Turns Out It Was All Three Billion

Turns Out It Was All Three Billion

Tech News data breach passwords privacy security yahoo

So Yahoo announced this week that the 2013 breach everyone's known about for a year didn't hit a billion accounts. It hit all three billion. Every single account that existed. Not "up to," not "as many as" — all of them, full stop, according to the notice Verizon (who owns the whole mess now under that awkward Oath branding) put out on October 3rd.

If you've been following this story since 2016 you'll remember Yahoo's original number was a billion, which already sounded enormous at the time. Then it turns out the real figure was three times that, and somehow nobody caught it for four more years after the actual hack happened. I dont know how you go from "a billion" to "literally everyone who has ever had an account" without someone in a meeting saying, hey, maybe we should double check that math before we say it out loud in a press release. Names, email addresses, birthdates, security questions, and passwords protected with the weak MD5 hashing scheme that security people have been telling companies to stop using since roughly forever. Not great!

I'll admit this hit a little close to home, because I still have a Yahoo Mail account from 2003. I dont use it for anything real anymore, hasnt been my primary inbox since maybe 2009, but I never got around to closing it, and for years it was where I ran a fantasy football league with a group of guys from my old job. There's probably a security question in there with my mother's actual maiden name on it, because who thinks about that stuff in 2003. I spent about twenty minutes last night logging back in (address bar still autocompleted the URL, which tells you something about how long it's been sitting in my browser history) just to see what was still lurking in there. Mostly spam and a decade of unsubscribe links. But also a handful of old messages from my grandfather, who passed a few years back, and I ended up saving those as PDFs instead of just nuking the account like I'd planned. So that plan's on hold now.

What bugs me about the whole thing isnt really the breach itself, breaches happen, everybody gets breached eventually if they exist long enough online. Its the drip-feed. First it's "half a billion," then a few months later its "actually a billion," then a year after that its "no wait, everyone, we mean everyone." Each revision gets its own news cycle and its own round of "well at least now we know the real number," and then six months later there's another real number. At some point you have to wonder whether anyone at these companies actually knows what happened to their own systems, or if they're just raising the estimate every time a lawyer tells them the old one is no longer defensible.

This is also, not coincidentally I'd guess, the same week Equifax's former CEO was up on Capitol Hill getting grilled by Congress about the breach from this summer, so it's been a rough stretch generally for anyone who'd like to believe the companies holding their personal data have a handle on things. Two different companies, two different breaches, three years apart, and the same basic story: it was worse than they told you, and you find out on their schedule, not yours.

Anyway. If you, like me, have some ancient email account you've been meaning to deal with, this is as good a nudge as any. Go change the password on anything that still shares one with an account from 2003. I'm not deleting mine yet, turns out, but I did finally turn on two-factor on it, which is more than I'd done in the fourteen years before this week.