Thanks For The Identity Theft, Yahoo
b0ing.me
b0ing.me
Because if you're not using that Yahoo account for e-mail anymore, then you're probably not using it as a sign-in or password recovery e-mail for your banking, Facebook, or anything else important -- because the whole point is, everything that's actually important to you, you're using your current e-mail address. After all, that's where important account notifications go, credit card receipts, bank statements, password resets, etc. -- things which are necessary for you to see.
Of course you'll likely have a bunch of accounts you forgot even existed on random sites you signed up for in the past, with your old Yahoo e-mail address. Most of them will be harmless -- who cares if someone gets access to some random sports forum you once posted on.
The biggest risk I can see is that 1) the new owner chooses to be malicious, 2) successfully locates a site that sends out password-recovery emails with the original passwords in plaintext, which the specific user has an account on, 3) knows the original user's current valid address, 4) tries the old password on the user's new address they use with banking/etc., and it works. But the risk of this would appear to be so small, that it's just lumped in with all the other kinds of "identity theft" weaknesses that already exist (guessing security questions, etc.).
(And then, there's scamming on whatever social networks or forums the old e-mail address had an account on. Although it seems like Facebook etc. is protecting against that? And it's not like spoofing e-mails/accounts is anything new.)
As long as Yahoo is giving significant heavy warning to the e-mail accounts themselves, and months' worth of time -- well if you never check your free e-mail account, it's not unreasonable to expect that it might be deactivated someday. Annoying, but not unreasonable. And if you use the same password for your Facebook, banking, etc. as you did for other random sites you signed up for years ago, then that's a security risk regardless of what Yahoo does.
Imagine the fun that could be had if Hollywood decided to 're-use' old stage names. We could get a bunch of new John Wayne movies!
Sorry if I missed out on some new (or old...I have no idea) thing here, but I've never heard of you nor your site. Is this suppose to be some alternate blog/identity for some other semi-famous tech writer or something?
Again, I apologize for not being hip or "with it" in regards to who you are. But you tend to obscure who you are on both your site and twitter feed. Why?
Hopefully, Yahoo would also find themselves vulnerable to at least one of the obvious legal attack vectors and wind up paying out a small fortune in compensation to make good on losses due to identity theft and/or frauds committed using false identities they supported. This could be an educational lesson for a lot of businesses that don't take privacy and data protection seriously today because collecting everything you possibly can about everyone is seen almost pure upside with little real cost or risk.
Isn't the real problem that users and services put too much trust in plain email addresses? Especially when accounts are outdated? Crypto might help here someday in the future.
We could even say: Isn't it your fault that you didn't keep track on which services you used that email? Or that you lost your password? Why blame Yahoo for that?
And while some other email providers do the same, it's particularly bad with yahoo because they are such a huge and longstanding provider, they have tons of email, some that are a decade old, and a lot owned by people who are not very technical or who don't check their email very often.
As I user, I have to update my email address I use and other services should delete inactive accounts, too. Or at least notify inactive users. I know, especially the latter option is more or less inexistent. But although think of all the data that users have no access to, because of lost passwords etc. I rather see that deleted.
Also, if Yahoo is doing things right, they would only delete accounts with no activity for a serious amount of time, e.g. no access, not even POP3 since over 2 years.
But on the other hand, Yahoo is a falling behemoth that is trying to earn itself a new image; and doing such a stupid move can and will earn them the mark that they still "don't get it", and rightly so.
I just don't see it that wrong like you do. I wonder, if there is an argumentation to really call them stupid. And I don't even think this is relevant referring to their image.
As you said, this only affects people who aren't either informed about computer topics, don't know they had a Yahoo mail at all or who simply reregister their old mail address.
I had setup my mom's email on Yahoo (cause Gmail didn't exist and Hotmail, freshly bought by MS, was rubbish). She had a habit of entering it to everything and was soon unusable. We went over online browsing and safety, but not before her private info ended up on a dozen or so spammy sites. That was more than 10 years ago.
There's no way to reset the password for that thing, since backup emails weren't present plus IT WAS MORE THAN 10 YEARS AGO! Also, she doesn't have a Facebook page, doesn't want a Facebook page and will likely never get one in the future. She's done handing out her info to people she doesn't know.
I'm sure some of her info is still on it, but if Yahoo goes through with this, there will be hell to pay.
Because having your identity stolen can pretty much destroy your life, or at the very least cause you a great deal of suffering for many months. This change would mean a tiny oversight from many years ago could allow those things to happen.
It's also a paradise for fraudsters and charlatans, who will have a bountiful source of new identities to build on if they can just find someone who has since died or can otherwise be assumed not to need an old account any more.
When I tried to reset a password recently, I got "your password is too weak" for every password I tried, including very long randomly-constructed not-previously-used passwords resembling line noise. This after carefully making sure both entries of the password matched. Multiple times. The form simply does not allow the user to proceed, and it gives false reasons. It is broken.
