Vulnerabilities / Threats
3/6/2014
07:39 AM
Kristin Burnham
Kristin Burnham
Quick Hits
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Yahoo Unfriends Facebook, Google Sign-In

Yahoo drops third-party logins, will soon require Yahoo IDs

If you use your Google or Facebook credentials to sign into Yahoo services, you'll soon be out of luck: The company said it will end this process and require everyone to use a Yahoo ID instead.

"Yahoo is continually working on improving the user experience," a Yahoo spokesperson said in a statement. "This new process, which now asks users to sign in with a Yahoo username, will allow us to offer the best personalized experience to everyone."

Read the full article here.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kristin Burnham currently serves as InformationWeek.com's Senior Editor, covering social media, social business, IT leadership and IT careers. Prior to joining InformationWeek in July 2013, she served in a number of roles at CIO magazine and CIO.com, most recently as senior ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
rpbrennan
50%
50%
rpbrennan,
User Rank: Apprentice
3/7/2014 | 10:05:28 AM
re: Yahoo Unfriends Facebook, Google Sign-In
Faceplant auth: bad for security, bad for privacy. What's not to (un)like?
shjacks55
50%
50%
shjacks55,
User Rank: Apprentice
3/7/2014 | 4:34:00 AM
re: Yahoo Unfriends Facebook, Google Sign-In
Piss poor security to let Facebook be your log-in manager.
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3562
Published: 2014-08-21
Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory.

CVE-2014-3577
Published: 2014-08-21
org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-...

CVE-2014-5158
Published: 2014-08-21
The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary commands via unspecified vectors.

CVE-2014-5159
Published: 2014-08-21
SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL commands via the ws_data parameter.

CVE-2014-5210
Published: 2014-08-21
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.