Huge Yahoo! authentification security bug


Recommended Posts

A huge bug has been discovered in Yahoo! authentification mechanism affecting third party applications, even those created by Yahoo!A member of the Yahoo! Mail Group has discovered that people having connected third party applications may have a problem if they lose their smartphone. Indeed, despite what Yahoo says, changing the password will not be enough. This will not totally revok access to those third party applications.

Explanations :

Someone using Yahoo! services and owning a smartphone may have have installed the Yahoo Mail application for Android, Yahoo! Messenger on Android and iOS or the Yahoo! Mobile application. Even though those have been developed by Yahoo! those are considered as third party applications just like Yahoo! Messenger for Mac OS X or web services inviting you to connect with your Yahoo! ID like Facebook or Twitterfeed.

Should that person lose his smartphone, he may go ahead and change his Yahoo! password so that no one can actually dig into the address book or read his email. Upon password change, Yahoo! mentions that third party applications access will be revoked, but in truth, the lost/stolen smartphone is not safer that before.

Web user ?sy1bzbn? explains:

What does this mean? It means if you were using the YMail app on your lostphone, then whoever has physical access to it can continue to READ, SEND, and REPLY. If you were using the YMessenger app, then that person can impersonate you until you signed into YMessenger elsewhere.

I myself tested this on the iPhone. After changing my password, a pop-up alerted me that a new authentification was necessary but I could simply tap on it to make it disappear and continue using the Yahoo! Messenger application. I was able to send messages, receive IM notifications, browse my contacts and see who was connected. People?s online status were properly updated live. In fact, I was able to access Yahoo! Messenger, even after rebooting the phone!

The connection was permanently maintained and one has to manually dig into the application options to turn it off. In fact I was able to connect both on my iPhone and on Yahoo! Mail Messenger with the updated password. Two instances were running and the conversations were updating on both screen. Remember ; the two sessions had two different passwords! Only the Yahoo! Voice calls failed to go through.That?s pretty bad for Yahoo!

Source : Clubic.com (French) - translated on Streamlog

if you had an application installed that had access to your account from your mobile device - and you lost one or more of your mobile devices, wouldn't you for starters report the phone lost/stolen and it would be disabled by your phone carrier?

Also wouldn't you just with common sense revoke said applications access to your account? Are you saying the user does not have the ability to revoke applications access to their account once given?

Not a yahoo user myself, but I would think you would have to have the ability to revoke applications access to your account whenever you deemed it fitting.

It does seem like an issue sure - but seems some common sense security measures would clearly mitigate the issue. I would have to think that once it has been pointed to yahoo that they would correct such a flaw posthaste?

@Budman no indeed you cannot really revoked access to those third party apps. Even if you dig in your Yahoo! account and revoke those access + change your password... someone finding your phone will still be able to use those applications with your ID. Those applications need to be manually logged out from the phone...

You tell me it's feature ? i tell you it's a huge bug

Web user ?sy1bzbn? explains:

What does this mean? It means if you were using the YMail app on your lostphone, then whoever has physical access to it can continue to READ, SEND, and REPLY. If you were using the YMessenger app, then that person can impersonate you until you signed into YMessenger elsewhere.

Isnt that stating the obvious. and I like how they say "Web User" haha as if they were some kind of Technology Expert lol

Again I am not a yahoo user, but I think its unfathomable to me that the user would not have the ability to REVOKE an applications access to their account?

On google for example

post-14624-0-72504500-1326837518.jpg

I can see how there could be an issue with just changing your password does not revoke. User would not like the fact that every time they changed their password all applications lost access. That could be a nightmare. But you should be able to REVOKE their access.

But yeah change of email password not revoking application access to me would seem like a feature ;) Users would be dumbfounded why X no longer worked every time they changed their yahoo email password.

I don't see a major issue with that, IF the user can directly revoke access from said application via some method.

edit: ok quick google ;)

http://help.yahoo.com/l/us/yahoo/developer/moreinfo/moreinfoapis.html

Changing Permissions If you previously granted a third-party application access to your data, you may revoke permissions at any time by visiting your Application Management page. Doing so might adversely affect the performance and functionality of installed applications if it requires access to your profile data.

Seems like to me you can revoke access whenever you want.

