What a spectacular mess, Yahoo. At least 500 million accounts across your myriad services have been hacked. Data ranging from phone numbers to date of birth, email addresses, phone numbers and security questions (but, mercifully, not decrypted passwords) have been in the hands of black hats for not a day, a week or even a month, but five months or more.
SEE ALSO:If you use any Yahoo services, here's what to do following the massive breachYou left us all hanging out there is the wind for FOUR MONTHS, Yahoo. What the hell?!
The exclamation point at the end of the company's official name is supposed to symbolize action, but what Yahoo did over the past four months is the opposite of action.
They waited and wondered and left all of us holding the hacked data bag. For that reason, Yahoo forfeits the exclamation point.
You left us all hanging out there is the wind for FOUR MONTHS, Yahoo. What the hell?!
If, upon learning this Yahoo data breach news you are not as outraged as I am, you should be. Yahoo is a vast collection of sites and services including Yahoo Mail, Flickr, Tumblr, domains through Yahoo Aabaco Small Business, Yahoo Finance, Yahoo Messenger and more. Suffice to say, if you have 500 million users, you’re big and the impact of a data breach is potentially massive.
Even if your various Yahoo accounts show no signs of a breach, that doesn’t mean they weren’t hacked or that the information has not been used. People with your name, phone number, date of birth and answers to your security questions(!) could have enough to do some triangulation and certainly have engaged in some identity theft by now. Again, you might have a disreputable doppelgänger somewhere and not even know it. The key to good identity theft is to create fake profiles of people and do just enough to not get caught, but still make it profitable for the identity thief.
Also, even if you haven’t used many of your Yahoo services in a while, if the data in the breach is accurate, you’re still at risk.
Before you or I go any further, though, let’s pause a moment to change all of our freaking Yahoo passwords.
Okay. With that all done, we can dive into the other burning questions.
Why did Yahoo wait all these months to confirm that the data was real?
Back in June, reports emerged that the data for as many as 200 million Yahoo accounts was for sale on the Dark Web. A hacker ironically named “Peace” claimed responsibility and, according to The Hacker News, was selling it all for 3 bitcoins (almost $2,000).
Opening up about the hack might have derailed its long sought strategic exit.
Yahoo acknowledged the existence of the possible breach, but would not verify that the data was in fact theirs (or, really, ours). In a way, I can understand why Yahoo didn’t come right out and say they were hacked. Opening up about the hack might have derailed its long sought strategic exit.
Back in March, Yahoo set a deadline for all suitors interested in snapping up its web and associated businesses. By the spring, the field had narrowed with Verizon leading the pack. Yahoo closed the $4.83 billion deal with Verizon in late July, a little more than a month after news first broke of the Peace Hack and Yahoo’s potential connection.
Revealing publicly that all that data (and more) was actually there could have potentially derailed the deal or at least delayed it significantly. I wouldn’t expect anyone to actually back out of a deal with a company that’s been hacked. If that were the benchmark for deal-making, it’s unlikely any deals would be made.
In Thursday’s Yahoo press release on the massive data breach, it repeatedly calls the investigation “ongoing,” as if to say, “We couldn’t notify you because the authorities hadn’t actually figured it out yet."
I don’t buy this. The data was out there on the Dark Web for months and simply had to be matched against Yahoo’s own actual user data -- a match that probably could have been made in hours or at least days. Even if it took weeks, does anyone believe it would have taken as many as 16 weeks?
In the same release, Yahoo also seems to try and hide behind a “this is happening everywhere defense.” It’s true, cyber hacking is nearing epidemic and scary proportions. Yahoo also claims to be proactive, saying that it’s had a program in place since late last year to detect when a “state-sponsored actor has targeted an account.” So far, they have notified 10,000 users of such attempts.
This little bit of self-congratulatory detail, though, is all the more galling when compared to the half a billion Yahoo customers who have not, until now, been notified.
I asked founder and CEO of Cybersecurity Ventures Steven Morgan if I was being unfair to Yahoo. "In my opinion it took four months for Yahoo! to think about how to deal with the reputational damage that comes with the hack. They should have a good PR plan by now," he wrote in an email.
Let this serve as a warning to all other sites and online services that have not stepped forward to claim hacked data on the Dark Web as their own. “The investigation is ongoing” is not an excuse. We demand an abundance of caution. Tell us even when there’s the smallest possibility you were hacked and recommend we change our passwords today. We’ll complain, be annoyed and drag our heels, but we will act and, some day, thank you.
TopicsCybersecurityYahoo
(责任编辑:焦點)
'Rocket League' Championship Series Season 2 offers $250,000 prize pool
Rocket League。's competitive scene is just getting started. 。The。 Rocket League。Championship Series i
...[详细]
小孩子的身體發育還不夠完善
,在成長的過程當中總會患上感冒,發燒這樣的疾病,最讓家長難受的事情就是在給小孩吃了退燒要之後被孩子給吐了出來 ,看著孩子哭鬧的樣子既無奈也心疼
,對於這樣的情況除了要給小孩補吃藥
...[详细]
山藥中含有大量的澱粉
,所以烹飪時間較長的山藥
,吃起來口感軟糯
,就算是牙口不好的人也不在話下
。與此同時最常見的山藥做法莫過於山藥排骨湯
,因為山藥排骨湯融合了山藥與排骨的味道,讓湯羹變得更加鮮美,營養價值
...[详细]
牛肉是生活中比較常見的肉類之一,這和普通的豬肉相比牛肉中的營養會更加的豐富一點。而且在用於烹飪中牛肉的口感相對也會更好一點,營養價值也是非常高的。在很多營養的食物搭配中牛肉也是必不可少的,所以還是要注
...[详细]U.S. government issues warning on McDonald's recalled wearable devices
Last week's McDonald's debacle, which saw the fast food giant forced to recall its first wearable tr
...[详细]
很多人因為內分泌的問題可能會導致皮膚出現痘痘,像這種情況一定要結合個人的皮膚狀態來針對性的治療和調理。嘴唇旁邊長痘痘的原因是比較多的內分泌失調,並不是絕對性因素也不是唯一的原因,所以治療的時候要考慮其
...[详细]
內分泌失調是臨床上的常見問題,很多人都有內分泌失調的問題
,尤其是女性內分泌失調是非常常見的,而且女性內分泌失調的影響也是體現在多方麵的
,所以要注意調理,目前臨床上很多人針對內分泌失調是通過藥物來進行調
...[详细]
女性朋友往往都會對胸部健康問題非常關注 ,因為近幾年來乳腺癌疾病的發病概率正在逐漸增加,也成為了危害女性身體健康的一個嚴重問題
。例如胸部脹痛就是在不少女性身體上都會發生的一種問題 ,除了胸部脹痛之外
,也有
...[详细]Did our grandparents have the best beauty advice?
Do our grandparents really know what's best?They're older and wiser, and they have no shortage of ad
...[详细]
複方甘草酸苷片這是屬於一種治療藥物
,在服用之前就需要先經過醫生的同意,尤其是孕婦麽,盡量的不要去吃些對於孕婦們有害的藥物,這是會使得胎兒出現胎位不穩的情況,一定要謹慎用藥
,就算是病情很嚴重也應該要多使
...[详细]