3 ms·
> Yandex officials also said they re-secured the compromised accounts and blocked what appeared to be unauthorized logins. They are now asking impacted account
by edrobap 6y ago
> Yandex officials also said they re-secured the compromised accounts and blocked what appeared to be unauthorized logins. They are now asking impacted account owners to change their passwords.
I’m curious how access was provided to these sold accounts. The password change implies the passwords were shared and that means plan text password were available to admins!?
- justusthane 6y agoI'm not sure why you were downvoted - I vouched for your comment to bring it back (in fact, looking at your comment history it looks like almost all of your comments are dead). I think you're right though--it does seem like they must have sold the passwords themselves. It's interesting to think about how you would sell access to an account if you wanted to.
- ncann 6y agoDepending on your level of access, I can think of many ways. You can do a "takeout" of all data in the account and sell that. Or it can be anything that is requested, like a dump of all the private messages. You can change the password of the account, possibly at a time like 3am at the user's local time so they're less likely to be using the account, then change it back at say 5am. This requires DB access. You can find the user's session token/id if they're logged in somewhere and sell that.
- edrobap 6y agoAll 3 ways make sense. The dump and session token ways look cleaner from Yandex employees’ perspective. Although, none of the three should require a password change for the compromised user account. At no point, users password or hash of the password gets shared.