The above article says the user changed his password, he says nothing about actually revoking access.. So I would have to agree, like I said an application should not be revoked just because you changed your yahoo email password. That would be a big issue for lots and lots of users!!

edit2: I think I might try this, I know I can install yahoo on my blackberry -- I think I will give it a try. Because sofar it seems like this article is pure scaremongering from what I can tell. No **** changing your password on your email should not revoke all applications access, why would anyone think that. And where did they read that from yahoo?

Ok created an yahoo account.. Logged in, then when to change my password - I don't see anything saying my applications access will be revoked?

post-14624-0-82083300-1326838537.jpg

Now I have to leave - the beer after work is calling me ;) But while at the bar I will install yahoo on my phone. And then later I will revoke it and see what happens..

If you want to chat with me at the bar, my new yahoo account is [email protected] ;)

@ChuckFinley : "Isnt that stating the obvious. and I like how they say "Web User" haha as if they were some kind of Technology Expert lol"

And you think you are.... ?

@Budman : Again

I had Yahoo Messenger installed and running on the iPhone.

I quit the app

I changed my password

I got a message telling me that my third party application would not work

I check my iPhone=> Yahoo! Messenger still working

Also manually revoking access to 3rd party apps through the account notification would not do it.

I check my iPhone=> Yahoo! Messenger still working

Not sure how to make it clearer

Again no where on the change password page does it say its going to revoke anything??

I changed my yahoo account password, did not say anything about revoking my apps

here are my apps

post-14624-0-59087300-1326864803_thumb.p

So after I changed my password on my Account I went back to my kindle fire - and says sign in required, and will not let me access my mail. No hitting cancel or backspace, etc.. did not let me in. So from my own testing so far is not matching up with what your saying.

Here is me changing my password -- where are you saying your getting told changing your password will revoke or break your applications?

post-14624-0-78454700-1326865357.png

Now in the morning I will try it on my blackberry and see what happens with messenger app, wouldn't install on my KF but got a IMO app to work with yahoo, but I want to test actually chatting and contacts etc.. and then go in and test.

But so far changing password blocked access on my KF yahoo mail app, and I didn't even revoke access.

@BudMan : "I changed my yahoo account password, did not say anything about revoking my apps"

Really ? ...I did the process again, here is what i get

screenshot20120118at911.png

I went back to my Yahoo! Messenger on the iPhone and here is what i get:

doneme.jpg

Now as stated before, all i have to do is to tap on this notification to continue using the application logged in with a different password (the previous one). And again, as stated before, i can reboot the phone or quit the application so that it's not running in the background... i'll still be able to use it. I have to manually sign out byt going into the options at shown below :

photo180112092142.png

What is "Yahoo! Go Phone" -- I do not think that is the messenger app your using. Which I see here and doesn't seem like its called that

http://itunes.apple....d309219097?mt=8

So ok it revoked app A, does not mean app B will not still work.. Like I said changing your password should really not revoke apps.

I went to go check my blackberry this morning - and it seems our IT dept has blocked by policy messenger ;) Other yahoo app I found was just a mobile frontend not really an app. Wait til my son wakes up and will try on his phone, I know he uses yahoo messenger..

Dude sorry what I am seeing is not matching up with what your saying.. Now go into your apps, see that link there and do you see a messenger link. Revoke THAT, now does you messenger work on your phone?

Well, anyways, I contacted Yahoo! Security a few days ago and they came back to me saying that in some cases they found no problem and in other cases they were able to replicate the problem. I was told that they were working on a fix. That's the good news for Yahoo! users i guess :)

Not sure how this is gonna be deployed. Either though an app update or on their server side...

You find it "unlikely". Seriously, who do you think you are to judge each of my posts like this ?

if I tell this happened, then this happened.

But then you know what. i could as well say that i don't believe what you said earlier. You just photoshoped images and invented a story as well.

It was not an email it was a phone call.

You want to see the previous warning i sent to them ? Sure. Do you read French? here is the first reply

http://img814.images...2789/emailf.jpg

Have fun

I work as a journalist and this French Yahoo! PR contacted Yahoo Security EMEA and Sunnyvale and call me back at lunch time

Do you also want her phone number to check ? Cause i can give it to you if you're still skeptical ? You wanna call her? Let me know i'll PM you her number but then you better record your phone conversation.

