Slashdot Mirror


Yahoo Repeatedly Didn't Invest In Security, Rejected Bare Minimum Measure To Reset All User Passwords: NYTimes

If it wasn't already enough that the mega breach at Yahoo affects over 500 million users, a new investigative report on The New York Times states the extent to which Yahoo didn't care about its users' security (Editor's note: the link could be paywalled; alternate source). The report says Yahoo CEO Marissa Mayer refused to fund security initiatives at the company, and instead invested money in features and new products. Despite Edward Snowden warning Yahoo that it was too easy of a target for hackers, the company took one year to hire a new chief information officer. The company hired Alex Stamos, who is widely respected in the industry. But Stamos soon left partly due to clashes with Mayer, The Times adds. And it gets worse. From the report:But when it came time to commit meaningful dollars to improve Yahoo's security infrastructure, Ms. Mayer repeatedly clashed with Mr. Stamos, according to the current and former employees. She denied Yahoo's security team financial resources and put off proactive security defenses, including intrusion-detection mechanisms for Yahoo's production systems. [...] But during his tenure, Ms. Mayer also rejected the most basic security measure of all: an automatic reset of all user passwords, a step security experts consider standard after a breach. Employees say the move was rejected by Ms. Mayer's team for fear that even something as simple as a password change would drive Yahoo's shrinking email users to other services.

36 of 129 comments (clear)

  1. Bad CEO is bad by networkBoy · · Score: 3, Insightful

    topic says it all...

    --
    whois gawk date unzip strip find touch finger mount join nice man top fsck grep eject more yes exit umount sleep dump
    1. Re:Bad CEO is bad by elrous0 · · Score: 5, Funny

      Perhaps you missed the fact that this CEO is a *WOMAN*, which makes her a hero and an inspiration.

      This is somehow all the evil male patriarchy's fault.

      --
      SJW: Someone who has run out of real oppression, and has to fake it.
    2. Re: Bad CEO is bad by Luthair · · Score: 3, Informative

      She ended up with a couple hundred million so...

    3. Re:Bad CEO is bad by Oswald+McWeany · · Score: 2

      She is heroically bad and an inspiration to all people achieving mediocrity in management.

      --
      "That's the way to do it" - Punch
    4. Re:Bad CEO is bad by gweihir · · Score: 2

      Indeed. She should go to prison and personally have to compensate anybody who suffered damage from her criminal acts.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  2. Short sighted by sjbe · · Score: 5, Funny

    Employees say the move was rejected by Ms. Mayer's team for fear that even something as simple as a password change would drive Yahoo's shrinking email users to other services.

    At my company we call this "stepping over a dollar to pick up a nickel".

    1. Re:Short sighted by houstonbofh · · Score: 2

      Actually this is called "risk assessment." It was just badly done and very public risk assessment. Along the lines of Ford Pinto bad...

    2. Re:Short sighted by Anonymous Coward · · Score: 2, Informative

      In England they call this "penny wise, pound foolish".

    3. Re:Short sighted by Oswald+McWeany · · Score: 4, Funny

      Mine will hire an outside contractor to pick up both for $20- and then let them keep the dollar and the nickel.

      --
      "That's the way to do it" - Punch
    4. Re:Short sighted by losfromla · · Score: 2

      That would explain MY employer's (major defense contracting corporation) incredible increase in profitability lately.

      --
      Only I can judge you.
  3. So Where Was the Board? by Jawnn · · Score: 2

    Surely, the board of directors at Yahoo had someone that they listened to when it came to security issues that had the potential to affect the profitability and viability of the company. Right? I mean, after all, that's a board's job, to see to those two things. [/heavy sarcasm]

    1. Re:So Where Was the Board? by phantomfive · · Score: 4, Insightful

      Why do you think this will affect profitability? Did LinkedIn become less profitable when they leaked everyone's user accounts? Or did everyone just forget about that and move on?

      --
      "First they came for the slanderers and i said nothing."
    2. Re:So Where Was the Board? by PCM2 · · Score: 5, Insightful

      Well, for starters, LinkedIn only leaked data for around 6 million accounts. Yahoo leaked data for half a billion accounts. Also, considering that people use Yahoo for their personal email and to track their finances, the data on Yahoo was potentially much more sensitive than anything on LinkedIn.

      --
      Breakfast served all day!
  4. Buh-bye... by Aaden42 · · Score: 2

    Finally deleted my Yahoo & Flickr accounts today. Nothing of value was lost...

  5. yahoo made me change my password by Anonymous Coward · · Score: 3, Interesting

    They did it twice in recent memory. One time was in 2015 and came out of the blue, possibly as a result of this hack.

