Live data from Hacker News

Thanks For The Identity Theft, Yahoo

b0ing.me

51–60 of 62 posts

Re: Thanks For The Identity Theft, Yahoo

#51

Thanks for posting this. I've got several accounts on autopay attached to my yahoo address, but nothing else of note. Re-captured my account after 2 years away. This would not have been good if it had been given away.

Legitimate question: how can you have accounts on autopay attached to an e-mail address you haven't checked in 2 years? You have literally not looked at any of the receipts in 2 years? If you've cancelled any of the credit cards, you had no idea that there was an autopay problem? The merchants had no way of contacting you, because you never checked that email? That doesn't make any sense to me. Or was it just forward…

You have literally not looked at any of the receipts in 2 years? If you've cancelled any of the credit cards, you had no idea that there was an autopay problem? The merchants had no way of contacting you, because you never checked that email?

For me, this is done through the web interface in almost all cases. Did my hosting account try to charge my credit-card and it was declined? It'll show up in the account dashboard. Do I want to look at my Amazon receipts? They're under Your Account -> Your Orders.

I'm updating some old emails now since I was reminded of it, but generally I don't care about receiving email from websites, so I typically send them to an account I don't check in order to keep them out of my way, and to ensure that if they sell my email, the spam will go there too (in my case it's an old AOL account). A number of sites won't even send you anything via email except "please log in" anyway. For example, when my bank sends me a "bank statement" by email, all it contains is a notification that there is a new bank statement waiting online, if I want to log in and read it. So the email is not needed or useful for services where I already log in regularly.

Re: Thanks For The Identity Theft, Yahoo

#53

I agree that this is a terrible move, in theory. But in actual practice, I'm not convinced it will be so bad. Because if you're not using that Yahoo account for e-mail anymore, then you're probably not using it as a sign-in or password recovery e-mail for your banking, Facebook, or anything else important -- because the whole point is, everything that's actually important to you, you're using your current e-mail addr…

What about when someone uses their old email address as the password recovery email for the new email address? I agree with Silhouette in that I hope they follow through with this... It will surely be fun to watch, and also people will become a little bit more security conscious.

Re: Thanks For The Identity Theft, Yahoo

#55

I agree that this is a terrible move, in theory. But in actual practice, I'm not convinced it will be so bad. Because if you're not using that Yahoo account for e-mail anymore, then you're probably not using it as a sign-in or password recovery e-mail for your banking, Facebook, or anything else important -- because the whole point is, everything that's actually important to you, you're using your current e-mail addr…

I changed my email address at my bank. They still send emails to my old address (and to my new address). They have no idea why and how. I'm pretty sure this kind of "thing" will happen to many others, with the difference that I keep my old (yahoo) address active...

Re: Thanks For The Identity Theft, Yahoo

#56
post #26
post #20

Earlier quoted context omitted.

Still, we can't blame Yahoo for that, right? We can't blame them for peoples Internet incompetence. We can't blame them for the limited scope most service developers have. As I user, I have to update my email address I use and other services should delete inactive accounts, too. Or at least notify inactive users. I know, especially the latter option is more or less inexistent. But although think of all the data that…

You can't blame Yahoo as-in "they are technically and legally allowed to do that". But on the other hand, Yahoo is a falling behemoth that is trying to earn itself a new image; and doing such a stupid move can and will earn them the mark that they still "don't get it", and rightly so.

I never talked about the legal part. Of course it is legal since their terms might likely allow this.

I just don't see it that wrong like you do. I wonder, if there is an argumentation to really call them stupid. And I don't even think this is relevant referring to their image.

As you said, this only affects people who aren't either informed about computer topics, don't know they had a Yahoo mail at all or who simply reregister their old mail address.

Re: Thanks For The Identity Theft, Yahoo

#57
post #49

Is it just me or is that an awesomely designed blog page. I'm a fairly decent programmer, but when I see a beautiful page like that I give up all pretenses that I'll ever be more than a barely adequate designer.

:') you just made my day

Glad too! My designs look utility functions ;-)

Re: Thanks For The Identity Theft, Yahoo

#58
post #5
post #3

I clicked on the link expecting it be alarmism, but this legitimately boggles the mind.

I definitely did a little title baiting, but I think it's justified in this case. This is a monumental cock-up.

It is a pretty compelling argument for little benefit on Yahoo's part. The correct answer for Yahoo is to freeze email in the previous domain, create a new domain for mail and move forward. But there is a certain lack of understanding that is settling in a Yahoo which feels distinctly like 'new young people' (and I mean that in the nicest way possible) but people who consider the time before they were aware of the world "ancient history" and for new grads from college in 2012 - 2013 that was anything before 2000.

Imagine the fun that could be had if Hollywood decided to 're-use' old stage names. We could get a bunch of new John Wayne movies!

Re: Thanks For The Identity Theft, Yahoo

#59

Thanks for posting this. I've got several accounts on autopay attached to my yahoo address, but nothing else of note. Re-captured my account after 2 years away. This would not have been good if it had been given away.

Legitimate question: how can you have accounts on autopay attached to an e-mail address you haven't checked in 2 years? You have literally not looked at any of the receipts in 2 years? If you've cancelled any of the credit cards, you had no idea that there was an autopay problem? The merchants had no way of contacting you, because you never checked that email? That doesn't make any sense to me. Or was it just forward…

By watching charges via online banking, and it being a service I use every day with a very small repeating charge (e.g. Pandora). Set it, forget it, reap the benefits. Most services do not require monitoring.

As for warning emails, I had a backup email listed with them, and I have received nothing on either the backup email or the Yahoo email warning of this potential problem.

Re: Thanks For The Identity Theft, Yahoo

#60
post #12

Hope someone grabs Palin's old (compromised) email. This decision by Yahoo is a troll's wet dream.

I'm fairly certain grabbing an unused address doesn't give you the old e-mail...

But you can do password recovery on every service they've ever used with that email and get any private info from that service. Yahoo should define "dormant" as an email that hasn't RECEIVED email in over X years. Also they should lock the dormant email addresses for 5 years before releasing them to new users.
Post reply on HN