptywheel<\/em> has pointed to an <a href=\"https:\/\/twitter.com\/emptywheel\/status\/779063654742368256\">individual account<\/a> hacked earlier this year.<\/p>\n<p>There&rsquo;s something very unsettling about the way tech companies are responding to these big security breaches: none of them informed their users with anything resembling a sense of urgency.<\/p>\n<\/blockquote>\n\n<p><a href=\"http:\/\/macperformanceguide.com\/blog\/2016\/20160923_0730-yahoo-data-breach.html\">Lloyd Chambers<\/a>:<\/p>\n<blockquote cite=\"http:\/\/macperformanceguide.com\/blog\/2016\/20160923_0730-yahoo-data-breach.html\"><p>Yahoo stored unenencrypted user data, including all sorts of personal data that should be stored encrypted, but was not&mdash;gross security incompetence to maintain a dossier on every user.<\/p><\/blockquote>\n\n<p><a href=\"http:\/\/www.nytimes.com\/2016\/09\/29\/technology\/yahoo-data-breach-hacking.html\">Nicole Perlroth and Vindu Goel<\/a> (via <a href=\"https:\/\/twitter.com\/MelanieHannah\/status\/781122116552908800\">Melanie Ehrenkranz<\/a>, <a href=\"https:\/\/tech.slashdot.org\/story\/16\/09\/28\/167241\/yahoo-repeatedly-didnt-invest-in-security-rejected-bare-minimum-measure-to-reset-all-user-passwords-nytimes\">Slashdot<\/a>):<\/p>\n<blockquote cite=\"http:\/\/www.nytimes.com\/2016\/09\/29\/technology\/yahoo-data-breach-hacking.html\"><p>The 2014 hiring of Mr. Stamos &mdash; who had a reputation for pushing for privacy and antisurveillance measures &mdash; was widely hailed by the security community as a sign that Yahoo was prioritizing its users&rsquo; privacy and security.<\/p>\n<p>[&#8230;]<\/p>\n<p>Mr. Stamos and his team had pressed for Yahoo to adopt end-to-end encryption for everything. [&#8230;] Mr. Bonforte said he resisted the request because it would have hurt Yahoo&rsquo;s ability to index and search message data to provide new user services.<\/p>\n<p>[&#8230;]<\/p>\n<p>But when it came time to commit meaningful dollars to improve Yahoo&rsquo;s security infrastructure, Ms. Mayer repeatedly clashed with Mr. Stamos, according to the current and former employees. She denied Yahoo&rsquo;s security team financial resources and put off proactive security defenses, including intrusion-detection mechanisms for Yahoo&rsquo;s production systems. Over the last few years, employees say, the Paranoids have been routinely hired away by competitors like Apple, Facebook and Google.<\/p>\n<p>[&#8230;]<\/p>\n<p>Mr. Stamos, who departed Yahoo for Facebook last year, declined to comment. But during his tenure, Ms. Mayer also rejected the most basic security measure of all: an automatic reset of all user passwords, a step security experts consider standard after a breach. Employees say the move was rejected by Ms. Mayer&rsquo;s team for fear that even something as simple as a password change would drive Yahoo&rsquo;s shrinking email users to other services.<\/p><\/blockquote>\n<p>Update (2016-09-30): <a href=\"https:\/\/www.schneier.com\/blog\/archives\/2016\/09\/the_hacking_of_.html\">Bruce Schneier<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.schneier.com\/blog\/archives\/2016\/09\/the_hacking_of_.html\"><p>I did a bunch of press interviews after the hack, and repeatedly said that &ldquo;state-sponsored actor&rdquo; is often code for &ldquo;please don&rsquo;t blame us for our shoddy security because it was a really sophisticated attacker and we can&rsquo;t be expected to defend ourselves against that.&rdquo;<\/p><p>Well, it turns out that Yahoo! had shoddy security and it was a bunch of criminals that hacked them. <\/p><\/blockquote>\n\n<p>Update (2016-10-03): <a href=\"http:\/\/www.businessinsider.com\/yahoo-insider-hacking-2016-9\">Paul Szoldra<\/a> (via <a href=\"https:\/\/developers.slashdot.org\/story\/16\/10\/01\/0549241\/yahoo-insiders-believe-hackers-could-have-stolen-over-1-billion-accounts\">Slashdot<\/a>):<\/p>\n<blockquote cite=\"http:\/\/www.businessinsider.com\/yahoo-insider-hacking-2016-9\"><p>To be sure, Yahoo has said that the breach affected <em>at least<\/em> 500 million users. But the former Yahoo exec estimated the number of accounts that could have potentially been stolen could&nbsp;be anywhere between 1 billion and 3 billion.<\/p><\/blockquote>\n\n<p>Update (2016-10-04): <a href=\"http:\/\/www.reuters.com\/article\/us-yahoo-nsa-exclusive-idUSKCN1241YT\">Joseph Menn<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=12637126\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"http:\/\/www.reuters.com\/article\/us-yahoo-nsa-exclusive-idUSKCN1241YT\">\n<p>Yahoo Inc last year secretly built a custom software program to search all of its customers&rsquo; incoming emails for specific information provided by U.S. intelligence officials, according to people familiar with the matter.<\/p>\n<p>[&#8230;]<\/p>\n<p>The sources said the program was discovered by Yahoo&rsquo;s security team in May 2015, within weeks of its installation. The security team initially thought hackers had broken in.