<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Hackers take Yahoo: 453,000 login credentials&#160;nabbed</title>
	<atom:link href="http://boingboing.net/2012/07/11/hackers-take-yahoo-453000-lo.html/feed" rel="self" type="application/rss+xml" />
	<link>http://boingboing.net/2012/07/11/hackers-take-yahoo-453000-lo.html</link>
	<description>Brain candy for Happy Mutants</description>
	<lastBuildDate>Thu, 23 May 2013 20:17:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: robuluz</title>
		<link>http://boingboing.net/2012/07/11/hackers-take-yahoo-453000-lo.html#comment-1476051</link>
		<dc:creator>robuluz</dc:creator>
		<pubDate>Fri, 13 Jul 2012 03:51:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=170749#comment-1476051</guid>
		<description>I was with you right up until you stopped talking about what a good joke it was.</description>
		<content:encoded><![CDATA[<p>I was with you right up until you stopped talking about what a good joke it was.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cowicide</title>
		<link>http://boingboing.net/2012/07/11/hackers-take-yahoo-453000-lo.html#comment-1475259</link>
		<dc:creator>Cowicide</dc:creator>
		<pubDate>Thu, 12 Jul 2012 17:47:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=170749#comment-1475259</guid>
		<description>Thank goodness for &lt;a href=&quot;https://agilebits.com/onepassword&quot; rel=&quot;nofollow&quot;&gt;1Password&lt;/a&gt;.  I just have to know one ridiculously complex password for that to keep track of all my other passwords.  Stuff like this happening is why I don&#039;t like the idea of keeping all my credentials in one place &quot;in the cloud&quot; with some multi-service thing.  One services fails then many others may go down with it.</description>
		<content:encoded><![CDATA[<p>Thank goodness for <a href="https://agilebits.com/onepassword" rel="nofollow">1Password</a>.  I just have to know one ridiculously complex password for that to keep track of all my other passwords.  Stuff like this happening is why I don&#8217;t like the idea of keeping all my credentials in one place &#8220;in the cloud&#8221; with some multi-service thing.  One services fails then many others may go down with it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cowicide</title>
		<link>http://boingboing.net/2012/07/11/hackers-take-yahoo-453000-lo.html#comment-1475257</link>
		<dc:creator>Cowicide</dc:creator>
		<pubDate>Thu, 12 Jul 2012 17:44:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=170749#comment-1475257</guid>
		<description>It still might not be &quot;that&quot; bad...

FTA:&lt;blockquote&gt;only about 5 percent of the exposed credentials were still valid on Yahoo&lt;/blockquote&gt;

According to Yahoo in that article, at least.</description>
		<content:encoded><![CDATA[<p>It still might not be &#8220;that&#8221; bad&#8230;</p>
<p>FTA:<br />
<blockquote>only about 5 percent of the exposed credentials were still valid on Yahoo</p></blockquote>
<p>According to Yahoo in that article, at least.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dragonfrog</title>
		<link>http://boingboing.net/2012/07/11/hackers-take-yahoo-453000-lo.html#comment-1475209</link>
		<dc:creator>dragonfrog</dc:creator>
		<pubDate>Thu, 12 Jul 2012 16:51:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=170749#comment-1475209</guid>
		<description> Probably but not guaranteed - has anyone seen the password dump?  How strong are the passwords?  It could be that the passwords they posted as plaintext are simply those that were weak enough to rapidly crack the hashes.</description>
		<content:encoded><![CDATA[<p> Probably but not guaranteed &#8211; has anyone seen the password dump?  How strong are the passwords?  It could be that the passwords they posted as plaintext are simply those that were weak enough to rapidly crack the hashes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: teapot</title>
		<link>http://boingboing.net/2012/07/11/hackers-take-yahoo-453000-lo.html#comment-1475153</link>
		<dc:creator>teapot</dc:creator>
		<pubDate>Thu, 12 Jul 2012 15:40:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=170749#comment-1475153</guid>
		<description>lol their announcement page is down because of the traffic volume. Lucky there&#039;s always BT.