Dude I am not judging your posts, I am just saying I could not duplicate anything you were saying.

You post something that could be seen as pure SCARE MONGERING and yahoo bashing -- ie their security is flawed.

Your tests should be very easy for someone to duplicate -- I don't see anyone here in this thread saying they could duplicate your example. Seem I was the only one even attempting to verify your statements. And from my test they did not hold water - sorry!

So have you actually went in and revoked access to messenger?

I really shouldn't have to repeat myself that changing a password does not mean applications that you have given access to should be revoked from said access.

Your post of Go Yahoo when you changed your passed -- that does not seem like "messenger" to me.

So post up your applications -- I posted mine showing messenger and mail applications having access. And all I had to do was change my password and email on my KF instantly required password to re access. But to be honest I should really have to revoke the access directly to cause what it did.

So actually Revoke messanger application from having access and then lets see your access and there might be something to talk about.

You have not shown anything backing up your claim that makes sense, and then you say you contacted Yahoo and they got back to you saying that they duplicated your issue some times, in 2 days they lab this out and got back to you -- come on dude how can someone not be skeptical at such claims.

Again what do you not understand here?

YES i did manually revok those applications and YES again, described in the first post, i was able to access Y! Messenger after that

Yahoo Go Phone is a former java-based Yahoo Mobile app. It is immediately added to my Yahoo account when first signing Yahoo! Messenger on the iPhone which means that Yahoo Go became Yahoo! Messenger

And this is precisely written by the web user in the link i mention in my 1st post.

