Log in to Yahoo by July 15th to keep your email address
yahoo.tumblr.com
yahoo.tumblr.com
I have a month to compile a list of the most popular first and last names and popular e-mail names and get a bot ready to register them all.
Once registered, I can then attempt password recovery for these @yahoo.com email addresses at the most popular web sites across the Internet that rely on established identities (ebay.com?).
If JamesSmith@yahoo.com ever used his yahoo id to register an account on EBAY.com, or with another online service, now is my chance to try to steal his online accounts by requesting password resets on these services and assuming his identity.
Now, to build a bot that will do this thousands of times!
Sites with 2 factor authentication may be immune to this, but these identities will now be unrecoverable to somebody who has used his @yahoo address as his recovery e-mail address, even if he doesn't check it often.
At the very least it will cause confusion. At worst, accounts will get hacked.
Someone could turn my life upside down if they had access to the hotmail account that I use to sign up for services that I know will spam me.
I've actually run into a few services that won't accept signups from any "free webmail" provider, usually listed as Hotmail/Outlook, Yahoo, and Gmail. I suspect the reason for such policies is worries about spammy new accounts, but the risk of account lapse followed by impersonation might be another reason to favor such a policy. On the other hand, it would also lock out a number of legitimate users who use one of those services as their main or even only email.
2. Claim as many of those E-mail addresses as you can
3. Hold your newly acquired domains hostage for $$$
Yahoo better act like they know what they are doing. I'm sure their technical team does, but management doesn't always listen to the engineers, sometimes management just says "MAKE IT HAPPEN."
Even if that person wasn't doing it for nefarious purposes that would completely defeat Yahoo's whole goal here of getting these names in the hands of users who actually want to use them.
Meaning, you get what you paid for and if your usage of said service falls outside of an expected range then don't be surprised if your service is suspended.
It's 2013. I feel like this particular lesson should be well established, public domain knowledge but here it is again:
Free data, storage and associated services means that you are the product. If a provider decides to discontinue a particular product line, that really is their prerogative. If you want otherwise, then pay for the services you use and rely on and then you'll have a valid complaint if they are suspended.
There is a lot of problems with this from both from security and moral points of view.
Now, thanks to this move by Yahoo, your Google account is in danger of being compromised.
> Twitter is not currently releasing inactive user names. Unless your user name issue involves Terms of Service violations, you'll have to wait until all inactive user names are released. We're working on a better long term solution for this, and we should have more news soon.
Four years later, the username I want(ed) has had no more activity, and that "long term solution" is nowhere to be seen.
If you think your identity could be stolen because of an unused email address, it might be your fault that's going to happen. Why would you register with an inactive email address and not check it? Email address seem like the main way for most people to login, if you have multiple, you must at least check them for something once every six months.
This announcement only says that they will remove those that haven't logged into their account in the last 12 months. Seems like a very long time in internet time.
I haven't used that paypal account or that email address in years. A while back I realised the folly of this and removed as much information as I could from the account.
But, what if I'd just forgotten about it? Now anyone who registers my (common) yahoo email, attempts a password reset on the popular websites, can drain my bank account.
(1) "Resell" is the not quite accurate word here as they are going to give it for free, but I can't come with a better word.
The point is email address arent just for getting emails, they're used as identities online.
How horrible and shortsighted. Yahoo is actively inviting ill will and complexity.
A simple query would show that these vanity addresses are sitting stagnant. A touch of PR and awareness instills or revives interest.
I think an optimistic view is that Yahoo! is willing to cut the fat and take chances on reuniting strayed in addition to inviting new users.
If thomasted110 is the best what's available for now at yahoo, there will be, simplifying a bit, 109 another unhappy users (thomasted1..thomasted109) + tedthomas_xx users + other unhappy Ted Thomases settled for different username at yahoo.com.
None of them is aware if tedthomas will be available. Most of them will not even know that this grand redistribution will take place. In the end if tedthomas will be "reused" only one of them will be moderately happy, while others are no better of.
I thought about snagging something short and nice (like my initials) just for kicks, but...am really not sure what I'd do with the account after I had it.
I think the title of this post could be amended to make it a little more reflective of the actual post.
Also, what about other accounts on the web that are linked to the email address? Many web sites allow you to reset your password by proving that you own the email address a user was originally registered with.
This seems like a spectacularly bad idea on Yahoo's part. I can't make any sense of it.
Regular: foo@gmail.com
Password recovery: foo.special.admin.email@gmail.com
e.g. Joe Public hasn't logged into joe.public@yahoo.com for a year because he has taken a year off to live in a Buddhist monastery. So Eve goes in and signs up for that address, without any malicious intent.
Fast forward to a week later, when Eve signs up for CatNip, a website for sharing cat pictures. It says "You are already signed up for this service. Click here to send a password reset link to your email!" Eve can't resist the allure, and clicks through.
One click later, Eve has access to all of Joe Public's cat pictures on CatNip. (Even though she didn't really sign up for the address with the express intention of getting them.)
Let's say JamesSmith@yahoo.com used this email address long ago as his ebay recovery address, but really doesn't use his @yahoo account any more. I can register JamesSmith@yahoo.com, and use ebay's account recovery option to assign the ebay account a new password for an ebay account I have now stolen.
This scenario isn't possible with an online game account name, as game accounts aren't used to recover bank passwords or other important account passwords.