*opening*

*checking*

OK I don&#039;t think there&#039;s a lot for users to worry about as (I believe) these are only email/PW combinations to use the Yahoo Voice whatever-it-is, NOT login details for email inboxes themselves. All of the email/PW combos I tried didn&#039;t work (except one on Yahoo that said I hadn&#039;t signed into my email in a while). The only users at risk are ones that actually USE Yahoo mail.... plus users who use the same PW across several accounts which means they&#039;re asking for it anyway :)

There&#039;s a few US military emails in there... let&#039;s see how effective they are at creating strong passwords. First 15 on  the list: maestero, emanuel, pat727rod850, portal55, a&#064;rron76 , pokemon, soccerba11, annieruth60, 153125, daniela, employment, monkey23, armani1, 12snooks34, ljm*8702
Conclusion: mostly terrible

bcsizemo: I believe a majority of attack still use SQL injection. Wordpress installations was getting screwed over a few months ago.</description>
		<content:encoded><![CDATA[<p>lol their announcement page is down because of the traffic volume. Lucky there&#8217;s always BT.</p>
<p>*opening*</p>
<p>*checking*</p>
<p>OK I don&#8217;t think there&#8217;s a lot for users to worry about as (I believe) these are only email/PW combinations to use the Yahoo Voice whatever-it-is, NOT login details for email inboxes themselves. All of the email/PW combos I tried didn&#8217;t work (except one on Yahoo that said I hadn&#8217;t signed into my email in a while). The only users at risk are ones that actually USE Yahoo mail&#8230;. plus users who use the same PW across several accounts which means they&#8217;re asking for it anyway :)</p>
<p>There&#8217;s a few US military emails in there&#8230; let&#8217;s see how effective they are at creating strong passwords. First 15 on  the list: maestero, emanuel, pat727rod850, portal55, a&#064;rron76 , pokemon, soccerba11, annieruth60, 153125, daniela, employment, monkey23, armani1, 12snooks34, ljm*8702<br />
Conclusion: mostly terrible</p>
<p>bcsizemo: I believe a majority of attack still use SQL injection. WordPress installations was getting screwed over a few months ago.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bcsizemo</title>
		<link>http://boingboing.net/2012/07/11/hackers-take-yahoo-453000-lo.html#comment-1475001</link>
		<dc:creator>bcsizemo</dc:creator>
		<pubDate>Thu, 12 Jul 2012 12:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=170749#comment-1475001</guid>
		<description>Like someone posted on Ars a lot of these email accounts aren&#039;t just limited to Yahoo.  But that makes me wonder if they are just linked to the Yahoo account, just like you can link other email accounts into GMail.  The plaintext part bothers me, but I&#039;m more concerned with an SQL injection attack...I though those kinds of things died out years ago.  (Perhaps Ars was simplifying it all for the readers?) </description>
		<content:encoded><![CDATA[<p>Like someone posted on Ars a lot of these email accounts aren&#8217;t just limited to Yahoo.  But that makes me wonder if they are just linked to the Yahoo account, just like you can link other email accounts into GMail.  The plaintext part bothers me, but I&#8217;m more concerned with an SQL injection attack&#8230;I though those kinds of things died out years ago.  (Perhaps Ars was simplifying it all for the readers?) </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: traalfaz</title>
		<link>http://boingboing.net/2012/07/11/hackers-take-yahoo-453000-lo.html#comment-1474994</link>
		<dc:creator>traalfaz</dc:creator>
		<pubDate>Thu, 12 Jul 2012 11:56:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=170749#comment-1474994</guid>
		<description>The fact that they posted plaintext passwords means that Yahoo had plaintext passwords on file.  This, in turn, means that Yahoo has no idea what they&#039;re doing when it comes to security.  You do NOT store plaintext passwords.
Incompetence at Yahoo is really no surprise though.</description>
		<content:encoded><![CDATA[<p>The fact that they posted plaintext passwords means that Yahoo had plaintext passwords on file.  This, in turn, means that Yahoo has no idea what they&#8217;re doing when it comes to security.  You do NOT store plaintext passwords.<br />
Incompetence at Yahoo is really no surprise though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: penguinchris</title>
		<link>http://boingboing.net/2012/07/11/hackers-take-yahoo-453000-lo.html#comment-1474913</link>
		<dc:creator>penguinchris</dc:creator>
		<pubDate>Thu, 12 Jul 2012 09:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=170749#comment-1474913</guid>
		<description>It&#039;s a good joke, but Flickr accounts require a Yahoo account so even a lot of tech-savvy people have Yahoo accounts they regularly use... including e.g. Cory Doctorow who posts photos to his account regularly (and myself).

