Yahoo says half a billion accounts breached by nation-sponsored hackers

(credit: Photograph by Randy Stewart)

At least half a billion Yahoo accounts have been breached by what investigators believe is a nation-sponsored hacking operation. Attackers probably gained access to a wealth of holders’ personal information, including names, e-mail addresses, phone numbers, birth dates, answers to security questions, and cryptographically protected passwords.

Yahoo Chief Information Security Officer Bob Lord dropped that bombshell announcement on Thursday afternoon, several hours after news site Recode reported the company was poised to disclose a compromise affecting several hundred million accounts. With at least 500 million accounts included in Yahoo’s official statement, the breach is among the biggest ever to hit a single Web property.

“We have confirmed, based on a recent investigation, that a copy of certain user account information was stolen from our networks in late 2014 by what we believe is a state-sponsored actor,” Lord wrote. “The account information may have included names, e-mail addresses, telephone numbers, dates of birth, hashed passwords (the vast majority with bcrypt), and, in some cases, encrypted or unencrypted security questions and answers.”

Read 8 remaining paragraphs | Comments

Technology Lab – Ars Technica

Google weakens Allo privacy promises

This should save Google some headaches: Allo messages will be accessible to law enforcement with warrants, unlike with apps like WhatsApp.
Naked Security – Sophos

Cisco says router bug could be result of ‘cosmic radiation’ … Seriously?

A Cisco bug report addressing “partial data traffic loss” on the company’s ASR 9000 Series routers contends that a “possible trigger is cosmic radiation causing SEU soft errors.”

Cosmic radiation? While we all know that cosmic radiation can wreak havoc on electronic devices, there’s far less agreement as to the likelihood of it being the culprit in this case. Or that Cisco could know one way or the other.

A reader of Reddit’s section devoted to networking asks the question: “Has anyone ever seen ‘cosmic radiation’ as a cause for software errors in a bug report before? The ‘fix’ is to reload the line card. This did resolve the issue in our case. Anybody else experience this?”

To read this article in full or to leave a comment, please click here

Network World Paul McNamara

Rand Study: Average Data Breach Costs $200K, Not Millions – Dark Reading

Rand Study: Average Data Breach Costs $ 200K, Not Millions
Dark Reading
"We find that the typical cost of a data breach is less than $ 200,000, far lower than the millions of dollars often cited in surveys (e.g. Ponemon 2015)," writes Sasha Romanosky, author of the Rand study, Examining the costs and causes of cyber

“data breach” – Google News