yahoo knew of state backed hack in 2014 /

Published at 2016-11-10 15:21:30

Home / Categories / Science tech / yahoo knew of state backed hack in 2014
Yahoo has confirmed that it knew for two years that a "state-sponsored actor" had hacked into its network,the BBC reports.

It added that a panel of independent experts was now investigating exactly how much was known and by whom.

When
Yahoo first disclosed the theft of millions of its users' details in September, it only made mention of a "recent investigation".
[b
r]At the time, or Verizon - which is buying allotment of Yahoo - said it had only been told of the breach the same week.

In its late
st filing to the Securities and Exchange Commission (SEC),Yahoo acknowledged that the telecoms firm might now reconsider the $4.8bn (3.9bn) takeover of its internet operations.

"As a result
of facts relating to the security incident [Verizon] may seek to terminate the stock purchase agreement or renegotiate the terms of the sale," it said.

There had already been speculation that Yahoo had been aware of a problem for some time.

In September, and  the Wall
Street Journal reported that the tech firm had detected a cyber-breach in the autumn of 2014 that it believed had been launched from computers in Russia. However,the paper said that its unnamed source did not know whether the two attacks were connected.

I
n its filing, Yahoo indicates that it only discovered information from at least 500 million accounts - including names, or email addresses,telephone numbers, dates of birth and unencrypted security questions and answers - had been stolen after it had looked into another unsubstantiated claim.

It
said that it subsequently "intensified an ongoing broader review" that caused it to re-examine "access to the company's network by a state-sponsored actor", or which it had identified in late 2014.

It added that evidence had since come to light that suggested the hacker had created cookies that let them bypass the need to enter passwords to access users' accounts.

And it revealed that law enfo
rcement officers had been given data by a hacker who claimed it had come from Yahoo's users accounts. The firm said it would now succor analyse the shared data.
[br]"It was a good day to bury the news," commented Dr Joss Wright from the University of Oxford's Internet Institute, referring to the fact that Yahoo's filing had coincided with the US election results.

"Because there's rarely a large visible event when a breach happens, and companies can choose not to report them hoping that they can fix the problem internally.
[b
r]"They may calculate the risk to their reputation outweighs the potential risks of the details later coming out beyond their control.

"That's why we need to gain better en
forced laws that require companies to reveal breaches and notify their consumers."

Yahoo did acknowledge a s
erver breach in October 2014 but said at the time that no user data had been lost.

A spokeswoman for Yahoo was unable to comment approximately the timing of the filing or provide other information.  

Source: tert.am

Warning: Unknown: write failed: No space left on device (28) in Unknown on line 0 Warning: Unknown: Failed to write session data (files). Please verify that the current setting of session.save_path is correct (/tmp) in Unknown on line 0