But if it was Yahoo Voice that was compromised as petsounds reports below, well, I have no idea what Yahoo Voice is or who its users are but the crossover with Flickr users is probably pretty small :)</description>
		<content:encoded><![CDATA[<p>It&#8217;s a good joke, but Flickr accounts require a Yahoo account so even a lot of tech-savvy people have Yahoo accounts they regularly use&#8230; including e.g. Cory Doctorow who posts photos to his account regularly (and myself).</p>
<p>But if it was Yahoo Voice that was compromised as petsounds reports below, well, I have no idea what Yahoo Voice is or who its users are but the crossover with Flickr users is probably pretty small :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marc Mielke</title>
		<link>http://boingboing.net/2012/07/11/hackers-take-yahoo-453000-lo.html#comment-1474866</link>
		<dc:creator>Marc Mielke</dc:creator>
		<pubDate>Thu, 12 Jul 2012 06:52:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=170749#comment-1474866</guid>
		<description>Hey! They still have decent p0rn groups...or so I&#039;ve heard....from some totally not-me people!</description>
		<content:encoded><![CDATA[<p>Hey! They still have decent p0rn groups&#8230;or so I&#8217;ve heard&#8230;.from some totally not-me people!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: petsounds</title>
		<link>http://boingboing.net/2012/07/11/hackers-take-yahoo-453000-lo.html#comment-1474850</link>
		<dc:creator>petsounds</dc:creator>
		<pubDate>Thu, 12 Jul 2012 05:47:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=170749#comment-1474850</guid>
		<description>Kevin Mitnick is saying on Twitter that the service compromised was Yahoo Voice.</description>
		<content:encoded><![CDATA[<p>Kevin Mitnick is saying on Twitter that the service compromised was Yahoo Voice.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: robuluz</title>
		<link>http://boingboing.net/2012/07/11/hackers-take-yahoo-453000-lo.html#comment-1474847</link>
		<dc:creator>robuluz</dc:creator>
		<pubDate>Thu, 12 Jul 2012 05:38:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=170749#comment-1474847</guid>
		<description>&lt;blockquote&gt;To support their claim, the hackers posted what they said were the plaintext credentials for 453,492 Yahoo accounts.&lt;/blockquote&gt;Luckily, none of the accounts had been used since 1998.</description>
		<content:encoded><![CDATA[<blockquote><p>To support their claim, the hackers posted what they said were the plaintext credentials for 453,492 Yahoo accounts.</p></blockquote>
<p>Luckily, none of the accounts had been used since 1998.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: workin</title>
		<link>http://boingboing.net/2012/07/11/hackers-take-yahoo-453000-lo.html#comment-1474844</link>
		<dc:creator>workin</dc:creator>
		<pubDate>Thu, 12 Jul 2012 05:30:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=170749#comment-1474844</guid>
		<description>Hmm, mom recently passed and took her password with. Tried getting in, nope, maybe they d33ds got it for me-seems the D co didn&#039;t secure there own stuff because they got all their own info posted by another&#039;s SQL attack - circlejerk</description>
		<content:encoded><![CDATA[<p>Hmm, mom recently passed and took her password with. Tried getting in, nope, maybe they d33ds got it for me-seems the D co didn&#8217;t secure there own stuff because they got all their own info posted by another&#8217;s SQL attack &#8211; circlejerk</p>
]]></content:encoded>
	</item>
</channel>
</rss>