http://groups.yahoo.com/group/Y-Mail/message/22692

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • BATorrent 4.1.0 by Razvan Serea BATorrent is a lightweight, open-source BitTorrent client built with modern C++ and Qt 6, offering a clean, fast, and privacy-focused alternative to traditional torrent apps. It supports magnet links, .torrent files, resume data, sequential downloading, per-file priorities, and even imports from qBittorrent. Power users benefit from integrated RSS auto-download with regex filtering, duplicate detection, and automatic tracker lists from Stremio. Streaming is seamless thanks to auto-detected players like VLC and IINA. BATorrent includes robust VPN tools—interface binding, auto-detection for WireGuard-based services like Mullvad and NordLynx, kill switch, proxy support, and IP filtering. A full WebUI enables remote control, while integrations with Plex, Jellyfin, and Emby automate library updates. With themes, speed scheduling, system-tray alerts, and cross-platform support for Windows, Linux, and macOS, BATorrent delivers a polished, high-performance torrenting experience. BATorrent features: Core .torrent file and magnet link support Resume data — picks up where you left off after restart Import torrents from qBittorrent Create .torrent files from any file or folder Sequential download mode Per-file priority control (skip, low, normal, high) Seed ratio limits with auto-pause DHT, PEX, UPnP, NAT-PMP RSS Auto-Download Subscribe to RSS feeds — automatically download new torrents as they appear Regex filters — match only what you want (e.g. 1080p|720p, S01E\d+) Per-feed settings — custom save path, check interval (5–1440 min), enable/disable Auto-download — matched items are downloaded automatically in the background Supports magnet links, .torrent URLs, and tags Tray notifications when items are auto-downloaded Duplicate detection — never downloads the same item twice Stremio Stremio Addon System pre-installed — works out of the box Auto tracker list from ngosang/trackerslist Streaming Play while downloading — stream video files before the download is complete Supports mp4, mkv, avi, mov, wmv, flv, webm, m4v, ts Auto-detects installed players (VLC, IINA, system default) VPN & Privacy Interface binding — lock torrent traffic to a specific network interface (e.g. tun0) Auto VPN detection — identifies VPN interfaces (tun, tap, WireGuard, Mullvad, NordLynx, ProtonVPN) Kill switch — automatically pauses all torrents if the VPN interface drops Auto-resume — resumes only the torrents paused by the kill switch when VPN reconnects Proxy support — SOCKS5 and HTTP proxy with optional authentication IP filtering — load P2P blocklists to block unwanted IP ranges Protocol encryption (enabled / forced / disabled) WebUI Remote management — control torrents from any browser at http://localhost:8080 REST API with JSON responses Add torrents via magnet link or .torrent upload Pause, resume, remove torrents remotely View peers and files per torrent Dark theme matching the desktop app HTTP Basic Auth with SHA-256 password hashing Configurable port and remote access (localhost vs 0.0.0.0) Interface 3 themes: Dark, Light, Midnight (bat/vampire aesthetic) Real-time speed graph Detailed panel with tabs: General, Peers, Files, Trackers Filter bar: search by name, filter by state (Active, Downloading, Seeding, Paused, Finished) Drag & drop .torrent files and magnet links Drag & drop reorder in torrent list System tray with notifications (download complete, kill switch events, RSS auto-downloads) Splash screen with bat animation Bilingual: English and Portuguese (BR), auto-detected from system locale Bandwidth Scheduler Alternative speed limits — set different download/upload limits on a schedule Time range — configure active hours (e.g. 01:00 to 07:00), supports overnight ranges Per-day control — choose which days of the week the schedule applies Automatically switches between normal and alternative speeds Media Server Integration Plex — automatically trigger library scan when a download completes Jellyfin / Emby — same automatic library refresh via API Configure server URL and authentication token/key in Settings System Cross-platform: Windows, Linux, macOS Auto-shutdown — automatically shut down PC when all downloads complete (60s cancellable countdown) Auto-update system (AppImage on Linux, installer on Windows, DMG on macOS) CLI arguments: pass .torrent files or magnet: URIs directly Keyboard shortcuts: Space to toggle pause, Ctrl+A to select all, Ctrl+O to open BATorrent 4.1.0 release notes: A community-driven release: everything here came straight from your reports and requests. It closes the remaining gaps with qBittorrent and fixes the Windows settings/tray/splash issues several of you hit. Fixed Settings now actually save. A whole class of preferences — speed limits (and the alternative limits), max active downloads, seed ratio, listen port, max connections, DHT/uTP/encryption, VPN interface, kill switch and proxy — weren't being persisted and reset to defaults on every launch. They now round-trip correctly. (Thanks to everyone who reported "the upload limit always goes back to 0".) Splash and tray toggles stick on Windows. Turning off the startup animation (or "close to tray") no longer reverts — the Windows registry stored these booleans as integers and the UI was misreading them. Close-to-tray hint. The first time the window hides to the tray you get a one-time notification, so the app doesn't look like it vanished (Windows 11 tucks new tray icons into the overflow). macOS Dock icon size. The icon filled its canvas edge-to-edge and rendered larger than neighbouring apps; it now uses the standard safe-area padding. Native file picker language. The "Torrent file / All files" filter in the open dialog follows the app language instead of being hard-coded. Added — qBittorrent parity Alternative speed limits toggle — a turtle button in the