Yahoo Loses 453,000 User Passwords to Hackers
July 12, 2012 4:45 PM
comment(s) - last by
Hackers say data was posted as a warning
) all over again!
Hackers with "D33ds Company" have posted 453,000 passwords from Yahoo! Inc.'s (
) Voices -- a part of its news service. Bafflingly, Yahoo administrators apparently opted for no encryption of the passwords, storing them in plain-text.
Hackers scooped up the passwords using
The hackers write on their text dump:
We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call, and not as a threat. There have been many security holes exploited in Web servers belonging to Yahoo! Inc. that have caused far greater damage than our disclosure. Please do not take them lightly.
They were at least kind enough not to publish details of how the penetrated Yahoo's servers.
Some of the 453,000 compromised accounts. [Image Source: TrustedSec]
Yahoo insists that it's not that big a deal, saying that only 5 percent of the user passwords would pass as valid passwords on its other sites, hence most users day-to-day passswords were likely not compromised.
It does apologize, though, for the inconvenience,
At Yahoo! we take security very seriously and invest heavily in protective measures to ensure the security of our users and their data across all our products. We are fixing the vulnerability that led to the disclosure of this data, changing the passwords of the affected Yahoo! users and notifying the companies whose users accounts may have been compromised.
Multiple military and government email addresses were found among the users with leaked passwords.
This article is over a month old, voting and posting comments is disabled
RE: was I on the list ...
7/13/2012 10:09:13 AM
It would have been nice to check, I've already changed mine, but again, only use it for spam.
But I don't buy the hackers BS line about a wake up call to Yahoo. They could have grabbed the info and not posted it, but instead they want to potentially hurt other users. I have no problem with "security researchers" who can compromise a system and then let the company and public know. But by dumping proprietary info onto the internet, they're now aholes. Track them down and prosecute.
RE: was I on the list ...
7/13/2012 10:41:28 AM
pfff, you think that any of these companies will listen to somebody sending them a polite little email informing them of their own incompetence? The only thing most big tech corporations respond to in the way of security is public embarrassment.
Bottom line is that Yahoo is the one who posted the passwords by storing them in plain text.
"It seems as though my state-funded math degree has failed me. Let the lashings commence." -- DailyTech Editor-in-Chief Kristopher Kubicki
Nokia is the Victim of SQL Injection, Loses Developer Records
August 29, 2011, 8:37 AM
LulzSec Strikes Again, 1M Sony Pictures User Accounts Compromised
June 2, 2011, 6:27 PM
FCC Orders Advertisers to Cut Out That Racket, Turn Down Commercials
August 29, 2014, 12:49 PM
Dropbox Bows to Competitive Pressure, Provides 1TB of Storage for $10/Month
August 27, 2014, 11:17 AM
Amazon Acquires Twitch for $970 Million
August 25, 2014, 4:37 PM
Facebook Adds Satire Tags to Its Auto-Generated "Related News" Posts
August 18, 2014, 10:43 AM
Comcast, TWC Pull Dinner Gift for FCC Commissioner... Sort Of
August 15, 2014, 1:10 PM
Comcast Accused of Wooing FCC Commissioner w/ $110K Dinner
August 13, 2014, 8:20 PM
Most Popular Articles
Numerous Leaks Detail 4.7" iPhone 6 Processor, RAM, Cellular and NFC Capabilities
August 29, 2014, 10:37 PM
Windows 9: "Upgrade Now" Button Coming for Enterprise Updates, ARM Preview in H1 2015
August 26, 2014, 8:00 PM
L.A. Unified School District’s Apple iPad Contract Canceled Following Heavy Criticism
August 26, 2014, 12:37 PM
Apple Builds Not-So-Secret Secret 3-Story Tower for iPhone 6/iWatch Unveil
August 28, 2014, 3:41 PM
Netflix Accuses Comcast of Ripping Off Customers, Files to Block Merger
August 26, 2014, 5:49 PM
Latest Blog Posts
Space Terrorism is a Looming Threat For the United States
Apr 23, 2014, 7:47 PM
Facebook Aims to Provide Internet to "Every Person in the World" with Drones, Satellites
Apr 1, 2014, 10:20 AM
Retail Mobile Sites Experience Outages in Light of Simplexity's Bankruptcy
Mar 14, 2014, 8:48 AM
Tesla vs. BMW: Who Has the Safer EV?
Feb 1, 2014, 2:56 PM
Justice Leaks Details of Next HTC One Two Flagship Phone
Dec 5, 2013, 4:04 PM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information