Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Yahoo Mail Passwords: Act Now
Threaded  |  Newest First  |  Oldest First
Drew Conry-Murray
50%
50%
Drew Conry-Murray,
User Rank: Ninja
1/31/2014 | 10:20:38 AM
Just one password?
If I have to create a really long password to ues a password manager, why not just use that really long password for every site instead of having a password manager in the first place?
krassofnod
50%
50%
krassofnod,
User Rank: Apprentice
1/31/2014 | 11:10:42 AM
Re: Just one password?
because if you use a single passwrod for everything if that password gets hacked anywhere, the hacker has access to everything
Drew Conry-Murray
50%
50%
Drew Conry-Murray,
User Rank: Ninja
1/31/2014 | 11:12:10 AM
Re: Just one password?
But wouldn't that happen if a hacker hacked my password manager password too?
krassofnod
50%
50%
krassofnod,
User Rank: Apprentice
1/31/2014 | 11:22:28 AM
Re: Just one password?
yes which is why i don't use it either, I just memorize 10 different crazy difficult passwords and change them ever 2-3 months
Drew Conry-Murray
100%
0%
Drew Conry-Murray,
User Rank: Ninja
1/31/2014 | 11:31:54 AM
Re: Just one password?
I can't tell if you're being sarcastic. If you're not, I salute your dedication to password hygenie (and your memory!)
krassofnod
50%
50%
krassofnod,
User Rank: Apprentice
1/31/2014 | 11:38:39 AM
Re: Just one password?
honestly no sarcasm intended and thank you
Susan Fourtan
50%
50%
Susan Fourtan,
User Rank: Apprentice
1/31/2014 | 12:01:13 PM
Re: Just one password?
krass, 

Just wow! I should follow your example on password dedication. I think I have become a little lazy about passwords lately. 

-Susan
ChrisMurphy
50%
50%
ChrisMurphy,
User Rank: Strategist
1/31/2014 | 3:30:27 PM
Re: Just one password?
Does anyone else get a bit numb to these warnings? I know I should change my password, I believe this is true, but ... 
Laurianne
0%
100%
Laurianne,
User Rank: Apprentice
1/31/2014 | 3:47:40 PM
Re: Just one password?
Chris is right. Password fatigue is a big deal. And if you're thinking, who's still using Yahoo Mail, I saw someone using AOLmail on a plane the other day. No joke.
anon7244892334
100%
0%
anon7244892334,
User Rank: Apprentice
1/31/2014 | 4:44:36 PM
Re: Just one password?
What's so shocking about someone using AOL mail?  It's reliable, doesn't have hacking issues, and filters spam well.  Seems like a smart service to use.
anon7244892334
100%
0%
anon7244892334,
User Rank: Apprentice
1/31/2014 | 4:47:27 PM
Re: Just one password?
Yes of course, but the probability that someone will hack your password manager versus hacking any of a multiple of sites/accounts where you're using the same UN/PW is substantiall lower.  The likely culprit in this case of Yahoo was probably not a very secure site.
Susan Fourtan
50%
50%
Susan Fourtan,
User Rank: Apprentice
1/31/2014 | 6:37:16 PM
Re: Just one password?
anon, 

"The likely culprit in this case of Yahoo was probably not a very secure site."

Exactly. Yahoo! Mail has never been secure. It has had plenty of hacking problems. I am not surprised about this new one at all. 

-Susan
Susan Fourtan
50%
50%
Susan Fourtan,
User Rank: Apprentice
1/31/2014 | 12:25:55 PM
Re: Just one password?
Drew, 

What makes you think that using just one password is better than a password manager? 

-Susan
Drew Conry-Murray
50%
50%
Drew Conry-Murray,
User Rank: Ninja
1/31/2014 | 5:01:29 PM
Re: Just one password?
I'm not sure it's better, but if I need to create an insanely complex password to protect my password manager, why not just use that insanely complex password everywhere and save myself the trouble of the password manager?
AmericanPrivacy
100%
0%
AmericanPrivacy,
User Rank: Apprentice
1/31/2014 | 10:30:42 AM
Still think your free email is free? Think again
So News has broke that Yahoo emails have been compromised. This does not surprise me in the least. Did you know that Google, Yahoo, Hotmail, AOL and other service providers are scanning, analyzing and categorizing your emails every day? As a result, these numerous providers are pleased to give you a "free" email service because they generate large revenues for themselves through the selling of your personal information to third parties! That's right third parties! Exactly who yahoo is blaming for this data breach!!
100% Privacy guaranteed. At americansrighttoprivacy.com you will remain anonymous as we DO NOT and WILL NOT copy, scan, or sell any of your content. Our email service is 100% privacy guaranteed. Privacy is not only a human right but also required to survive in a competitive business environment. We are very serious about protecting your electronic communications and due to the strict restrictions of the U.S. Patriot Act for law abiding citizens, we cannot align ourselves with servers located in the United States. Therefore, our servers are located in Switzerland where strong data privacy laws do not abide by the U.S. Patriot Act.
Kristin Burnham
50%
50%
Kristin Burnham,
User Rank: Apprentice
1/31/2014 | 1:06:50 PM
Password managers
I'm sure most people are aware that they shouldn't be using the same password for multiple sites, but it's a cumbersome habit to break. The article recommends using a password manager. Which are your favorites?
Shane M. O'Neill
50%
50%
Shane M. O'Neill,
User Rank: Apprentice
1/31/2014 | 4:36:26 PM
Re: Password managers
I don't trust that a password manager can't be hacked. So I continue on in the living hell that is memorizing passwords and keeping them on a piece of paper hidden in my house. 
jgherbert
50%
50%
jgherbert,
User Rank: Apprentice
1/31/2014 | 9:51:24 PM
Re: Password managers
@Shane M. O'Neill:

"I don't trust that a password manager can't be hacked. So I continue on in the living hell that is memorizing passwords and keeping them on a piece of paper hidden in my house. "

That's _so_ 1980s. Anybody with any self respect would use Post-Its stuck to their monitor, surely?