toolbar flips your throttled limits on/off instantly, independent of the scheduler. Follow system theme — switch light/dark automatically with the OS (Settings → Appearance). Pre-allocate disk space — reserve the full file size up front to reduce fragmentation (Settings → Downloads). Recheck data on add — optionally force a hash check when adding a torrent, so existing or partial files on disk are detected. Port status indicator — a 🔴 dot in the status bar shows whether your listen port looks reachable (UPnP/NAT-PMP + listen state; fully local, no external check). Add torrent from URL — File → Add torrent from URL (Ctrl+U) fetches a remote .torrent and routes it through the normal add dialog. Export .torrent — right-click a torrent → Export .torrent to save its metadata file. Already there (in case you missed it) Watch folder — auto-add .torrent files dropped into a monitored directory (Settings → Files). This release just surfaces it. Incomplete files already carry a .!bt suffix until they finish. Under the hood Regression tests for the settings-persistence and Windows boolean bugs. A new Qt Quick Test harness covering the startup splash and the design-system widgets. Download: BATorrent 4.1.0 | 37.5 MB (Open Source) Download: BATorrent Portable | 51.7 MB Links: BATorrent Website | Screenshot | Changelog Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Disabling open on hover, great! That was so stupid! They need to do a fix, where if a network share is disconnected, it doesn't hang when opening "This PC" for 20 seconds.
    • Microsoft releases major feature updates for stock Windows 11 apps by Taras Buria In addition to releasing new Windows 11 preview builds, Microsoft announced that inbox Windows apps now have dedicated release notes in the official documentation. At long last, users have access to all the release notes for each app, with changes listed in chronological order. Microsoft used to announce feature updates for stock apps with each build. Now, with Windows Insider release notes hosted on the Microsoft Learn website, each app has a dedicated space for its changelog, which is very useful for those who want to track new features and improvements. Alongside that, Microsoft dropped massive feature updates for six stock apps: Clock, Media Player, Calculator, Voice Recorder, Photos, and Paint. Each app packs quite a lot of changes and new capabilities, so here are the release notes. Here are quick notes so that you can jump to the app you are interested in the most: Calculator Camera Clock Media Player Paint Photos Sound Recorder Here is what is new for the Calculator in version 11.2605.9.0: More accurate square-root results — Fixed rare cases where a calculation that should equal zero (like sqrt(2.25) - 1.5) returned a tiny leftover value instead. Readable text in High Contrast themes — Settings text now shows the correct colors in the High Contrast Aquatic and Desert themes. Fixed layout for right-to-left languages — For languages like Arabic and Hebrew, the graph, number pad, equation fields, and scroll buttons now appear correctly oriented. Reliable launch after upgrading — Fixed an issue where upgrading from much older versions could leave outdated settings that stopped the app from opening. Here is what is new for the Camera app (version 2026.2605.7.0): Zoom slider works on more cameras — The zoom slider now works on the latest cameras, respects your system zoom settings, and updates instantly when you change those settings. Full range of zoom levels — Fixed an issue where the zoom slider only showed three steps on some devices that zoom in finer increments. Front camera works on more devices — Resolved a problem that blocked the front-facing camera on certain wide-angle devices. More video resolution choices — You can now pick video resolutions that were previously hidden; the app shows a heads-up warning instead of removing them. QR links you can still use — When a scanned QR code points to something with no matching app, the link is now copied to your clipboard (with a notification) while still offering a Store search. Smarter default settings — When you haven't set a preference, the app now follows your system settings by default. The Clock app has a massive changelog with the following improvements in version 11.2605.9.0: Timers keep counting after they hit zero — When a timer runs out, it now keeps counting up (for example, -00:27:31) so you can see how far past the time you've gone. You can turn off the daily goal — Focus Sessions now include an "Off" option so you can skip setting a daily goal entirely. New 15-minute snooze option — Alarms now offer a 15-minute snooze interval. Run up to 3 countdowns at once — The Countdown Widget now supports three simultaneous countdowns, up from two. Timer Widget notifications now appear — Fixed an issue where the "timer finished" notification didn't show when the timer was started from the widget. Less clutter in Focus Sessions — Tasks you've already completed no longer show up in the Focus Session task list. More accurate focus progress — Fixed a rounding issue that could show your daily focus progress as a minute short (for example, 49 minutes instead of 50). Smoother World Clock comparisons — The World Clock compare page now loads dates as you scroll, so it feels more responsive. Up-to-date World Clock locations — Refreshed country and city names to match their current names. Correct sun and moon icons during midnight sun — Fixed an icon that wrongly showed a moon during all-day daylight in polar regions. Fixed back-button behavior in clock comparisons — Pressing back once now takes you back as expected, instead of jumping the date to 1926. Corrected the Newfoundland time zone — Newfoundland now uses the right time zone (St. John's). Disabled alarms stay looking disabled — Editing a turned-off alarm no longer makes it appear turned on. Cleaner timer cards — The expand button is now turned off on timer cards that have no time set, preventing actions that wouldn't do anything. Clearer theme setting — Updated the wording to "Choose your preferred app theme." Smoother Settings links — The "About" links in Settings no longer trigger an unexpected "switch apps" prompt. Fixed spacing in Spotify settings — Corrected uneven spacing in the Spotify settings card. Better focus visibility in High Contrast — The focus highlight in World Clock is now clearly visible in the High Contrast Aquatic and Desert themes. No more double announcements — Screen readers no longer read the timer value twice. Countdown names read correctly — Screen readers now properly announce the name of each countdown. Keyboard focus stays put — Focus no longer disappears after you press the Timer Reset button. Clearer alarm toggle for screen readers — Tidied up how the alarm on/off switch is announced. The Media Player app received plenty of changes as well (version 11.2605.14.0): Custom captions — You can now personalize how closed captions appear, with caption styling tied to your Windows caption settings, plus a quick link to open those settings directly. "Indexing" banner in the play queue — When your media library is still being scanned, a banner now explains why some items may not appear yet. Fixed the look of selected items — Corrected a layout glitch with selected items in lists. Fewer playback failures — Improved how the app recognizes supported file types, so more files play without issues. Playlists need a name — You can no longer accidentally save a playlist with a blank name. Cleaner look for empty playlists — Improved how a playlist appears when it has no items yet. More stable play queue edits — Fixed a crash that could happen when changing the play queue while the app was switching between sessions. Clearer "missing codec" message — Improved the dialog that appears when a file needs a codec you don't have, with clearer guidance on what to do. A big update is also available for Paint in version 11.2605.61.0: Adjustable eraser transparency — You can now control how transparent the eraser is. Cleaner stamp brush strokes — Fixed visible color shifts and artifacts when using stamp-style brushes. JPEG photos save in place — Opening a rotated JPEG and pressing Save now overwrites the original instead of unexpectedly prompting "Save As." No more crash on bad image files — Opening a damaged or invalid image, from within the app, by double click, or commandline, now shows a clear error message instead of closing the app. Classic selection behavior restored — The selection outline now hides while you move, resize, or rotate a selection, just like in classic Paint. Tidier AI image panel — Fixed missing spacing at the bottom of the AI image generation panel for a cleaner layout. Visible button hover in light theme — Toolbar split buttons now show a clear hover highlight in the light theme. Snappier toolbar — Streamlined how the ribbon lays out, giving a small speed boost at startup. Fewer background crashes — Fixed a crash that could happen while background tasks were finishing up. Stable app shutdown — Prevented rare crashes when closing the app. Fixed layer removal glitch — Deleting the active layer no longer leaves the layers list in an inconsistent state. Here is what is new in the Photos app (version 2026.11060.2004.0): AI watermarking — AI-generated or edited images can now carry a visible Copilot watermark. You choose Never, Always, or Ask Every Time in Settings, with a confirmation when saving. The watermarking is off by default in settings. Better viewing of small images and pixel art — Tiny images (like 16×16 pixel art) now zoom in far more to fill the screen and stay crisp instead of looking blurry. Select scanned text with the keyboard — When text is detected in an image, you can now navigate and select it using the arrow keys, Shift+Arrow, Home/End, and Ctrl+A, with a clear focus highlight. Fixed a crash in text recognition — Resolved a crash that could close Photos while detecting text in images; the app now recovers gracefully. Easier keyboard navigation — Tabbing through the navigation bar no longer stops on hidden controls, so it takes a single Tab to move past it instead of three. And finally, here is the Sound Recorder (version 11.2605.1.0): Waveform shows with Bluetooth mics — The live waveform now displays correctly when you record using a Bluetooth audio device. No more stray scrollbar — A non-working horizontal scrollbar no longer appears at the bottom of the waveform unless you've zoomed in. Mark button ready right away — The Mark button no longer looks grayed out until you hover over it after opening the app. Markers hidden for WAV files — Markers are now turned off for WAV recordings, since that format can't store them — so they're no longer lost silently. Smoother deleting — Quickly pressing Delete and Enter to remove several recordings in a row no longer triggers a "file doesn't exist" error. Fixed a memory issue — Resolved a memory leak that occurred each time a recording started. You can find all these changelogs in the official documentation here.
    • again, an article about Microsoft Edge and ridicules hater's comments
    • From this very same article: "For organizations that prefer a “more deliberate pace”, the Extended Stable channel remains an option."
  • Recent Achievements

    • Very Popular
      AndrewSteel earned a badge
      Very Popular
    • Veteran
      Taliseian went up a rank
      Veteran
    • One Month Later
      Clizby earned a badge
      One Month Later
    • One Month Later
      Timaximus earned a badge
      One Month Later
    • Week One Done
      Timaximus earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      517
    2. 2
      PsYcHoKiLLa
      170
    3. 3
      +Edouard
      162
    4. 4
      Steven P.
      84
    5. 5
      ATLien_0
      78
  • Tell a friend

    Love Neowin? Tell a friend!