Yahoo Password Breach

Yahoo investigating reported mass password breach

 

LONDON (AP) — Yahoo Inc. said Thursday it is investigating reports of a security breach that may have exposed nearly half a million users' email addresses and passwords.

 

More here: http://news.yahoo.com/yahoo-investigating-reported-mass-password-breach-115756144--finance.html

80,266 views 36 replies
Reply #1 Top

Time to change......everything! Oy!  o_O

All done. |-)

Reply #2 Top

Yes... happened through spam.

I'd recommend changing passwords soonest.

Reply #3 Top

I was sending spam the other day, so I have already changed mine.  :D

Reply #4 Top

Quoting RedneckDude, reply 3
I was sending spam the other day, so I have already changed mine. 
End of RedneckDude's quote
.....and I didn't even get a sandwich. Some friend you are. <X3

Reply #5 Top

LONDON (AP) — Yahoo Inc. said Thursday it is investigating reports of a security breach that may have exposed nearly half a million users' email addresses and passwords.
End of quote

 

The breach/leak has been confirmed by Yahoo and further reported .....

The New York Times reports that those credentials were used not only for Yahoo! services but to services such as Gmail, AOL, Hotmail, Comcast, MSN, SBC Global, Verizon, Bellsouth and Live.com.

 

Here is a link set up through Sucuri Malware Labs where you can enter your yahoo email to see if yours was one of the 400k that was breached/posted on line.

http://labs.sucuri.net/?yahooleak

Reply #6 Top

Damn yahoos....

I've received TONS of spam from randomly generated Yahoo emails for a long time.
Would be nice if they vamped up their security a bit - unless offcause the yoyos are getting paid to ignore it, or for sending out all the spam themselves.

Reply #7 Top

Thanks PO for the link. Everything said Good for me.

Reply #8 Top

I checked with the link, it said I was good this time around.  Not long ago I had to change my password because (as a few of you know, you got the spam) my account was hacked. A check of traffic with Yahoo mail showed my account was accessed  in Poland.

 

Reply #9 Top

Quoting Wizard1956, reply 8
I checked with the link, it said I was good this time around.
End of Wizard1956's quote

I did also, and said I was good as well.

WebGizmos got a spam mail from me anyway... after I changed my pw again. 

From this I can only conclude that the list published by the hackers was incomplete or deliberately misleading.

So... if you have a Yahoo email, best to change your pw and not put your eggs in the 'I checked' basket.

Reply #10 Top

The breakdown of the passwords is . . stunning.

A sample:

Top 10 passwords

  1. 123456 = 1666 (0.38%)
  2. password = 780 (0.18%)
  3. welcome = 436 (0.1%)
  4. ninja = 333 (0.08%)
  5. abc123 = 250 (0.06%)
  6. 123456789 = 222 (0.05%)
  7. 12345678 = 208 (0.05%)
  8. sunshine = 205 (0.05%)
  9. princess = 202 (0.05%)
  10. qwerty = 172 (0.04%)

 
Top 10 base words

  1. password = 1373 (0.31%)
  2. welcome = 534 (0.12%)
  3. qwerty = 464 (0.1%)
  4. monkey = 430 (0.1%)
  5. jesus = 429 (0.1%)
  6. love = 421 (0.1%)
  7. money = 407 (0.09%)
  8. freedom = 385 (0.09%)
  9. ninja = 380 (0.09%)
  10. writer = 367 (0.08%)

More: http://pastebin.com/2D6bHGTa

Use something like LastPass to generate better passwords.

Reply #11 Top

I only use strong ones, Zu. Still, what happened, happened:

> Date: Thu, 12 Jul 2012 14:53:57 -0700
> From: [email protected]
> Subject: Re2:
> To:


> How are you getting on?
> http://documentarios.org/sohuv.php?cymsubpage715



> ______________
> "I is, is I? Well, you answer me dis: Didnt you tote out de line in decanoe fer to make fas to de tow-head?No, I didnt." (c) adalinda aekerman
> Thu, 12 Jul 2012 22:53:57

Reply #12 Top

Quoting Zubaz, reply 10
Use something like LastPass to generate better passwords.
End of Zubaz's quote

LAST PASS ROCKS! And it's free for your laptop and desktop. (Mobile version has a monthly fee of 1.99)

I finally got my wife to use it and she loves it for creating passwords and the convenience of the automatic log-ins. Also that it requires a master password to access it, so all her passwords are secure if her laptop is stolen or lost. 

It's available as an add-on for Firefox, Opera, and Chrome. I haven't tried it on any other browsers.

LAST PASS

Reply #13 Top

I'll look at LastPass...thanks guys!  Sucuri says I'm ok too...but...

Reply #15 Top

Quoting PoSmedley, reply 5
http://labs.sucuri.net/?yahooleak
End of PoSmedley's quote

Thank you, Sir ...

 

Reply #16 Top

Fracking Yahoo Mail... wouldn't touch it with a 20ft pole, being it is the absolute worst for span and all other unwanted/unwelcome crap.  Since I deleted my one and only Yahoo email account ever, my spam quota has reduced by 99.99999%.   I only used my ISP provided email these days, and while I may get the occasional lottery win from Nigeria, I may see spam once in a very blue moon, if ever.

Reply #17 Top

Quoting starkers, reply 16
Fracking Yahoo Mail... wouldn't touch it with a 20ft pole,
End of starkers's quote

My wife has a yahoo acct but she says she only uses it to play the games they have. I'm kind of surprised it's still used at all. In all the tech sites I follow, I see update articles for dozens of email services, web and desktop, and I honestly can't remember the last time I saw one for Yahoo or anyone saying putting Yahoo above any other web email service.

I keep waiting for Google or someone to just buy Yahoo out. The only time I used it was for geocities and that had to be 10 years ago.

Reply #18 Top

I use it for messenger.

Reply #19 Top

Quoting RedneckDude, reply 18
I use it for messenger.
End of RedneckDude's quote

DON"T REMIND ME! lol

 

Reply #21 Top

lmao

Reply #22 Top

It is my "throw Away" email account for all the places I don't want to give my secure email address.

Reply #24 Top

There are a lot of good reasons to use an email client instead of a webmail... privacy and spam among them.

It also appears that Yahoo is down this morning, probably to give it a proper cleaning.

 

Unfortunately, Mozilla very recently announced it was not going to devote time to develop Thunderbird.

Reply #25 Top

Checked with sucuri and it says I'm good. Changed my pw anyway.