    Honestly, I don't think passwords are the bigger thing here. When my password was compromised as part of the Gawker leak, Yahoo locked down their system so that you couldn't log into accounts from new IPs. You had to change your password from an IP you've used before before you could log in again.

    Getting hacked (seemingly phished) was really bad. Having a system where people in the company can give away this data is also really bad. Not resetting everyone's password seems kind of small potatoes next to all that.

  6. Mayer 2020? by OverlordQ · · Score: 3, Insightful

    Maybe she'll go the route of Carly Fiorina and after she's done running companies into the ground she'll try at politics.

    --
    Your hair look like poop, Bob! - Wanker.
    1. Re:Mayer 2020? by aaarrrgggh · · Score: 3, Interesting

      In fairness, yahoo was almost a lost cause when she came on board, while Carly...

      Not quite sure if anything could have been done to save them. They lacked meaningful sources of profit, and improving efficiency would not be enough. I think Mayer realized that the spinoff was the only hope when they unveiled the new logo. Just took too long to execute.

  7. lawsuits by XparXnoiaX · · Score: 2

    I've said it before, but these companies need to be sued into the ground. It's the only way things will ever change.

    --
    Irresponsible disclosure is responsible
    1. Re:lawsuits by Oswald+McWeany · · Score: 2, Insightful

      On the surface it sounds good; but if companies get sued for being hacked then more people will try hacking companies that piss them off (or in some cases maybe who are rivals).

      Get fired? Hack your employer so that they get sued as payback. Rival kicking your arse? Hire some Russian miscreants to hack them.

      --
      "That's the way to do it" - Punch
  8. Not a surprise by ErichTheRed · · Score: 5, Interesting

    Not one organization I have ever worked for has seriously cared about IT security. The second anyone mentions security, the next question is how much it costs. So I don't think it's a Yahoo thing - I think it happens everywhere. Even banks and healthcare companies, who have some of the most regulated data in the world don't go beyond lip service and a few token defenses to protect it. Companies will continue to offshore vital functions to companies that don't care what happens to data. They'll also continue to ignore key parts of new product development relating to security. I think one of the problems is that IT security guys can't articulate this to executives. They're either from the physical security world, or they're so tech-focused that they can't give a coherent presentation to people who only understand what dollars are.

    Companies have insurance, and it's always cheaper to say "oops" and give out free credit monitoring for a year than it is to build a serious defense against security breaches. Until it becomes too expensive to ignore, whether in the form of lost business, fines or lost intellectual property, nothing will change.

    1. Re:Not a surprise by pr0fessor · · Score: 4, Interesting

      We take security seriously where I work and have good security practices... That being said there are still management types who always want to find a loophole because being secure is to burdensome. They want to share logins, have password that never expire, put data on unencrypted thumb drives, etc...

      I usually just remind them that many of our clients want third parties to certify our security practices and if we can't keep that up we will not have clients and they can debate security all they want on the unemployment line.

    2. Re: Not a surprise by Anonymous Coward · · Score: 2

      Passwords that do not expire
      are not a problem. It is when
      the hashed passwords and the
      salts are exfiltrated that you have
      screwed up.

      I have passwords that are over
      ten years old. Resetting your
      password every x days is nothing
      but security theater.

      You do not need need to force
      a password reset until you are
      fairly suspicious that the breach
      has occurred. Or definitely know.

      Yahoo knew. This is epic fail.

    3. Re:Not a surprise by lgw · · Score: 5, Insightful

      Forcing users to change passwords regularly is a security anti-pattern. It produces lower security overall. It's something IT does to express their loathing of the userbase, not a security practice.

      Make users change passwords when there's evidence of a breach, and only then.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    4. Re:Not a surprise by pr0fessor · · Score: 3, Interesting

      Forcing users to change passwords regularly is a security anti-pattern. It produces lower security overall.

      That may be true if not for all the other things users do.

      I've disabled a manager's credential because I was sure they had shared them with someone they shouldn't even though I warned them not to previously and I found the log in had been used on that user's company device after they had been terminated under very bad circumstances. Needless to say everyone was pissed at me and raised a big stink but as soon as I mentioned a disgruntled ex-employee may have access to that account and why they had no problem listening.

      On a fun note someone (possibly the same disgruntled ex-employee) called up every plastic surgeon in about 500 miles and made an appoint for one our managers to have a consultation about breast enlargements.

