Live data from Hacker News

Thanks For The Identity Theft, Yahoo

b0ing.me

1–10 of 62 posts

Re: Thanks For The Identity Theft, Yahoo

#4
And how about all "forgot your password" forms that might be exploited on other services. An other service you not been using for long sends you a "long time no see" promotion and your old account is in someone else's hands.

I think there's been a lot of lessons lately about why Internet should not be centralized...

Re: Thanks For The Identity Theft, Yahoo

#6
Yahoo of all companies should know what type of users still retain their emails and what type has moved on.

I had setup my mom's email on Yahoo (cause Gmail didn't exist and Hotmail, freshly bought by MS, was rubbish). She had a habit of entering it to everything and was soon unusable. We went over online browsing and safety, but not before her private info ended up on a dozen or so spammy sites. That was more than 10 years ago.

There's no way to reset the password for that thing, since backup emails weren't present plus IT WAS MORE THAN 10 YEARS AGO! Also, she doesn't have a Facebook page, doesn't want a Facebook page and will likely never get one in the future. She's done handing out her info to people she doesn't know.

I'm sure some of her info is still on it, but if Yahoo goes through with this, there will be hell to pay.

Re: Thanks For The Identity Theft, Yahoo

#7
The freaking problem with that is that I couldn't retrieve in time my lost password to my old yahoo account I used for flickr.

Don't care that much about the yahoo account but I don't know what'll happen to my flickr pics and contact I use once in a year. And yes, I still use it.

The daisy-chaining of email addresses that may or may not be active anymore (some due to ISP going out of business) and stupid security questions that I can't remember (who was my freaking favourite author in 2002 ?!) turned this into a real clusterfuck.

Re: Thanks For The Identity Theft, Yahoo

#8
1. Yahoo has official email ids which no longer work (but were functional in the past). Are these also up for grabs? Or, are some email ids "more equal than others"?

2. Websites with paid access. There are people who sign up and do not access these sites for a long time. If the person who signed up with his Yahoo email id no longer uses it (the email id) now, there is the danger of someone claiming that email id and then using the "Forgot password" option on one of these paid websites. Most of them send your password to your email id, or send a link to reset it.

Boom. You now have access to their personal information (and possibly credit card/bank details) as well.

Edit: Even free websites quite often store personal information, for that matter.

Re: Thanks For The Identity Theft, Yahoo

#9
This is gobsmackingly awful. Their 'relax we won't let people use this to hijack accounts on other services solution is to check incoming email for a new header. a new header that yahoo invented.[1] good luck getting every web based sign up site with email password reset to update their email service.

1. http://www.wired.com/threatlevel/2013/07/yahoo-email/

Re: Thanks For The Identity Theft, Yahoo

#10

The freaking problem with that is that I couldn't retrieve in time my lost password to my old yahoo account I used for flickr. Don't care that much about the yahoo account but I don't know what'll happen to my flickr pics and contact I use once in a year. And yes, I still use it. The daisy-chaining of email addresses that may or may not be active anymore (some due to ISP going out of business) and stupid security que…

As far as I know logging into Flicker will keep your account activated.
Post reply on HN