<\/p>\n<p>When Stamos found out that Mayer had authorized the program, he resigned as chief information security officer and told his subordinates that he had been left out of a decision that hurt users&rsquo; security, the sources said. Due to a programming flaw, he told them hackers could have accessed the stored emails.<\/p>\n<\/blockquote>\n\n<p>Update (2016-10-11): <a href=\"https:\/\/techcrunch.com\/2016\/10\/10\/yahoo-makes-it-difficult-to-leave-its-service-by-disabling-email-forwarding\/\">Sarah Perez<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=12679250\">Hacker News<\/a>, <a href=\"https:\/\/news.slashdot.org\/story\/16\/10\/10\/2142225\/yahoo-disables-automatic-email-forwarding-feature-making-it-difficult-for-users-to-leave\">Slashdot<\/a>):<\/p>\n<blockquote cite=\"https:\/\/techcrunch.com\/2016\/10\/10\/yahoo-makes-it-difficult-to-leave-its-service-by-disabling-email-forwarding\/\">\n<p>At the beginning of October, Yahoo disabled an email forwarding feature, which would allow users to automatically redirect incoming emails sent to their Yahoo address to another account.<\/p>\n<\/blockquote>\n\n<p>Update (2017-01-23): <a href=\"http:\/\/www.macrumors.com\/2017\/01\/23\/yahoo-under-sec-investigation-data-breach\/\">Tim Hardwick<\/a>:<\/p>\n<blockquote cite=\"http:\/\/www.macrumors.com\/2017\/01\/23\/yahoo-under-sec-investigation-data-breach\/\">\n<p>Yahoo is under investigation from the Securities and Exchange Commission over its failure to disclose its massive data breaches sooner, according to <em><a href=\"http:\/\/www.wsj.com\/articles\/yahoo-faces-sec-probe-over-data-breaches-1485133124\">The Wall Street Journal<\/a><\/em>.<\/p>\n<\/blockquote>\n\n<p>Update (2017-10-04): <a href=\"https:\/\/9to5mac.com\/2017\/10\/03\/yahoo-hack-affects-all-accounts\/\">Chance Miller<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=15395946\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/9to5mac.com\/2017\/10\/03\/yahoo-hack-affects-all-accounts\/\">\n<p>Yahoo today has <a href=\"https:\/\/www.sec.gov\/Archives\/edgar\/data\/732712\/000073271217000003\/a2017_10x3xoathxexhibitx991.htm\">disclosed<\/a> that the <a href=\"https:\/\/9to5mac.com\/2016\/12\/14\/yahoo-1-billion-users-hacked\/\">2013 hack initially thought to have affected 1 billion<\/a> accounts actually affected all 3 billion of its user accounts. The company made the announcement in a filling with the SEC&#8230;<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/pxlnv.com\/linklog\/yahoo-three-billion\/\">Nick Heer<\/a>:<\/p>\n<blockquote cite=\"https:\/\/pxlnv.com\/linklog\/yahoo-three-billion\/\">\n<p>If you ignore the press release&rsquo;s spin of what <em>wasn&rsquo;t<\/em> stolen, you&rsquo;ll notice that they omit what <em>was<\/em>: as acknowledged <a href=\"https:\/\/yahoo.tumblr.com\/post\/154479236569\/important-security-information-for-yahoo-users\">previously<\/a>, that includes names, email addresses, MD5 hashed passwords, phone numbers, birthdates, and security questions and answers.<\/p>\n<\/blockquote>\n\n<p id=\"yahoo-says-hackers-stole-data-on-500-million-users-in-2014-update-2018-10-24\">Update (2018-10-24): <a href=\"https:\/\/www.macrumors.com\/2018\/10\/24\/yahoo-agrees-to-settlement-breach\/\">Mitchel Broussard<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.macrumors.com\/2018\/10\/24\/yahoo-agrees-to-settlement-breach\/\">\n<p>In the settlement, Yahoo has agreed to put $50 million into a fund for victims of the breach, provide two years of credit monitoring from AllClear, and a few other benefits for victims. The settlement is still awaiting court approval.<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Bob Lord (via Hacker News): A recent investigation by Yahoo has confirmed that a copy of certain user account information was stolen from the company&rsquo;s network in late 2014 by what it believes is a state-sponsored actor. The account information may have included names, email addresses, telephone numbers, dates of birth, hashed passwords (the vast [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2018-10-24T19:50:57Z","apple_news_api_id":"8aa1e745-dcff-46b3-9e59-88fad40a1ef8","apple_news_api_modified_at":"2018-11-26T19:09:22Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAA==","apple_news_api_share_url":"https:\/\/apple.news\/AiqHnRdz_RrOeWYj61Aoe-A","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[1755,116,882,355,48,86,96,459],"class_list":["post-15845","post","type-post","status-publish","format-standard","hentry","category-technology","tag-breach","tag-flickr","tag-marissa-mayer","tag-privacy","tag-security","tag-verizon","tag-web","tag-yahoo"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/15845","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=15845"}],"version-history":[{"count":14,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/15845\/revisions"}],"predecessor-version":[{"id":23168,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/15845\/revisions\/23168"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=15845"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=15845"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=15845"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}