Please create an account to participate in the Slashdot moderation system


Forgot your password?
Yahoo! Security IT Technology

Former Yahoo Engineer Pleads Guilty To Hacking User Emails in Search For Porn ( 52

A former Yahoo software engineer pleaded guilty yesterday to hacking into the personal accounts of over 6,000 Yahoo users, in search of sexual images and videos. From a report: Reyes Daniel Ruiz, 34, of Tracy, California, worked for more than ten years for Yahoo!, where he served as a reliability engineer for the company's Yahoo! Mail service, among other roles. According to court documents, Ruiz used the access to Yahoo!'s internal network that his job provided to crack users' passwords and gain access to their email accounts. In total, he accessed about 6,000 accounts, most belonging to younger women, including personal friends and work colleagues. Once in, he searched and downloaded images and videos, which he stored at home on a hard drive. Ruiz also used access to the hacked Yahoo! email inboxes to compromise accounts at services like Apple iCloud, Facebook, Gmail, DropBox, and others, where the victims used the Yahoo! email address to register accounts. He did this by requesting password resets on the third-party sites, which he received inside the victim's Yahoo! inboxes. Ruiz then continued his search of personal images and videos on these new accounts.
This discussion has been archived. No new comments can be posted.

Former Yahoo Engineer Pleads Guilty To Hacking User Emails in Search For Porn

Comments Filter:
  • Just asking? Or did this engineer hack archived emails or something?
    • My Dad, but he is close to 90 years old. That's about it I believe.
    • I have a couple of junk accounts still that I've had forever. I still use them for things that require an e-mail address but that I don't want to give a "good" one to. (Not porn though... :) )
    • A friend, uh, yeah, that's it, a friend I know has hundreds of old accounts.
    • I know a lot of people still have Yahoo email accounts. Some are jumk ones, but I know a that set this up as their primary email account back in the day, and have never found good reason to drop it in favor of a new one.

      I guess don't fix what ain't broke you know?

      But my question is, with all the FREE pr0n out there, why is this guy jumping through so many hoops and putting his freedom at danger which plenty of pr0n is out there just a click away?

      You'd think he'd heard of pornhub by now?

      • Thrill of seeing stuff people don't want you to see?

      • I think it the headline is misleading to call it pr0n. He was hacking into people's personal accounts which may or may not have included revealing images and probably mostly did not. It sounds more like simple nosiness.
    • I do. Not that I've ever used their website for anything. Yahoo has provided POP/IMAP access since back when Hotmail was still a thing.

    • I do. They are great for throwaway email addresses. I think they were one of the last the required phone number linkage too, so you could setup an infinite number of them.

    • I know tons of people still using yahoo mail, including most the members of my family. It is actually hugely popular despite the conspicuous lack of security.

  • I hope the dude wrote at least a rudimentary AI to do the searching for him.

    Cauce clicking through 6000 accounts by hand woulda left him with such horrible Carpal Tunnel Syndrome in his hands that those very same hands wouldn't have been of any use to him when he actually stumbled upon some quality pr0n...


    Get off teh t00bz & back into meatspace.


    Eat Keto/Paleo.

    Learn GAME!!!!!
  • So abusing root privilege now counts as hacking, I'm sure the script kiddies will be pleased.

    • So abusing root privilege now counts as hacking, I'm sure the script kiddies will be pleased.

      Read it again

    • by Calydor ( 739835 )

      When you start using the credentials you scoop up with your root access to gain access on OTHER machines, sites etc. then yes, it's hacking. Or does brute force attempts using a leaked list of credentials not count as hacking in your world?

    • Hacking, adjective: Attempting, over and over, in a methodical way, to achieve something that's outside of the original design.

      Just because you're an admin on the server doesn't mean that it's not a hack. It's certainly low-hanging fruit, nothing to beat your chest about, but it's hacking for sure. Especially since the word "hacking" has become a term.

  • I'm curious to know what percentage of accounts actually got him porn.
  • by Sigma 7 ( 266129 ) on Tuesday October 01, 2019 @12:19PM (#59257142)

    In total, he accessed about 6,000 accounts, most belonging to younger women, including personal friends and work colleagues.

    Personal friends/colleagues? Seems more like blackmail material.

    Of course, if he was just searching for porn for consumption reasons... that's rather silly considering there's websites that give them out for free - one of which is now doubling up as a popular imageboard while being the cesspool of the Internet.

    • Really? You have never wanted to see pictures people you know vs people you don't?

  • by sqorbit ( 3387991 ) on Tuesday October 01, 2019 @12:50PM (#59257278)
    Being a young man in the 90s lead me to learn the Linux shell that our local dial up BBS provider had to access the internet. Once I realized there were horrible quality gifs of naked ladies doing much more than I ever saw in playboy I knew I had to try out the internet! Now I'm 20 years into an IT career and using Linux everyday. Thank you naked ladies!
  • Goes beyond even a peeping tom because of the level of violation and the fact that the visuals can be shared and remain in public forever. The law needs an update in this realm (and many other tech related realms). Just getting a hacking charge isn't sufficient.
    • I hear what you're saying, but very much dislike the term "visual rape" as it lessens the actual meaning of "rape".

      • How about technological sexual exploitation? He was using technology to get his jollies at the expense of the rights of others. I get what you're saying on the term of rape. What's a word that is in between voyeur (minimal harm) and rape (personal, physical and mental harm) that doesn't diminish rape? We need that word and an appropriate charge for it.
        • And by "minimal harm" re: voyeurism, I mean that there is no record of it which can be shared with the world, there is no physical harm. There is still an unacceptable and harmful invasion of privacy which should be redressed.
    • I'll one up you here. I don't think there's a chance in hell voyeurism or curiosity had anything to do with this. Sure, 10-20 people closely related to him by blood or circumstance, that might be curiosity. But 6000? No, 6000 is a hunting expedition. This asshole was a paid spy. He should be investigated for espionage and treason. The pr0n is just a lame cover story, planned ahead of time as a diversionary tactic.

  • From the end of the FA:

    Ruiz stopped working at Yahoo! in July 2018. He's currently employed at a Silicon Valley tech company specialized in SSO (single sign-on) solutions.

    So this character that has just pleaded guilty to hacking has a job writing security applications.

  • No system (private or public) is better than the people who staff it.

    Somebody has to have the guns, and/or somebody has to have root (depending on context). And that somebody is going to be a fallible (dare I say sinful?) human being.

  • by rnturn ( 11092 ) on Tuesday October 01, 2019 @02:44PM (#59257974)

    ... to find porn. Most people find it without having to hack emails.

    Maybe he had blackmail in mind.

  • pleaded guilty yesterday to hacking into the personal accounts of over 6,000 Yahoo users, in search of sexual images and videos.

    So, this guy has never heard of the internet?

    • Yes, the payoff does not seem in proportion to the risk. You're on the right track. Now just ask yourself "What if he was looking for something else and the porn was just a cover story?"

There's got to be more to life than compile-and-go.
