Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think it has to do with the sophistication of the attack. If they used multiple zero-days, multiple pieces of custom coded software, and a team of operators working full time for long periods of time then it can be assumed it's a multi-million dollar effort involving a large team of engineers. In such a case the list of potential adversaries can be reduced to corporate or state actors.


It is PR. It makes them seem less incompetent if the attack was performed by a "state sponsored actor".


I agree, but the typical PR spin tends to be "a sophisticated adversary". It'd look bad to say an attack was state sponsored if you didn't have good reason to believe it, since that's a pretty specific accusation.

My guess is they hired a firm that actually knows security - probably FireEye or Crowdstrike - and their analysts came to that conclusion.


> since that's a pretty specific accusation.

No it's not. It's an entirely vague specification.

Was it the Russians, the Chinese, the NSA?

It's also something they'll never have to prove or verify so from a PR perspective it makes you look far less incompetent if you say 'state sponsored actor' instead of '17 year old high-schooler from Estonia'.


>It's also something they'll never have to prove or verify so from a PR perspective

I disagree. In breaches like these, attribution discussion begins pretty quickly after the announcement. If researchers find evidence it was some script kiddie or a black hat group or whatever, that would embarrass Yahoo even more.

If you don't know who the attacker is, you have nothing to lose by saying you were compromised by a sophisticated adversary in a targeted attack. You have more to lose by saying a nation-state attacked you if they actually didn't.


> It'd look bad to say an attack was state sponsored if you didn't have good reason to believe it

Did you just say it would "look bad"? They just had one of the biggest data breaches in history..


It'd look worse if security researchers started poking holes in their story. (Which has happened before for other breaches.)


It seems like the Hillary/Russia thing has everyone thinking, without any evidence, that it's always fake when a state actor is accused. I don't see any reason to doubt them, do people think that countries are not trying to hack into these systems?


Exactly. I see no reason why a "state sponsored actor" would spend "millions" on hacking Yahoo, to turn around and sell the stolen data for $1200 on the black market.


> I think it has to do with the sophistication of the attack.

The security team probably sees thousands of attacks every day, mostly automated but probably a dozen a day targeted/custom. If one gets through the security, that is of course more sophisticated than all the other ones, plus it outsmarted the security team and developers, so you'd hardly tell your boss "we were too stupid". Instead, it came from China* so state-sponsored is a good text to write.

*Or something like that. Enough infected computers there to go around (or government cares little enough if you rent a server).


>potential adversaries can be reduced to corporate or state actors //

Don't black-hat hacker groups exist?


Yes. There have been several that operate at a level equivalent to state-sponsored actors.

"Corporate adversaries" are pretty much a myth, or are just a black hat group hired by a company.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: