Huge Yahoo! authentification security bug


Recommended Posts

A huge bug has been discovered in Yahoo! authentification mechanism affecting third party applications, even those created by Yahoo!A member of the Yahoo! Mail Group has discovered that people having connected third party applications may have a problem if they lose their smartphone. Indeed, despite what Yahoo says, changing the password will not be enough. This will not totally revok access to those third party applications.

Explanations :

Someone using Yahoo! services and owning a smartphone may have have installed the Yahoo Mail application for Android, Yahoo! Messenger on Android and iOS or the Yahoo! Mobile application. Even though those have been developed by Yahoo! those are considered as third party applications just like Yahoo! Messenger for Mac OS X or web services inviting you to connect with your Yahoo! ID like Facebook or Twitterfeed.

Should that person lose his smartphone, he may go ahead and change his Yahoo! password so that no one can actually dig into the address book or read his email. Upon password change, Yahoo! mentions that third party applications access will be revoked, but in truth, the lost/stolen smartphone is not safer that before.

Web user ?sy1bzbn? explains:

What does this mean? It means if you were using the YMail app on your lostphone, then whoever has physical access to it can continue to READ, SEND, and REPLY. If you were using the YMessenger app, then that person can impersonate you until you signed into YMessenger elsewhere.

I myself tested this on the iPhone. After changing my password, a pop-up alerted me that a new authentification was necessary but I could simply tap on it to make it disappear and continue using the Yahoo! Messenger application. I was able to send messages, receive IM notifications, browse my contacts and see who was connected. People?s online status were properly updated live. In fact, I was able to access Yahoo! Messenger, even after rebooting the phone!

The connection was permanently maintained and one has to manually dig into the application options to turn it off. In fact I was able to connect both on my iPhone and on Yahoo! Mail Messenger with the updated password. Two instances were running and the conversations were updating on both screen. Remember ; the two sessions had two different passwords! Only the Yahoo! Voice calls failed to go through.That?s pretty bad for Yahoo!

Source : Clubic.com (French) - translated on Streamlog

if you had an application installed that had access to your account from your mobile device - and you lost one or more of your mobile devices, wouldn't you for starters report the phone lost/stolen and it would be disabled by your phone carrier?

Also wouldn't you just with common sense revoke said applications access to your account? Are you saying the user does not have the ability to revoke applications access to their account once given?

Not a yahoo user myself, but I would think you would have to have the ability to revoke applications access to your account whenever you deemed it fitting.

It does seem like an issue sure - but seems some common sense security measures would clearly mitigate the issue. I would have to think that once it has been pointed to yahoo that they would correct such a flaw posthaste?

@Budman no indeed you cannot really revoked access to those third party apps. Even if you dig in your Yahoo! account and revoke those access + change your password... someone finding your phone will still be able to use those applications with your ID. Those applications need to be manually logged out from the phone...

You tell me it's feature ? i tell you it's a huge bug

Web user ?sy1bzbn? explains:

What does this mean? It means if you were using the YMail app on your lostphone, then whoever has physical access to it can continue to READ, SEND, and REPLY. If you were using the YMessenger app, then that person can impersonate you until you signed into YMessenger elsewhere.

Isnt that stating the obvious. and I like how they say "Web User" haha as if they were some kind of Technology Expert lol

Again I am not a yahoo user, but I think its unfathomable to me that the user would not have the ability to REVOKE an applications access to their account?

On google for example

post-14624-0-72504500-1326837518.jpg

I can see how there could be an issue with just changing your password does not revoke. User would not like the fact that every time they changed their password all applications lost access. That could be a nightmare. But you should be able to REVOKE their access.

But yeah change of email password not revoking application access to me would seem like a feature ;) Users would be dumbfounded why X no longer worked every time they changed their yahoo email password.

I don't see a major issue with that, IF the user can directly revoke access from said application via some method.

edit: ok quick google ;)

http://help.yahoo.com/l/us/yahoo/developer/moreinfo/moreinfoapis.html

Changing Permissions If you previously granted a third-party application access to your data, you may revoke permissions at any time by visiting your Application Management page. Doing so might adversely affect the performance and functionality of installed applications if it requires access to your profile data.

Seems like to me you can revoke access whenever you want.

The above article says the user changed his password, he says nothing about actually revoking access.. So I would have to agree, like I said an application should not be revoked just because you changed your yahoo email password. That would be a big issue for lots and lots of users!!

edit2: I think I might try this, I know I can install yahoo on my blackberry -- I think I will give it a try. Because sofar it seems like this article is pure scaremongering from what I can tell. No **** changing your password on your email should not revoke all applications access, why would anyone think that. And where did they read that from yahoo?

