A grandmother who has barely learned how to use email died in 2012.
Her friends are all in their 80s and only send 1 email a year.
Someone new registers the account and then... Then, the Holiday season in 2013 roles around and all of a sudden a new person is receiving emails from another person's friends.
At that point, the scams they could pull off would be insanely easy.
Additionally: Any sensitive material intended for the original person would instantly be compromised.
Yahoo is playing a somewhat dangerous game. The better option would have been to buy a domain name similar to Yahoo.com and use that.
[ADDED] Now I'm really mad. I tried logging in and it requires me to send an email to an account I had when I signed up for yahoo 10 years ago to log in because it "doesn't recognize my device". Just like Google there is no way to email them or contact them. Unacceptable. There is no way for me to log in to my account.
Same here. In this case the device is the same browser I've been logging in with daily. The back-up email is one that hasn't existed for a decade, and the "secret questions" for which I generated random number answers and carefully saved don't match.
That's on a mostly throw-away account, so I don't care too much. On a more regularly used account I just checked I was able to log in fine. My email inbox is page upon page of spam that should be easily filtered on their end, but at least I can get in.
choose,
Product: Yahoo Account category: Password and signin sub-category: My issue doesn't appear on the list
Maybe I'm just being naive, but it seems to me that someone getting a letter addressed to you is much less of an issue than someone getting your email.
The web runs on the assumption that you have access to an email address and you'll never lose control of it. Ignoring that assumption and opening up your old users to identity theft just because you want to reissue short usernames that will again be squatted on is kind of crappy.