A View from Tom Simonite
Yahoo Should Say Whose Data Was Used to Hack Yahoo Mail
Naming the company whose poorly secured data is being used to attack Yahoo Mail accounts could improve online security.
Yahoo warned yesterday that many Yahoo Mail accounts are being targeted by someone with a list of passwords and usernames stolen from another company. Yahoo could help make the Web more secure by naming the source of that “third-party database compromise.”
Naming the company would set a precedent and raise the stakes for those with large userbases. Knowing that your company could be publicly shamed if data from your servers enabled attacks like that on Yahoo Mail would provided added incentive to properly secure username and password databases.
That’s needed because we have evidence that even major technology companies don’t bother to properly secure their passwords, even though password databases are frequently stolen. When 6.5 million passwords were taken from LinkedIn in 2012, decrypted versions were available online a day later because the company’s encryption was relatively weak. The 130 million passwords taken from Adobe in November last year were also discovered to have been improperly secured, in a manner that falls far short of industry best practices.
Better technical solutions to the problem of encrypting passwords do exist and are not prohibitively expensive for such companies. They just seem not to care enough about their customers’ security. That might change if Yahoo was brave enough to say where the data that led to its users having their e-mail accounts targeted came from. Yahoo didn’t respond to a enquiry this morning about the source of that data.