Home Your IT Home IT Snafu: Don’t be a yahoo by re-using your password!
Get all your tech news delivered to your mail box five days a week
iTWire UPDATE - it's FREE!


The yahoos at Yahoo have let one of its websites be hacked by self-claimed “good” hackers intent only on “exposing” the serious security yahoo-ishness that the yahoos at Yahoo have snafu’d.

Clock this password breach as a seriously silly snafu by the yahoos at Yahoo.

Yes, it’s a security breach that has uncovered serious security missteps at the web’s most famous company starting with Y, leading to questions over exactly Y this snafu has happened.

Y’see, 453,000+ user accounts on a service called “Yahoo Voices” were stored as plain text – they weren’t hashed, re-hashed, salted, peppered or anything – just stored and served up raw by devilishly clever hackers.

The hackers are from a group called “D33Ds Company”, and using a technique known as “union-based SQL injection”, they were able to break into a site with the domain name “dbb1.ac.bf1.yahoo.com” with database command trickery that caused this particular database to divulge far more information than was clearly ever intended.

This, it is said, was from a service called “Associated Content”, a content-farm that Yahoo purchased – and then seemingly went about not properly securing.

Email addresses and passwords from Yahoo, Gmail, Hotmail and other services have been exposed, as the Yahoo Voices platform did not force its users to use an Yahoo user ID, thus potentially exposing more than simply Yahoo customers in this particular breach.

Yahoo’s initial response has been a politically correct statement about only an “older file” being breach, with TechCrunch the first to post the company's note saying: “At Yahoo! we take security very seriously and invest heavily in protective measures to ensure the security of our users and their data across all our products.

“We confirm that an older file from Yahoo! Contributor Network (previously Associated Content) containing approximately 400,000 Yahoo! and other company users names and passwords was stolen yesterday,July 11.  Of these, less than 5% of the Yahoo! accounts had valid passwords.

“We are fixing the vulnerability that led to the disclosure of this data, changing the passwords of the affected Yahoo! users and notifying the companies whose users accounts may have been compromised.  We apologize to affected users.  We encourage users to change their passwords on a regular basis and also familiarize themselves with our online safety tips at security.yahoo.com”, concluded the seriously unserious Yahoos.
What it all means is this: if you use the same password on multiple sites, you’re a yahoo.

It also means that even the biggest sites simply cannot be trusted to secure your password.

So, don’t be a yahoo and use the same password on more than one site, and for goodness sake, make sure that password is long and complicated with letters, numbers and characters.

Finally, if you’re really worried about how the heck you’re going to remember all those passwords, then invest in software like 1Password, while keeping a backup on paper hidden somewhere very, very safe that you’ll a) remember and b) won’t be found by others – like a locked Liberty Safe or some such.

Otherwise your password is one day virtually guaranteed to be exposed by some hacker, somewhere – just as the site “ShouldIChangeMyPassword.com” exposes, with over 10m compromised email addresses already in its database – one which might already include yours!

RECRUITMENT & RETENTION REPORT 2013

HIRE OR FIRE? BUY OR BUILD

2013 is well underway and Australian companies need to know whether they should invest in IT skills training or pay a premium for the people they need.

If you want to know which choices are being made in your sector, what skills are hard to find, which sectors intend to hire or fire and where the IT spend is going, this free report is must have.

GET YOUR REPORT NOW

Alex Zaharov-Reutt

joomla counter

One of Australia’s best-known technology journalists and consumer tech experts, Alex has appeared in his capacity as technology expert on all of Australia’s free-to-air and pay TV networks, including stints as presenter of Ch 10’s Internet Bright Ideas, Ch 7’s Room for Improvement and tech expert on Ch 9’s Today Show, among many other news and current affairs programs.

Connect

http://bs.serving-sys.com/BurstingPipe/adServer.bs?cn=tf&c=19&mc=imp&pli=5460041&PluID=0&ord=[2000]&rtu=-1