Ok created an yahoo account.. Logged in, then when to change my password - I don't see anything saying my applications access will be revoked?

post-14624-0-82083300-1326838537.jpg

Now I have to leave - the beer after work is calling me ;) But while at the bar I will install yahoo on my phone. And then later I will revoke it and see what happens..

If you want to chat with me at the bar, my new yahoo account is [email protected] ;)

@ChuckFinley : "Isnt that stating the obvious. and I like how they say "Web User" haha as if they were some kind of Technology Expert lol"

And you think you are.... ?

@Budman : Again

I had Yahoo Messenger installed and running on the iPhone.

I quit the app

I changed my password

I got a message telling me that my third party application would not work

I check my iPhone=> Yahoo! Messenger still working

Also manually revoking access to 3rd party apps through the account notification would not do it.

I check my iPhone=> Yahoo! Messenger still working

Not sure how to make it clearer

Again no where on the change password page does it say its going to revoke anything??

I changed my yahoo account password, did not say anything about revoking my apps

here are my apps

post-14624-0-59087300-1326864803_thumb.p

So after I changed my password on my Account I went back to my kindle fire - and says sign in required, and will not let me access my mail. No hitting cancel or backspace, etc.. did not let me in. So from my own testing so far is not matching up with what your saying.

Here is me changing my password -- where are you saying your getting told changing your password will revoke or break your applications?

post-14624-0-78454700-1326865357.png

Now in the morning I will try it on my blackberry and see what happens with messenger app, wouldn't install on my KF but got a IMO app to work with yahoo, but I want to test actually chatting and contacts etc.. and then go in and test.

But so far changing password blocked access on my KF yahoo mail app, and I didn't even revoke access.

@BudMan : "I changed my yahoo account password, did not say anything about revoking my apps"

Really ? ...I did the process again, here is what i get

screenshot20120118at911.png

I went back to my Yahoo! Messenger on the iPhone and here is what i get:

doneme.jpg

Now as stated before, all i have to do is to tap on this notification to continue using the application logged in with a different password (the previous one). And again, as stated before, i can reboot the phone or quit the application so that it's not running in the background... i'll still be able to use it. I have to manually sign out byt going into the options at shown below :

photo180112092142.png

What is "Yahoo! Go Phone" -- I do not think that is the messenger app your using. Which I see here and doesn't seem like its called that

http://itunes.apple....d309219097?mt=8

So ok it revoked app A, does not mean app B will not still work.. Like I said changing your password should really not revoke apps.

I went to go check my blackberry this morning - and it seems our IT dept has blocked by policy messenger ;) Other yahoo app I found was just a mobile frontend not really an app. Wait til my son wakes up and will try on his phone, I know he uses yahoo messenger..

Dude sorry what I am seeing is not matching up with what your saying.. Now go into your apps, see that link there and do you see a messenger link. Revoke THAT, now does you messenger work on your phone?

Well, anyways, I contacted Yahoo! Security a few days ago and they came back to me saying that in some cases they found no problem and in other cases they were able to replicate the problem. I was told that they were working on a fix. That's the good news for Yahoo! users i guess :)

Not sure how this is gonna be deployed. Either though an app update or on their server side...

You find it "unlikely". Seriously, who do you think you are to judge each of my posts like this ?

if I tell this happened, then this happened.

But then you know what. i could as well say that i don't believe what you said earlier. You just photoshoped images and invented a story as well.

It was not an email it was a phone call.

You want to see the previous warning i sent to them ? Sure. Do you read French? here is the first reply

http://img814.images...2789/emailf.jpg

Have fun

I work as a journalist and this French Yahoo! PR contacted Yahoo Security EMEA and Sunnyvale and call me back at lunch time

Do you also want her phone number to check ? Cause i can give it to you if you're still skeptical ? You wanna call her? Let me know i'll PM you her number but then you better record your phone conversation.

Dude I am not judging your posts, I am just saying I could not duplicate anything you were saying.

You post something that could be seen as pure SCARE MONGERING and yahoo bashing -- ie their security is flawed.

Your tests should be very easy for someone to duplicate -- I don't see anyone here in this thread saying they could duplicate your example. Seem I was the only one even attempting to verify your statements. And from my test they did not hold water - sorry!

So have you actually went in and revoked access to messenger?

I really shouldn't have to repeat myself that changing a password does not mean applications that you have given access to should be revoked from said access.

