Live data from Hacker News

Log in to Yahoo by July 15th to keep your email address

yahoo.tumblr.com

21–30 of 60 posts

Re: Log in to Yahoo by July 15th to keep your email address

#21

This is terrible idea. People will be able to claim Yahoo IDs and use them to take over other people’s identities with a few password resets. I have a Yahoo email address simply as a backup for GMail. Just because I don't sign in very often doesn't mean that it is safe to hand over to someone else!

This was my first thought. I've seen this done on a large scale with hotmail, where addresses automatically expire after a certain period of disuse.

Re: Log in to Yahoo by July 15th to keep your email address

#22
This is a terrible idea!

I have a month to compile a list of the most popular first and last names and popular e-mail names and get a bot ready to register them all.

Once registered, I can then attempt password recovery for these @yahoo.com email addresses at the most popular web sites across the Internet that rely on established identities (ebay.com?).

If JamesSmith@yahoo.com ever used his yahoo id to register an account on EBAY.com, or with another online service, now is my chance to try to steal his online accounts by requesting password resets on these services and assuming his identity.

Now, to build a bot that will do this thousands of times!

Sites with 2 factor authentication may be immune to this, but these identities will now be unrecoverable to somebody who has used his @yahoo address as his recovery e-mail address, even if he doesn't check it often.

Re: Log in to Yahoo by July 15th to keep your email address

#23
post #11

This is a fantastic idea, and I wish other services (I'm looking at you Twitter) would follow suit. Your Yahoo ID becomes a part of your identity when using their service, so it seems reasonable that people will feel happier and be more inclined to use Yahoo's stuff when they have an ID that they feel good about and aren't embarrassed to share with their friends.

I went to sign up for Twitter and found that my usual username was taken by someone with exactly one tweet, from 4 years ago! It's definitely frustrating.

is it possible that you are using their usual username?

Re: Log in to Yahoo by July 15th to keep your email address

#24
post #12

Earlier quoted context omitted.

This is a way worse then just disabling unused old accounts and, say, deleting emails stored there. Yahoo is going to "resell"(1) these accounts. This will create all kind of privacy problems, and potential for abuse: gaining access to other services through resetting passwords there, impersonating users, people receiving private communications not intended for them, etc. And all this for what purpose? Give few lucky…

reuse

Thought about it, but doesn't sounds quite right too: Yahoo didn't use these identities, it provided them to the users. Anyway I don't want to be pedantic here, just as long as it was clear what I tried to say, and nobody misunderstood that I accuse Yahoo literary selling its user accounts to the third party, I am happy. :)

Re: Log in to Yahoo by July 15th to keep your email address

#25

This is quite common in large online games where accounts often sit unused, having only a few hours of total hours logged over years.

This is a great strategy for gaming systems, a terrible strategy for accounts used as identity management and password recovery vectors.

Let's say JamesSmith@yahoo.com used this email address long ago as his ebay recovery address, but really doesn't use his @yahoo account any more. I can register JamesSmith@yahoo.com, and use ebay's account recovery option to assign the ebay account a new password for an ebay account I have now stolen.

This scenario isn't possible with an online game account name, as game accounts aren't used to recover bank passwords or other important account passwords.

Re: Log in to Yahoo by July 15th to keep your email address

#26

This is a terrible idea! I have a month to compile a list of the most popular first and last names and popular e-mail names and get a bot ready to register them all. Once registered, I can then attempt password recovery for these @yahoo.com email addresses at the most popular web sites across the Internet that rely on established identities (ebay.com?). If JamesSmith@yahoo.com ever used his yahoo id to register an ac…

That's exactly what I first thought. The fact that they don't get this means that I will not be using their services at all going forward.

Re: Log in to Yahoo by July 15th to keep your email address

#27

This is a terrible idea! I have a month to compile a list of the most popular first and last names and popular e-mail names and get a bot ready to register them all. Once registered, I can then attempt password recovery for these @yahoo.com email addresses at the most popular web sites across the Internet that rely on established identities (ebay.com?). If JamesSmith@yahoo.com ever used his yahoo id to register an ac…

You're absolutely right. Other services view email as non-transferrable (the "recover my password" feature of almost every website with a login ever is evidence of this). Think of what someone could do if they had access to your email account, even if it's one you haven't used in years.

Someone could turn my life upside down if they had access to the hotmail account that I use to sign up for services that I know will spam me.

Re: Log in to Yahoo by July 15th to keep your email address

#28

This is a terrible idea! I have a month to compile a list of the most popular first and last names and popular e-mail names and get a bot ready to register them all. Once registered, I can then attempt password recovery for these @yahoo.com email addresses at the most popular web sites across the Internet that rely on established identities (ebay.com?). If JamesSmith@yahoo.com ever used his yahoo id to register an ac…

That's exactly what I first thought. The fact that they don't get this means that I will not be using their services at all going forward.

Yes, Yahoo attempting to do this makes me seriously question their trustworthiness. I know they are trying hard to reinvent themselves, but this is a serious misstep unless they've got a magic trick to somehow deal with these issues that I am unaware of.

At the very least it will cause confusion. At worst, accounts will get hacked.

Re: Log in to Yahoo by July 15th to keep your email address

#29
post #19

If this isn't the sign of a product with declining use, I don't know what is. Of course it isn't news that few people use Yahoo mail anymore, but the fact that it's worth it to Yahoo to turn those emails off is interesting.

Maybe. My perspective is that Yahoo! did some research on why people left, stopped using, or never considered Y! as their mail service. I presume one of the responses is that people dislike non-vanity addresses. Instead of tedthomas@yahoo.com, the only variations that remain include thomasted110@ or tedthomasemail@. Ugh. A simple query would show that these vanity addresses are sitting stagnant. A touch of PR and awa…

Even leaving all negative conservatives of this decision aside for now, it hardly does solves anything.

If thomasted110 is the best what's available for now at yahoo, there will be, simplifying a bit, 109 another unhappy users (thomasted1..thomasted109) + tedthomas_xx users + other unhappy Ted Thomases settled for different username at yahoo.com.

None of them is aware if tedthomas will be available. Most of them will not even know that this grand redistribution will take place. In the end if tedthomas will be "reused" only one of them will be moderately happy, while others are no better of.

Re: Log in to Yahoo by July 15th to keep your email address

#30

This is a terrible idea! I have a month to compile a list of the most popular first and last names and popular e-mail names and get a bot ready to register them all. Once registered, I can then attempt password recovery for these @yahoo.com email addresses at the most popular web sites across the Internet that rely on established identities (ebay.com?). If JamesSmith@yahoo.com ever used his yahoo id to register an ac…

You're absolutely right. Other services view email as non-transferrable (the "recover my password" feature of almost every website with a login ever is evidence of this). Think of what someone could do if they had access to your email account, even if it's one you haven't used in years. Someone could turn my life upside down if they had access to the hotmail account that I use to sign up for services that I know will…

Is there anything people can do about that on the service-provider side of it, to limit account compromise via the Yahoo-email-password-reset vector? Short of something like disabling password reset emails to Yahoo addresses, which would cause a different kind of collateral damage?

I've actually run into a few services that won't accept signups from any "free webmail" provider, usually listed as Hotmail/Outlook, Yahoo, and Gmail. I suspect the reason for such policies is worries about spammy new accounts, but the risk of account lapse followed by impersonation might be another reason to favor such a policy. On the other hand, it would also lock out a number of legitimate users who use one of those services as their main or even only email.

Post reply on HN