26 May, 2013
News Channel – Mind Processors
times-of-indiabbc-news
cnet-newsyahoo-newsApple-newsgoogle-newsmsnbc-newscnn-newsfox-news
Skip to content
  • Home
  • Technology
    • Gadgets
    • Hardware
    • Software
    • Innovations
    • Linux
    • Open Source
    • Science
    • Telecom
    • Wireless
  • Business Tech
    • Eco-Bizz
    • Global Leaders
      • Apple
      • Google
      • Intel
      • Microsoft
      • Yahoo
    • Research
    • Politics & Law
  • Mind Processors
  • Gaming
    • News & Features
    • Playstation
    • X-Box
    • PC
    • Reviews
  • Security
  • Web
    • Social Media
  • Video
  • More
  • Subscribe
Follow @mindprocessors
Web Hosting Mindprocessors

Yahoo mail enables encryption, battles security flaw

Posted on January 10, 2013 by Source: msnbc.com
Tweet

Yahoo has finally given customers what Facebook, Gmail and Twitter users have had for years: the option to always enable HTTPS secure, encrypted browsing for all their Yahoo Mail activities.

Yahoo mail enables encryption, battles security flaw
Without HTTPS, a user’s online data can be accessed, stolen or destroyed by attackers with access to the same open network, such as the Wi-Fi hotspot in an airport, café or hotel.

“We’re really happy that Yahoo! is starting 2013 right by letting Yahoo! Mail users use HTTPS to access their e-mail accounts securely,” the Electronic Frontier Foundation’s Seth Schoen said in a blog posting Monday.

The EFF has long advocated HTTPS encryption for all communications, and even sent a letter in November to new Yahoo chief executive officer Marissa Mayer asking for its implementation in Yahoo services.

HTTPS is not enabled by default in Yahoo Mail, but users can quickly turn on the new feature by going to their Mail Options screen, choosing “General” and selecting “Turn on SSL.”

Close one door, and another opens
Unfortunately, HTTPS won’t stop every malicious attack, as a security researcher in the United Arab Emirates demonstrated Jan. 6.

Shahin Ramezany posted a YouTube video demonstrating a cross-site-scripting (XSS) flaw that allowed anyone with the right code and technical knowledge to access strangers’ Yahoo accounts.

Using professional debugging tools and special code that he said he won’t reveal until the flaw is fully patched, Ramezany showed that user cookies could be captured by a malicious website, then transferred from one Yahoo user to another, giving the second user access to the first’s account.

(Ramezany said on his Twitter feed that he had given Yahoo full details before posting the video.)

The exploit seems very similar to one that we reported on in November and which was being sold in underground online bazaars for $700. At that time, Yahoo was said to be working on a patch.

The Next Web tech blog suggested that Ramezany’s video was linked to what the blog perceived as a rash of break-ins to Yahoo Mail accounts beginning Sunday evening.

The Next Web’s evidence — complaints on Twitter from Yahoo users whose accounts had been hacked — was circumstantial at best. Twitter searches for “Yahoo hacked” will return results on almost any given day.

Fixed or not?
Tuesday, Yahoo told The Next Web that the flaw demonstrated by Ramezany had indeed been fixed.

Ramezany disputed that.

“Yahoo! patched the vulnerability but patch was not effective enough and users are still in risk,” he tweeted, pointing to a blog posting with a video that showed the exploit still working.

Yahoo Mail users can protect themselves, at least to some degree, from the XSS exploit by running robust anti-virus software that screens websites for malicious content. (That applies to Mac, iOS, Android and Linux users as well, since XSS flaws don’t discriminate among user platforms.)

To be truly sure, avoid clicking on unknown links in Yahoo Mail messages until the flaw is fully patched.

Related Post

  • 50 million compromised in Evernote hack
  • Email hacking: How to minimise risk
  • iOS 6.1 hack lets users see your phone app, place calls
  • Why your Google, Facebook accounts may be unsafe
  • 5 things every computer user needs to know how to do
  • Posted in Technology and tagged email, encryption, flaw, HTTPS, Security, yahoo-mail.Bookmark this post.

    Comments are closed.

    CompUSA
    • Recent Posts

      • Planck satellite: Esa to release maps of ancient light
      • Nvidia unveils virtual graphics server in push beyond PCs
      • Google Maps climbs world’s tallest mountains
      • Congress hears options for asteroid defense: Pay now or pray later
      • New Lizard Species Look Like Evil Dinosaur Hybrids
    • Subscribe News


    • Recent Comments

      • Kirk on Groupon launches credit card payment business to compete with Paypal
      • Green Bay Packers on Steve Jobs better career role model than Obama: Survey
      • MBT Women Shoes on HR checking candidates’ background on FB, Twitter, Google
      • sexleksaker on Facebook suspends photo tag tool in Europe
      • cbn grinding wheels on Aquarium releases 655-pound sea turtle off Cape Cod after treatment
    • Archives

      • March 2013
      • February 2013
      • January 2013
      • December 2012
      • November 2012
      • October 2012
      • September 2012
      • August 2012
      • July 2012
      • June 2012
      • May 2012
      • April 2012
      • March 2012
      • February 2012
      • January 2012
      • December 2011
      • November 2011
      • October 2011
      • September 2011
      • August 2011
    • Tags

      Amazon American Android Anonymous Apple AT&T BlackBerry California China computer Earth email Europe Facebook Gmail Google+ India Internet iOS iPad iPhone Japan London Mark Zuckerberg Microsoft Microsoft' mobile NASA New York Samsung smartphone smartphones social network Software Sony space Steve Jobs tablet tablets Twitter U.S. Windows Windows 8 Yahoo YouTube
    Latest News:-
    • Planck satellite: Esa to release maps of ancient light
    • Nvidia unveils virtual graphics server in push beyond PCs
    • Google Maps climbs world’s tallest mountains
    • Congress hears options for asteroid defense: Pay now or pray later
    • New Lizard Species Look Like Evil Dinosaur Hybrids
    • Curiosity breaks rock to reveal dazzling white interior

    Categories

    • - Business Tech
    • - Security
    • - Technology
    • - Gadgets
    • - Gaming
    • - Global Leaders
    • - Web

    Official Connections

    • - TheQueries.com
    • - Blog.MindProcessors.com
    • - Forum.MindProcessors.com
    • - Blog.AbhilashShukla.info
    • - MindProcessors.com
    • - Web.MindProcessors.com

    Disclaimer

    • Our news channel is intended to provide quality news from top online news providing companies. This channel is a collection of quality and best news at one place. The news and the logos of other providers are completely their own property.

    Where else we are

    • - Connect with us on FaceBook
    • - Follow us on Twitter
    • - Subscribe to our Youtube Channel
    • - Connect via LinkedIn
    • - Find us on Google+
    © 2011 Mind Processors Technologies, All rights reserved.
    • About us
    • Contact Us
    • Careers
    • Privacy Policy
    • Terms & Conditions
    • Sitemap