back to article Yahoo! Mail! offers! HTTPS! amid! account! hijack! spree!

Yahoo! is now offering to encrypt its webmail service with HTTPS for security-conscious users. Meanwhile, an exploit that allowed anyone to hijack Yahoo! Mail accounts if victims clicked on a link was being flogged to cybercrims for $700. The HTTPS development, which is not enabled by default, affords Yahoo! webmail users …


This topic is closed for new posts.
  1. Martin 47

    Seems to be enabled by default in the android app, which is nice

  2. Anonymous Coward
    Anonymous Coward

    Yahoo webservices are a festering pile of exploitable crap.

    Turning on https might be good PR, but I doubt it'll fix their broken code.

  3. BJC

    Not on BT Yahoo accounts

    I've just checked my BT Yahoo account and I see no such option.

    1. Ed 13

      Re: Not on BT Yahoo accounts

      I'm glad I was being blind. I couldn't see it either.

      Looked in Classic and New modes too...

  4. Phil W

    Yahoo! are still in business?

    I can't beleive it tbh, their services are crap.

    I can find no reason to use yahoo over many of the other much better providers.

  5. Dan 55 Silver badge

    Yahoo does something right at last

    Only they don't, the SSL option isn't available on Classic Mail.

  6. Anonymous Coward
    Big Brother

    Deep Packet Inspection of SSL-Encrypted Traffic

    "Deep Packet Inspection of Secure Socket Layer (DPI-SSL) extends SonicWALL’s Deep Packet Inspection technology to allow for the inspection of encrypted HTTPS traffic and other SSL-based traffic.

    The SSL traffic is decrypted transparently, scanned for threats and then re-encrypted and sent along to its destination.

    if no threats or vulnerabilities are found. DPI-SSL provides additional security, application control, and data leakage prevention for analyzing encrypted HTTPS and other SSL-based traffic." link

    1. Fuzz

      Re: Deep Packet Inspection of SSL-Encrypted Traffic

      This is installed in a business situation where you can create your own trusted root and deploy it to all the computers in the business. The trusted root is used to sign a wildcard certificate that the sonicwall box uses to do the encryption.

      I would guess that if you have that rapport software installed that banks like people to download it would flag this as dodgy since the certs wouldn't match.

  7. Morac

    Unfortuantely Yahoo's SSL usage is flawed

    When I turned on the SSL on my Yahoo Mail account, Yahoo Mail proceeded to keep asking me to log in when I took any action. I basically got stuck in an endless loop of being forced to log in over and over again without being able to do anything.

    The reason this happens, is because Yahoo is mixing SSL and non-SSL content on the page and the SSL content is referencing non-SSL content (and vice-versa). This causes the page loads to fail since most browsers (I was using Firefox) won't allow mixed content and Yahoo interprets this as needing to log in again and puts up a login page.

    Basically enabling SSL breaks Yahoo Mail. I managed to get in to the options using an old version of Internet Explorer (which allows non-SSL from SSL) and could turn off SSL. After that I could use Yahoo Mail without issue.

    The mobile version already uses SSL and if I need encryption, I just change the http to https after going to the Yahoo Mail page.

  8. Ian Yates


    Wasn't aware of this exploit and told my cousin to change her password when I got some spam from her account. She did, but 12 hours later it happened again so I told her to change it to a completely different and more complicated one.

    Feeling a bit mean now...

  9. Shannon Jacobs

    Yahoo should just MARRY the spammers

    Yahoo is such a sick joke I really can't understand how they are staving off bankruptcy. They're main residual value is their email system, and it's the worst of the majors--unless you're a spammer, in which case Yahoo is #1 for helping the spammers.

    Where to begin? I guess the way they forcibly split the headers from the email? Even if you want to fight the spammers, Yahoo makes it almost impossible to get a real look at what the spammers are doing. Naked headers are something of a sick joke these days. The spam is almost always coming from throwaway addresses and is just bait for suckers. The real payloads are routed to websites or other email systems.

    It's kind of weird. The spammers are holding up giant signs (especially on Yahoo) saying "Look at me! I'm a stinking criminal!" And yet their business models continue to work--or the spam would trail off.

    What I want is some effective anti-spammer tools build right into a VALUABLE low-spam email system. I want to go after ALL of the spammers' infrastructure, chase ALL of the spammers' accomplices, and even help and protect ALL of the spammers' victims. They aren't all idiots, after all. Consider the reputable companies who's valuable reputations are "harvested" by the spammers phishing for their trusting customers.

    In short, Yahoo should try to turn some of that spammer hatred into Yahoo love. If not, then death to Yahoo only seems fair. Yeah, it will be a big inconvenience for a lot of people--but a BIGGER inconvenience for the spammers.

  10. Maryland, USA
    Thumb Down

    Enough! already! with! the! Yahooesque! exclamation! marks!

    It! was! funny! the! first! jillion! times!

  11. Anonymous Coward
    Anonymous Coward

    Yahoo! Lies! Again!

    There is no such option on Yahoo Classic Mail.

    Perhaps the story should say "Yahoo! Still! Does! Not! Make SSL! The! Default!

This topic is closed for new posts.

Other stories you might like