CPL international stars announced for T20 draft 7:43 PM
$45m found at Kingston wharf 7:02 PM
Customs detains pork products in MoBay 6:31 PM
Two bodies fished from Kingston Harbour 5:18 PM
IMF appoints new rep for Jamaica 4:55 PM
J$99.12 to one US dollar 4:44 PM
News
Yahoo confirms theft of 450,000 users' passwords
Friday, July 13, 2012
LONDON, England (AP) — Some 450,000 Yahoo users' email addresses and passwords have been leaked because of a security breach, the company confirmed yesterday, adding that just a small fraction of the stolen passwords were valid.
The company said in a statement that an "old file" from the Yahoo Contributor Network was compromised Wednesday. Among the stolen emails and passwords were many from Yahoo's own email service along with those of other companies. The Yahoo Contributor Network is a content-sharing platform.
Yahoo said it is fixing the vulnerability that led to the disclosure, changing the passwords of affected Yahoo users, and notifying other companies whose users' accounts may have been compromised.
"We apologise to all affected users," the company statement said.
Technology news websites including CNET, Ars Technica, and Mashable identified the hackers behind the attack as a little-known outfit calling itself the D33D Company. The group was quoted as saying it had stolen the unencrypted passwords using an SQL injection — the name given to a commonly used attack in which hackers use rogue commands to extract data from vulnerable websites.
"We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call," the group was quoted as saying.
Online security experts said Yahoo might have done more to protect the stored passwords, with Ohio-based TrustedSec describing the Internet giant's decision not to encrypt them as "most alarming".
Nevertheless, the haul does not appear as useful to hackers as they might have thought. Yahoo cautioned that only five per cent of passwords associated with its account holders were valid.
It was not immediately possible to contact the Ukraine-registered website associated with D33D Company. Its contact form was inoperable yesterday, while an email address and a phone number attributed to the site's registrant appeared to be invalid.
Other Stories
Gov't urged to address waning support for Labour Day
Gov't sued - Keith Clarke’s family seeks big compensation
Boy falls into sea during fight, dies
Laundromat robbery said linked to cash-for-gold trade
Attempt to defraud ATL lands man in jail
PHOTOS: Scenes from Labour Day
Small plane crash kills 3 on Spanish island
Emergency landing causes delays at Heathrow
UK-bound Pakistan plane diverted, 2 men arrested
Former JHTA head 'shocked' by Bartlett's devaluing of local hotels
A university dream comes true for three wards of the state
Cash-for-gold man murdered in Buckfield
KPH increasing bed capacity to address patient overload
St Mary Infirmary residents pampered as building gets facelift
'Show the good side of the children'
Opposition calls for more focus on PATH food subsidy
St Elizabeth puts work into Labour Day
Homestead Place of Safety gets facelift from LIME Foundation


