Live data from Hacker News

Thanks For The Identity Theft, Yahoo

b0ing.me

11–20 of 62 posts

Re: Thanks For The Identity Theft, Yahoo

#14

Just put in my request for jerryyang@yahoo.com on their "wish list" site. This could be interesting.

Cheeky. But I doubt they'll include that. More than likely, they've whitelisted all Yahoo CEOs/employees/associates/minions and people with "allah" in the name somewhere.[1]

[1] http://en.wikipedia.org/wiki/Yahoo!_Mail#Username_bans

Re: Thanks For The Identity Theft, Yahoo

#15
Wow imagine this scenario:

I sign up for a service using my Yahoo email account. I don't use my Yahoo account for a year. Someone gains access to my email address. That person enters my email address into a forgot password field. Boom They now have access to my service.

As another poster stated, the mind boggles.

Re: Thanks For The Identity Theft, Yahoo

#16
Well, the Internet is dynamic isn't it? Other services are already freeing inactive accounts, email or e.g. Twitter handles, and think of changing mail service owners and domain changes, too. And why should a service hold an email forever, just because someone registered it and maybe was never even using it?

Isn't the real problem that users and services put too much trust in plain email addresses? Especially when accounts are outdated? Crypto might help here someday in the future.

We could even say: Isn't it your fault that you didn't keep track on which services you used that email? Or that you lost your password? Why blame Yahoo for that?

Re: Thanks For The Identity Theft, Yahoo

#17
post #5
post #3

I clicked on the link expecting it be alarmism, but this legitimately boggles the mind.

I definitely did a little title baiting, but I think it's justified in this case. This is a monumental cock-up.

Sure, a few people will lose their identity, but millions will get good email addresses!

Re: Thanks For The Identity Theft, Yahoo

#18
post #16

Well, the Internet is dynamic isn't it? Other services are already freeing inactive accounts, email or e.g. Twitter handles, and think of changing mail service owners and domain changes, too. And why should a service hold an email forever, just because someone registered it and maybe was never even using it? Isn't the real problem that users and services put too much trust in plain email addresses? Especially when ac…

Because for better or worse, email has become the defacto identity identifier on the web. If you allow people to grab emails that used to be owned by someone else, you effectively allow them to own their identity on every website where they registered with that email in the past.

And while some other email providers do the same, it's particularly bad with yahoo because they are such a huge and longstanding provider, they have tons of email, some that are a decade old, and a lot owned by people who are not very technical or who don't check their email very often.

Re: Thanks For The Identity Theft, Yahoo

#20
post #18
post #16

Well, the Internet is dynamic isn't it? Other services are already freeing inactive accounts, email or e.g. Twitter handles, and think of changing mail service owners and domain changes, too. And why should a service hold an email forever, just because someone registered it and maybe was never even using it? Isn't the real problem that users and services put too much trust in plain email addresses? Especially when ac…

Because for better or worse, email has become the defacto identity identifier on the web. If you allow people to grab emails that used to be owned by someone else, you effectively allow them to own their identity on every website where they registered with that email in the past. And while some other email providers do the same, it's particularly bad with yahoo because they are such a huge and longstanding provider,…

Still, we can't blame Yahoo for that, right? We can't blame them for peoples Internet incompetence. We can't blame them for the limited scope most service developers have.

As I user, I have to update my email address I use and other services should delete inactive accounts, too. Or at least notify inactive users. I know, especially the latter option is more or less inexistent. But although think of all the data that users have no access to, because of lost passwords etc. I rather see that deleted.

Also, if Yahoo is doing things right, they would only delete accounts with no activity for a serious amount of time, e.g. no access, not even POP3 since over 2 years.

Post reply on HN