Arkansas Democrat-Gazette

Yahoo breach raises concern of break- ins across Internet

- RAPHAEL SATTER

LONDON — Informatio­nsecurity experts are concerned that the recently announced record- breaking haul of password data from Yahoo will be used to open locks up and down the Web.

While it’s unknown to what extent the stolen data have been or will be circulatin­g, giant breaches can send ripples of insecurity across the Internet.

“Data breaches on the scale of Yahoo are the security equivalent of ecological disasters,” said Matt Blaze, a security researcher who directs the Distribute­d Systems Lab at the University of Pennsylvan­ia, in a message posted to Twitter.

A big worry is that a cybercrimi­nal technique known as “credential stuffing,” which works by throwing leaked user name and password combinatio­ns at websites to break in, a bit like a thief finding keys in an apartment lobby and trying them, one after the other, in every door in the building. Software makes the trial- and- error process practicall­y instantane­ous.

Credential stuffing typically succeeds between 0.1 percent and 2 percent of the time, according to Shuman Ghosemajum­der, the chief technology officer of Shape Security in Mountain View, Calif.. That means cybercrimi­nals wielding 500 million passwords could hijack tens of thousands of accounts.

“It becomes a numbers game for them,” Ghosemajum­der said in a telephone interview.

At the moment it’s not known who holds the passwords or whether a statespons­ored hacker, which Yahoo has blamed for the breach, would have an interest in passing the data to others.

Even if the hack was a straightfo­rward espionage operation, Gartner security analyst Avivah Litan said that wouldn’t be a reason to relax. Spies can mine trivialsee­ming data from apparently random people to tease out their real targets’ secrets.

“That’s how intelligen­ce works,” Litan said in a phone call.

Newspapers in English

Newspapers from United States