Live data from Hacker News

Thanks For The Identity Theft, Yahoo

b0ing.me

41–50 of 62 posts

Re: Thanks For The Identity Theft, Yahoo

#41
post #33
post #15

Wow imagine this scenario: I sign up for a service using my Yahoo email account. I don't use my Yahoo account for a year. Someone gains access to my email address. That person enters my email address into a forgot password field. Boom They now have access to my service. As another poster stated, the mind boggles.

It's a valid scenario, but I was starting to think quite unlikely. If I get a a new jrandom@yahoo.com address, I would have to know who that account used to belong to and on which online services it might have been used. If I'm in Boston and the old "jrandom" was in Atlanta, I'd have to first figure that out and then figure out what bank he used, and be lucky enough that he had not updated his email there. And websit…

"It's a valid scenario, but I was starting to think quite unlikely. If I get a a new jrandom@yahoo.com address, I would have to know who that account used to belong to and on which online services it might have been used. If I'm in Boston and the old "jrandom" was in Atlanta, I'd have to first figure that out and then figure out what bank he used, and be lucky enough that he had not updated his email there. And websites like banks and other financial services require more than just an email address to get a password reset. You need to answer some "secret questions" etc."

It's not that hard, actually, considering that most websites you sign up for send periodic marketing emails. You're the new owner, you get a marketing email addressed at the old owner, hit the "forgot my password" link, and you have ownership of the account.

Re: Thanks For The Identity Theft, Yahoo

#43
I am always wary of collateral damage arguments, but in a greater-good sense, I almost hope Yahoo do go ahead with this. It's such an obviously bad idea, and enough people probably would suffer significantly as a result, that it might just raise public awareness of why things like good security practices and privacy and data protection matter, and that it can "happen to them", even many years in the future, if they don't take care of how they behave and who they trust today.

Hopefully, Yahoo would also find themselves vulnerable to at least one of the obvious legal attack vectors and wind up paying out a small fortune in compensation to make good on losses due to identity theft and/or frauds committed using false identities they supported. This could be an educational lesson for a lot of businesses that don't take privacy and data protection seriously today because collecting everything you possibly can about everyone is seen almost pure upside with little real cost or risk.

Re: Thanks For The Identity Theft, Yahoo

#44
post #35

To top it off, their password reset for existing users is completely broken now. I don't mean "poorly designed," I mean it is simply not working. When I tried to reset a password recently, I got "your password is too weak" for every password I tried, including very long randomly-constructed not-previously-used passwords resembling line noise. This after carefully making sure both entries of the password matched. Mult…

I just changed my Yahoo password without any issue. It was incredibly straight forward for me.

Re: Thanks For The Identity Theft, Yahoo

#45
I agree that this is a terrible move, in theory. But in actual practice, I'm not convinced it will be so bad.

Because if you're not using that Yahoo account for e-mail anymore, then you're probably not using it as a sign-in or password recovery e-mail for your banking, Facebook, or anything else important -- because the whole point is, everything that's actually important to you, you're using your current e-mail address. After all, that's where important account notifications go, credit card receipts, bank statements, password resets, etc. -- things which are necessary for you to see.

Of course you'll likely have a bunch of accounts you forgot even existed on random sites you signed up for in the past, with your old Yahoo e-mail address. Most of them will be harmless -- who cares if someone gets access to some random sports forum you once posted on.

The biggest risk I can see is that 1) the new owner chooses to be malicious, 2) successfully locates a site that sends out password-recovery emails with the original passwords in plaintext, which the specific user has an account on, 3) knows the original user's current valid address, 4) tries the old password on the user's new address they use with banking/etc., and it works. But the risk of this would appear to be so small, that it's just lumped in with all the other kinds of "identity theft" weaknesses that already exist (guessing security questions, etc.).

(And then, there's scamming on whatever social networks or forums the old e-mail address had an account on. Although it seems like Facebook etc. is protecting against that? And it's not like spoofing e-mails/accounts is anything new.)

As long as Yahoo is giving significant heavy warning to the e-mail accounts themselves, and months' worth of time -- well if you never check your free e-mail account, it's not unreasonable to expect that it might be deactivated someday. Annoying, but not unreasonable. And if you use the same password for your Facebook, banking, etc. as you did for other random sites you signed up for years ago, then that's a security risk regardless of what Yahoo does.

Re: Thanks For The Identity Theft, Yahoo

#46
This isn't the first time they've taken this type of action with email account names.

I had an @att.net email address from when I had U-Verse that was essentially Yahoo mail with an ATT address. I thankfully didn't do anything on that account, but I kept it since it was the same user name I have registered on most major webmail services.

I got an email about a year ago that those addresses would be merging with Yahoo, and that my address would now be @yahoo.com. Fine with me, I thought, perfect if I ever wanted to try out Yahoo mail for a spell.

A few months later a get an email about my password being changed. Not good. From there I had about a 15 minute back and forth with someone else trying to get their information(alternate email address, password, security questions, phone number for 2-factor) on the account to lock me out. I prevailed, and in double checking how that person could have gotten access, found something disturbing. This was not my email account. It was mostly dormant, but there were legitimate emails from years ago sent by another person who shares my name.

I contacted Yahoo through their form about such matters, but they never answered. So now I've held on to the address, which I value for preserving my internet identity, but someone else is out of luck in trying to access an account they used sparingly years ago.

This is obviously much worse, as it's intentionally going to result in these types of account ownership issues, but it certainly seems reflective of Yahoo's attitude towards the importance of holding an email address.

Re: Thanks For The Identity Theft, Yahoo

#47

Thanks for posting this. I've got several accounts on autopay attached to my yahoo address, but nothing else of note. Re-captured my account after 2 years away. This would not have been good if it had been given away.

Legitimate question: how can you have accounts on autopay attached to an e-mail address you haven't checked in 2 years?

You have literally not looked at any of the receipts in 2 years? If you've cancelled any of the credit cards, you had no idea that there was an autopay problem? The merchants had no way of contacting you, because you never checked that email?

That doesn't make any sense to me. Or was it just forwarding the emails to the account you do use, or whatnot? In which case, I assume that Yahoo would be sending emails warning of the upcoming account closure, which you could receive and act on?

Re: Thanks For The Identity Theft, Yahoo

#50
post #33
post #15

Wow imagine this scenario: I sign up for a service using my Yahoo email account. I don't use my Yahoo account for a year. Someone gains access to my email address. That person enters my email address into a forgot password field. Boom They now have access to my service. As another poster stated, the mind boggles.

It's a valid scenario, but I was starting to think quite unlikely. If I get a a new jrandom@yahoo.com address, I would have to know who that account used to belong to and on which online services it might have been used. If I'm in Boston and the old "jrandom" was in Atlanta, I'd have to first figure that out and then figure out what bank he used, and be lucky enough that he had not updated his email there. And websit…

A lot of websites send "monthly newsletter from .com" type emails. Ironically it's the avoidance of such emails that often causes people to use throwaway yahoo accounts.

Once these start appearing in the inbox, the new owner can just do a password reset on these sites.

Post reply on HN