Your post of Go Yahoo when you changed your passed -- that does not seem like "messenger" to me.

So post up your applications -- I posted mine showing messenger and mail applications having access. And all I had to do was change my password and email on my KF instantly required password to re access. But to be honest I should really have to revoke the access directly to cause what it did.

So actually Revoke messanger application from having access and then lets see your access and there might be something to talk about.

You have not shown anything backing up your claim that makes sense, and then you say you contacted Yahoo and they got back to you saying that they duplicated your issue some times, in 2 days they lab this out and got back to you -- come on dude how can someone not be skeptical at such claims.

Again what do you not understand here?

YES i did manually revok those applications and YES again, described in the first post, i was able to access Y! Messenger after that

Yahoo Go Phone is a former java-based Yahoo Mobile app. It is immediately added to my Yahoo account when first signing Yahoo! Messenger on the iPhone which means that Yahoo Go became Yahoo! Messenger

And this is precisely written by the web user in the link i mention in my 1st post.

http://groups.yahoo.com/group/Y-Mail/message/22692

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • A few weeks ago, I had this same exact issue. Unfortunately, I didn't think of disabling the Secure Boot option in BIOS. I updated my BIOS to the latest version for my MB and it resolved the issue.
    • I have a partial answer, when I used a multi-port usb hub I had degraded speed performance with 3 large external hard drives connected. I managed to snag a nice (yet older) USB3 wavelink hub that had about x6 usb 3 ports and almost doubled the speed of the external hard drives transfer rate. This looks to be a slightly upgraded model -https://ebay.io/m/LZtjTy
    • Microsoft faces shareholder lawsuit over masking AI costs and slowing Azure growth by Karthik Mudaliar Microsoft is facing a class action lawsuit from shareholders who allege that the company intentionally overhyped its artificial intelligence initiatives to distract from slowing cloud revenue and an exploding infrastructure bill. The complaint was filed in a Seattle federal court by the Michigan-based City of St. Clair Shores Police and Fire Retirement System. The plaintiffs argue that Microsoft’s leadership painted an overly optimistic picture of its Copilot rollout and complex OpenAI partnership. They say that the company did this while downplaying the harsh reality that building the data centers required to power these next-generation tools requires a huge amount of capital. Back at the company's Q2 2026 earnings report from late January, Microsoft revealed that its flagship Azure cloud growth had slipped to 39% (down from 40% the prior quarter) and guided investors to expect a further deceleration to 37% or 38% for the first three months of 2026. Now, under normal circumstances, a slight percentage point drop in cloud growth is a minor operational hiccup. But the Redmond giant paired that guidance with $37.5 billion in quarterly capital expenditures. This figure, which is a 66% year-over-year surge, blew past any analyst estimates at that time. Much of this amount went into buying high-priced GPUs and custom silicon that were required to train and run large language models. This is why the market reacted violently and just a day after its earnings call on January 29, the company's stock plummeted 10%, and wiped out $357 billion of capital in just a trading session. Microsoft is doing better now, though. Its Q3 2026 results showed its run rate from its AI business was hitting $37 billion, proving that enterprise demand for its infrastructure is very real and continuing to scale. Microsoft isn't the only company pouring billions into infrastructure for the AI boom. We've seen most Big Tech companies, including Amazon and Google, also get the results of these **** with stronger-than-ever growth and increased income. via Reuters
    • Firefox 152.0 by Razvan Serea Firefox is a fast, full-featured Web browser. It offers great security, privacy, and protection against viruses, spyware, malware, and it can also easily block pop-up windows. The key features that have made Firefox so popular are the simple and effective UI, browser speed and strong security capabilities. Firefox has complete features for browsing the Internet. It is very reliable and flexible due to its implemented security features, along with customization options. Firefox includes pop-up blocking, tab-browsing, integrated Google search, simplified privacy controls, a streamlined browser window that shows you more of the page than any other browser and a number of additional features that work with you to help you get the most out of your time online. Firefox key features Enhanced Tracking Protection (ETP) – Blocks trackers, cookies, cryptominers, and fingerprinters by default. Private Browsing Mode – Deletes history, cookies, and temporary files when closed. Lightweight & Fast Performance – Optimized memory usage with efficient page loading. Cross-Platform Sync – Sync bookmarks, passwords, history, and open tabs across devices. Customizable Interface – Toolbars, themes, and extensions can be tailored to user needs. Strong Privacy Controls – Options to manage cookies, permissions, and site data easily. Reader Mode – Strips away clutter for