Live data from Hacker News

Thanks For The Identity Theft, Yahoo

b0ing.me

31–40 of 62 posts

Re: Thanks For The Identity Theft, Yahoo

#31
post #25

Yahoo could append a text header in the mail body reminding it's a recycled email so caution has to be taken and it should not be trusting it upfront. It adds it to the first 10000 mails sent or the first 6 month whichever comes _last_ That will sufficiently annoying so that only people that really wants back their email and commit to it will stay. It's not without flaws but it's a tad better than their current plan.

Imho, the main problem with this is people gaining the accounts, then using them to reset account passwords for services that are not dormant. For example, I use a @msn.com password for my facebook - I haven't used that email address in years, and haven't checked it in months. If microsoft announced something similar tomorrow, I would be totally screwed unless I can access the msn.com address, as facebook doesn't allow you to change email addresses.

This isn't a huge problem for me, as I try to keep up with tech news, but imagine that I'm not subscribed to hacker news, and don't realise what's about to happen to my account, in that case there's no possible way for me to rescue my email in time, and every account I've used it for is compromised.

Re: Thanks For The Identity Theft, Yahoo

#32
post #25

Yahoo could append a text header in the mail body reminding it's a recycled email so caution has to be taken and it should not be trusting it upfront. It adds it to the first 10000 mails sent or the first 6 month whichever comes _last_ That will sufficiently annoying so that only people that really wants back their email and commit to it will stay. It's not without flaws but it's a tad better than their current plan.

They are, in fact, doing that - http://www.wired.com/threatlevel/2013/07/yahoo-email/

Re: Thanks For The Identity Theft, Yahoo

#33
post #15

Wow imagine this scenario: I sign up for a service using my Yahoo email account. I don't use my Yahoo account for a year. Someone gains access to my email address. That person enters my email address into a forgot password field. Boom They now have access to my service. As another poster stated, the mind boggles.

It's a valid scenario, but I was starting to think quite unlikely. If I get a a new jrandom@yahoo.com address, I would have to know who that account used to belong to and on which online services it might have been used. If I'm in Boston and the old "jrandom" was in Atlanta, I'd have to first figure that out and then figure out what bank he used, and be lucky enough that he had not updated his email there. And websites like banks and other financial services require more than just an email address to get a password reset. You need to answer some "secret questions" etc.

But I grew up before Facebook and other social networking fads. I still don't use those services. So I sometimes forget how easy it is to get a very good life history on someone by just searching their email address, very possibly including the answers to typical "secret questions" like your pet's name, where you went to elementary school, etc. and maybe I can even get some clues about what bank they use.

So it really might not be too far-fetched a concern. Still I think it somewhat unlikely that an email account tied to a lot of social networking activity is itself going to be dormant. But it's possible. Maybe the person has the account forwarded to another address and never logs in directly. Would that count as "dormant" ??

Before issuing an account, Yahoo themselves should be sure it's not forwarded, and search for any associated internet content, especially on social media. If an account has not been used in years, AND internet searches for that account turn up nothing, it might be safe to reissue it.

Re: Thanks For The Identity Theft, Yahoo

#34
post #31
post #25

Yahoo could append a text header in the mail body reminding it's a recycled email so caution has to be taken and it should not be trusting it upfront. It adds it to the first 10000 mails sent or the first 6 month whichever comes _last_ That will sufficiently annoying so that only people that really wants back their email and commit to it will stay. It's not without flaws but it's a tad better than their current plan.

Imho, the main problem with this is people gaining the accounts, then using them to reset account passwords for services that are not dormant. For example, I use a @msn.com password for my facebook - I haven't used that email address in years, and haven't checked it in months. If microsoft announced something similar tomorrow, I would be totally screwed unless I can access the msn.com address, as facebook doesn't all…

Facebook doesn't allow you to change email addresses? Really? REALLY? That seems completely unbelievable.

Re: Thanks For The Identity Theft, Yahoo

#35
To top it off, their password reset for existing users is completely broken now. I don't mean "poorly designed," I mean it is simply not working.

When I tried to reset a password recently, I got "your password is too weak" for every password I tried, including very long randomly-constructed not-previously-used passwords resembling line noise. This after carefully making sure both entries of the password matched. Multiple times. The form simply does not allow the user to proceed, and it gives false reasons. It is broken.

Re: Thanks For The Identity Theft, Yahoo

#39

Am I missing something? You only lose accounts which you are not using, correct? It is easy enough to avoid losing the account by logging into it once. If you have lost access to the account, you can go ahead and reclaim the same account back through this scheme, if I am not mistaken. Could someone please explain why people are getting so worked up about this issue?

Could someone please explain why people are getting so worked up about this issue?

Because having your identity stolen can pretty much destroy your life, or at the very least cause you a great deal of suffering for many months. This change would mean a tiny oversight from many years ago could allow those things to happen.

It's also a paradise for fraudsters and charlatans, who will have a bountiful source of new identities to build on if they can just find someone who has since died or can otherwise be assumed not to need an old account any more.

Re: Thanks For The Identity Theft, Yahoo

#40
post #5

Earlier quoted context omitted.

I definitely did a little title baiting, but I think it's justified in this case. This is a monumental cock-up.

Sure, a few people will lose their identity, but millions will get good email addresses!

and don't forget: access to yahoo's amazing webmail client, IMAP and SSL/TLS support, free mail forwarding, and much more!
Post reply on HN