I sign up for a service using my Yahoo email account. I don't use my Yahoo account for a year. Someone gains access to my email address. That person enters my email address into a forgot password field. Boom They now have access to my service.
As another poster stated, the mind boggles.
I was hoping they had retained all my old emails so I could go trough and find any exposures. Unfortunately, once an account is deactivated, the emails are gone - even if you log back in with the same password. Deleting the emails from the dormant account is probably the right thing to do, but it makes it impossible to see what sites I may have used the Yahoo email account to register with.
But I grew up before Facebook and other social networking fads. I still don't use those services. So I sometimes forget how easy it is to get a very good life history on someone by just searching their email address, very possibly including the answers to typical "secret questions" like your pet's name, where you went to elementary school, etc. and maybe I can even get some clues about what bank they use.
So it really might not be too far-fetched a concern. Still I think it somewhat unlikely that an email account tied to a lot of social networking activity is itself going to be dormant. But it's possible. Maybe the person has the account forwarded to another address and never logs in directly. Would that count as "dormant" ??
Before issuing an account, Yahoo themselves should be sure it's not forwarded, and search for any associated internet content, especially on social media. If an account has not been used in years, AND internet searches for that account turn up nothing, it might be safe to reissue it.
It's not that hard, actually, considering that most websites you sign up for send periodic marketing emails. You're the new owner, you get a marketing email addressed at the old owner, hit the "forgot my password" link, and you have ownership of the account.
Once these start appearing in the inbox, the new owner can just do a password reset on these sites.
2. Websites with paid access. There are people who sign up and do not access these sites for a long time. If the person who signed up with his Yahoo email id no longer uses it (the email id) now, there is the danger of someone claiming that email id and then using the "Forgot password" option on one of these paid websites. Most of them send your password to your email id, or send a link to reset it.
Boom. You now have access to their personal information (and possibly credit card/bank details) as well.
Edit: Even free websites quite often store personal information, for that matter.
Don't care that much about the yahoo account but I don't know what'll happen to my flickr pics and contact I use once in a year. And yes, I still use it.
The daisy-chaining of email addresses that may or may not be active anymore (some due to ISP going out of business) and stupid security questions that I can't remember (who was my freaking favourite author in 2002 ?!) turned this into a real clusterfuck.
I had an @att.net email address from when I had U-Verse that was essentially Yahoo mail with an ATT address. I thankfully didn't do anything on that account, but I kept it since it was the same user name I have registered on most major webmail services.
I got an email about a year ago that those addresses would be merging with Yahoo, and that my address would now be @yahoo.com. Fine with me, I thought, perfect if I ever wanted to try out Yahoo mail for a spell.
A few months later a get an email about my password being changed. Not good. From there I had about a 15 minute back and forth with someone else trying to get their information(alternate email address, password, security questions, phone number for 2-factor) on the account to lock me out. I prevailed, and in double checking how that person could have gotten access, found something disturbing. This was not my email account. It was mostly dormant, but there were legitimate emails from years ago sent by another person who shares my name.
I contacted Yahoo through their form about such matters, but they never answered. So now I've held on to the address, which I value for preserving my internet identity, but someone else is out of luck in trying to access an account they used sparingly years ago.
This is obviously much worse, as it's intentionally going to result in these types of account ownership issues, but it certainly seems reflective of Yahoo's attitude towards the importance of holding an email address.
This would not have been good if it had been given away.
You have literally not looked at any of the receipts in 2 years? If you've cancelled any of the credit cards, you had no idea that there was an autopay problem? The merchants had no way of contacting you, because you never checked that email?
That doesn't make any sense to me. Or was it just forwarding the emails to the account you do use, or whatnot? In which case, I assume that Yahoo would be sending emails warning of the upcoming account closure, which you could receive and act on?
For me, this is done through the web interface in almost all cases. Did my hosting account try to charge my credit-card and it was declined? It'll show up in the account dashboard. Do I want to look at my Amazon receipts? They're under Your Account -> Your Orders.
I'm updating some old emails now since I was reminded of it, but generally I don't care about receiving email from websites, so I typically send them to an account I don't check in order to keep them out of my way, and to ensure that if they sell my email, the spam will go there too (in my case it's an old AOL account). A number of sites won't even send you anything via email except "please log in" anyway. For example, when my bank sends me a "bank statement" by email, all it contains is a notification that there is a new bank statement waiting online, if I want to log in and read it. So the email is not needed or useful for services where I already log in regularly.
As for warning emails, I had a backup email listed with them, and I have received nothing on either the backup email or the Yahoo email warning of this potential problem.
That will sufficiently annoying so that only people that really wants back their email and commit to it will stay.
It's not without flaws but it's a tad better than their current plan.
This isn't a huge problem for me, as I try to keep up with tech news, but imagine that I'm not subscribed to hacker news, and don't realise what's about to happen to my account, in that case there's no possible way for me to rescue my email in time, and every account I've used it for is compromised.
Are the advocates of "right to be forgotten" supporting this?
This could be interesting.
shudder
I think there's been a lot of lessons lately about why Internet should not be centralized...