I must confess that I am about at explosion point with passwords, especially with every site having different requirements for password strength. SSO has issues but I gotta tell you, right now I am all about some kind of federated SSO across web sites. 

I do use a password manager by the way, but there isn't a single product that I've yet found that works consistently across (in my case), windows, linux, OSX and iOS, and integrates with the web browser so that I don't have to jump between applications all the time to find and then paste in a password. Especially on a smartphone that's a huge pain.

 
Susan Fourtan
50%
50%
Susan Fourtan,
User Rank: Apprentice
1/31/2014 | 6:26:00 PM
Re: Password managers
Kristin, 

I can see how the habit of using the same password for multiple sites could have started for many.

If you have to sign in to ten, or more sites daily you may well forget some of the passwords. One password for all can solve the problem. It brings others, as we know. 

Chrome offers the option of remembering passwords. I choose this option to certain sites. Some other times I ask for a new password. This is handy for sites I don't use frequently. It's faster and easier than trying to remember a password I use a few times a year. 

For the important passwords I don't use a password manager at the moment. I have a password formula. 

-Susan 
Kristin Burnham
50%
50%
Kristin Burnham,
User Rank: Apprentice
2/1/2014 | 9:20:08 AM
Re: Password managers
I choose the option to have my browser remember most of my passwords, too. But it's the worst when you're required to clear cookies and other settings for some reason and all your passwords are cleared. Password hell all over again.
Li Tan
50%
50%
Li Tan,
User Rank: Apprentice
2/3/2014 | 1:45:14 AM
Re: Password managers
The best practice to my experience is using the same password with sufficient complexity for all your internet accounts. This sounds nothing new but sometimes it's difficult to handle it in this way due to various constraints from different web sites. Furthermore, I normally chose not let web browser to remember my password - it does not take me long to enter the password everytime and it helped me to remember it. 
Susan Fourtan
50%
50%
Susan Fourtan,
User Rank: Apprentice
2/3/2014 | 6:00:59 AM
Re: Password managers
Kristin, 

"I choose the option to have my browser remember most of my passwords, too. But it's the worst when you're required to clear cookies and other settings for some reason and all your passwords are cleared. Password hell all over again."

I know! I went through password hell this past weekend. I had to reset my FB password, which is always easier that trying all the password formula alternatives and all the possible combinations I can think of I used for a FB password.

I am still waiting one my online libraries to send me a new password. :( 

-Susan

 
M_Gordon
50%
50%
M_Gordon,
User Rank: Apprentice
2/3/2014 | 1:08:32 PM
Re: Password managers
Kristin,

You should check out LastPass, it's a really useful password manager. It allows to use many different and strong passwords without having to remember each one. They also have an security add-on option, Toopher, which adds another layer of security to each of your accounts in LastPass. It's extremely user friendly and uses location awareness of your smartphone to automate the authentication process. Check out this video, it helped me better understand what Toopher does. http://www.youtube.com/watch?v=k78xDTpy7PU
joe9804
50%
50%
joe9804,
User Rank: Apprentice
6/23/2018 | 6:47:27 PM
I want to share my personal experience.
After watching your article I want to share my personal experience with you guys. Some days ago I was a yahoo mail user. But I don't know how one day my account was hacked. I searched for Yahoo support in the Google and found some company. One of them is Yahoo Support Number. I called them but they didn't solve my problem. Then I contact some other support but no one can recover my account. Then I can understand that the problem is in Yahoo itself.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Enterprises are Attacking the Cybersecurity Problem
Concerns over supply chain vulnerabilities and attack visibility drove some significant changes in enterprise cybersecurity strategies over the past year. Dark Reading's 2021 Strategic Security Survey showed that many organizations are staying the course regarding the use of a mix of attack prevention and threat detection technologies and practices for dealing with cyber threats.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5669
PUBLISHED: 2021-10-26
Cross-site scripting vulnerability in Movable Type Movable Type Premium 1.37 and earlier and Movable Type Premium Advanced 1.37 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-40343
PUBLISHED: 2021-10-26
An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios user to elevate their privileges to the root user.
CVE-2021-40344
PUBLISHED: 2021-10-26
An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary extensions as long as the MIME type corresponds to an image. Therefore it is possible to upload a crafted PHP script to achieve remote command execution.
CVE-2021-40345
PUBLISHED: 2021-10-26
An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injection (within the name of the first file in the archive) allows an attacker to execute system commands.
CVE-2021-42343
PUBLISHED: 2021-10-26
An issue was discovered in Dask (aka python-dask) through 2021.09.1. Single machine Dask clusters started with dask.distributed.LocalCluster or dask.distributed.Client (which defaults to using LocalCluster) would mistakenly configure their respective Dask workers to listen on external interfaces (ty...