    5. Re:Not a surprise by Sassinak · · Score: 2

      Security has always been paid lip service because everyone assumes "it won't happen to me" until it does.. so its very difficult to get a CEO to sign off on a few thousand dollars on something that MAY happen (ironically they will purchase insurance and support contracts under the notion that IF something happens they are covered) Since I work in security and its always an issue.. the world is dangerous and since the laws allow them to, as you said.. "opps", wright off the breach as a loss on the taxes, pass on any costs incurred to the consumer, and keep on moving, there is really no incentive for them to actually DO anything.

      --
      God made the Idiot for practice, and then He made the School Board -- Mark Twain Look for http://Thebar.steelbeachca
    6. Re:Not a surprise by Anonymous Coward · · Score: 2, Informative

      One password is a simple to change. A hundred passwords becomes a big deal. Throw in a random grab bag of retention and password complexity rules and you end up with pissed off users. Pissed off users write passwords down, email them, and other problematic behavior to cope.

  9. This oughta help sell Yahoo... by MitchDev · · Score: 2

    Great PR move guys!

  10. I didn't think she was bad by Anonymous Coward · · Score: 3, Interesting

    I mean, I maybe she could do better, but usually you wouldn't call a person who took command of the Titanic as it scraped the iceberg a bad captain.

    But, apparently, she deliberately kept going full speed through a cluster of icebergs and ignored all hits. That's pretty damn bad.

  11. Amazing by LichtSpektren · · Score: 4, Funny

    It's in fact possible to be even less competent than Meg Whitman and Carly Fiorina.

  12. But just like Mylan by ThatsNotPudding · · Score: 3, Insightful

    But just like the Mylan CEO and Martin Shkreli; nothing, nothing, NOTHING of any import will happen to Marissa Myer.

    Just as morality doesn't apply to the 1%, neither does laws of the 99%.

    1. Re:But just like Mylan by Anonymous Coward · · Score: 3, Insightful

      The ex-CEO of Tyco, Dennis Kozlowski, served eight years in prison. My guess the whole time he was in there he was constantly shouting "WTF!" as various CEO's came and went unscathed for frauds much larger than his...

  13. The invisible hand strikes. by Ungrounded+Lightning · · Score: 4, Interesting

    Not one organization I have ever worked for has seriously cared about IT security.

    When it comes to rolling out new products, ignoring security is the norm.

    This is because the "window of opportunity" is only "open" for a short time - until the first, second, and maybe third movers go through it and grab most of the potential customers. Companies that spent the time to get the security right arrive at the window after it closes.

    This happens anywhere the customers don't test for and reject non-secure versions of the "new shiny" - which means enterprises sometimes hold suppliers' feet to the fire (if the new thing doesn't give them an advantage commensurate with, or perceived as outweighing, the risk) but consumer stuff goes out wide open.

    Then, if you're lucky and the supplier is clueful, they retrofit SOME security before the bad guys exploit enough holes to kill them.

    I expect this will continue until several big-name tech companies get an effective corporate death penalty in response to the damages their customer base took from their security failings. Then the financial types will start including having a good, and improving with time, security story (no doubt called "best practices") among their check boxes for funding.

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
  14. Re:Whhooogiffafuckina shittafuckle by Farmer+Tim · · Score: 2

    Thanks for quoting Marissa Mayer's comments on security spending, but next time please attribute it correctly.

    --
    Blank until /. makes another boneheaded UI decision.
  15. Clawback by h8sg8s · · Score: 2

    Marissa Mayer should be required to forgo all her pay and bonuses for the period when she refused to fund realistic security measures. She ran Yahoo! into the ground and will be richly rewarded for doing so. Great work if you can get it..

    --
    Organization? You must be joking..
  16. Re:Goal-focused CEO by losfromla · · Score: 2

    Except that he's not a moron and would not be assuaged by something that any fool could clearly see as a delaying tactic. They hired him for his expertise, people like him know what they know and he clearly had not just fallen off the turnip truck when he landed at "Yahoo!"

    --
    Only I can judge you.
  17. Re:Goal-focused CEO by ArmoredDragon · · Score: 2

    I've had a company I've worked for (contract work) as desktop support where I've complained loudly about atrocious security and nobody gave a shit. In fact, they had no plan in place at all for handling a breach, and there wasn't even somebody I could contact in the event of one, which I found out when we I noticed that we had a breach (and when I mentioned it to the system engineers, none of them seemed to care.) The only thing I could do was just let it go because the network engineers didn't want to add any kind of short term filtering as that would mean they would have to do some work, which was a thing they particularly hated doing.

    I suspect that if I was a manager or otherwise in a position where I had power, I probably never would have been given the budget to address any of the security concerns.

    As soon as the 90 days was up I just left and never looked back.