distraction-free reading. Pocket Integration – Save and read articles offline with Pocket built into Firefox. Picture-in-Picture (PiP) – Watch videos in a floating window while multitasking. Extensions & Add-ons – Vast library for productivity, security, and personalization. Built-in PDF Viewer – No need for external software to view PDFs. Firefox Monitor – Alerts users if their email is part of a known data breach. Multi-Account Containers – Isolate browsing sessions (e.g., work, personal, shopping). Performance & Resource Efficiency – Uses fewer system resources than some competitors. Open Source & Community-Driven – Transparent development with global contributions. Download: Firefox 64-bit | Firefox 32-bit | ARM64 | ~70.0 MB (Freeware) Download: Firefox for MacOS | 145.0 MB View: Firefox Home Page | Release Notes Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Microsoft Visio 2024 Professional for Windows is still at 90% off by Steven Parker Created by ChatGPT Today's highlighted Neowin Deal comes from our Apps & Software section of the Neowin Deals store, where you can save 90% on Microsoft Visio 2024 Professional for Windows [Digital License]. Microsoft Visio: Turn Complex Ideas into Clear Visuals Microsoft Visio 2024 is a robust diagramming software designed to empower individuals and businesses to visually represent complex data, processes, and workflows. With a host of advanced features, it caters to professionals from various industries, including IT, engineering, business, and architecture. Visio 2024 makes it easy for individuals and teams to create and share clear, professional diagrams that simplify complex information. It offers updated shapes, templates, and styles, along with a new search bar to improve your experience. Visio 2024 also has a fresh design that matches other Office apps you use. Create stunning diagrams Extensive Diagramming Capabilities: Visio 2024 offers a wide array of diagram types, including flowcharts, process maps, floor plans, network diagrams, and organizational charts. The software comes with a comprehensive set of pre-built templates and shapes, making it easier to get started on projects quickly. Professional Templates and Shapes: The software includes over 250,000 shapes across multiple diagram types, ensuring that users from any field-whether creating a simple flowchart or a complex engineering design-have the tools they need to represent their ideas visually. Data-Linked Diagrams: One of the most powerful features of Visio 2024 is its ability to link data to diagrams, allowing users to visualize real-time data directly within their diagrams. Whether you're pulling data from Excel, SQL Server, or other databases, the software ensures that your diagrams are automatically updated as data changes, giving users better insights and control. Advanced Formatting Options: Visio 2024 comes equipped with a range of formatting tools to create highly customized diagrams. These include shape formatting, text adjustments, and the ability to apply various themes, ensuring diagrams not only serve their functional purpose but also look professional. Enhanced Visual Styles: This version of Visio includes new visual styles and layouts that make complex diagrams easier to interpret. Whether you're designing an IT network, a business process flow, or a floor plan, the enhanced visual options improve clarity and presentation quality. Easy, secure collaboration Real-Time Collaboration: With Visio 2024's improved collaboration tools, multiple users can work on the same diagram simultaneously from anywhere, with changes being tracked in real-time. This makes it a highly efficient tool for teams working remotely or across different locations. Mobile and Cloud Access: Users can view and edit diagrams on the go with the Visio web app. This ensures that even when you're away from your desktop, you can access and make critical changes to diagrams via mobile devices. Integration with Microsoft 365: Visio 2024 integrates seamlessly with the Microsoft 365 suite, allowing users to easily embed diagrams into PowerPoint presentations, Word documents, or Teams chats. You can also store diagrams in OneDrive or SharePoint for easy sharing and access from any device. Security and Compliance: Built with enterprise-grade security, Visio 2024 ensures that your diagrams are protected. Microsoft's trusted cloud infrastructure means that your data is encrypted and safeguarded, with compliance with international standards. Good to know Length of access: lifetime Redemption deadline: redeem your code within 7 days of purchase Access options: desktop Bound to account - Limited to one device activation at a time Only available to existing and new users Version: 2024 Updates included Click here to verify Microsoft partnership Microsoft Visio 2024 Professional for Windows normally costs $579.99, but it can be yours for just $39.97 for a limited time, that's a saving of $520 (90%). For terms, specifications, and license info please click the link below. Microsoft Visio 2024 Professional for Windows for $54.97 (was $579.99) Although priced in U.S. dollars, this deal is available for digital purchase worldwide. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
  • Recent Achievements

    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      501
    2. 2
      +Edouard
      201
    3. 3
      PsYcHoKiLLa
      127
    4. 4
      Steven P.
      81
    5. 5
      ATLien_0
      76
  • Tell a friend

    Love Neowin? Tell a friend!