Jump to content

Yahoo Offers Abandoned E-Mail Addresses For Re-Use


Recommended Posts

Posted

This looks like an accident waiting to happen...

 

Picture this:

Joe Bloggs registered an account with GambleYourCash.com a couple of years ago using [email protected]. He only used the site once, but registered his card for a free £10 bet and never went back because their odds were rubbish.

He then moved over to gmail and forgot about his old yahoo email.

Jim Bloggs now requests use of [email protected] and gets it. He signs up for GambleYourCash.com but is informed he's already registered, so gets sent a new password. Upon logging in, he sees good old Joe's card details are still sat there, so places a few £1,000 bets for a laugh.

 

[NOTE: GambleYourCash.com does not, as far as I'm aware, exist]

 

I know that's a very simple way of looking at it, and I know Yahoo claim they have measures in place to help sites recognise a recycled email address, but they can't honestly expect every webmaster in the world to start running additional checks on email addresses just because they've decided they want to offer this service.

 

I give it 3 months (from launch) before some major privacy breaches are reported because of somebody exploiting this service.

Posted
This looks like an accident waiting to happen...

 

Picture this:

Joe Bloggs registered an account with GambleYourCash.com a couple of years ago using [email protected]. He only used the site once, but registered his card for a free £10 bet and never went back because their odds were rubbish.

He then moved over to gmail and forgot about his old yahoo email.

Jim Bloggs now requests use of [email protected] and gets it. He signs up for GambleYourCash.com but is informed he's already registered, so gets sent a new password. Upon logging in, he sees good old Joe's card details are still sat there, so places a few £1,000 bets for a laugh.

 

[NOTE: GambleYourCash.com does not, as far as I'm aware, exist]

 

I know that's a very simple way of looking at it, and I know Yahoo claim they have measures in place to help sites recognise a recycled email address, but they can't honestly expect every webmaster in the world to start running additional checks on email addresses just because they've decided they want to offer this service.

 

I give it 3 months (from launch) before some major privacy breaches are reported because of somebody exploiting this service.

 

You've hit the nail on the head there. Stupid idea from Yahoo.

Posted
This looks like an accident waiting to happen...

 

Picture this:

Joe Bloggs registered an account with GambleYourCash.com a couple of years ago using [email protected]. He only used the site once, but registered his card for a free £10 bet and never went back because their odds were rubbish.

He then moved over to gmail and forgot about his old yahoo email.

Jim Bloggs now requests use of [email protected] and gets it. He signs up for GambleYourCash.com but is informed he's already registered, so gets sent a new password. Upon logging in, he sees good old Joe's card details are still sat there, so places a few £1,000 bets for a laugh.

 

[NOTE: GambleYourCash.com does not, as far as I'm aware, exist]

 

I know that's a very simple way of looking at it, and I know Yahoo claim they have measures in place to help sites recognise a recycled email address, but they can't honestly expect every webmaster in the world to start running additional checks on email addresses just because they've decided they want to offer this service.

 

I give it 3 months (from launch) before some major privacy breaches are reported because of somebody exploiting this service.

 

This is why I renewed my first domain, it's blackholing E-Mail from sites I used to sign up to a decade ago but forgot about. :)

  • 2 months later...
Posted
This looks like an accident waiting to happen...

 

Picture this:

Joe Bloggs registered an account with GambleYourCash.com a couple of years ago using [email protected]. He only used the site once, but registered his card for a free £10 bet and never went back because their odds were rubbish.

He then moved over to gmail and forgot about his old yahoo email.

Jim Bloggs now requests use of [email protected] and gets it. He signs up for GambleYourCash.com but is informed he's already registered, so gets sent a new password. Upon logging in, he sees good old Joe's card details are still sat there, so places a few £1,000 bets for a laugh.

 

[NOTE: GambleYourCash.com does not, as far as I'm aware, exist]

 

I know that's a very simple way of looking at it, and I know Yahoo claim they have measures in place to help sites recognise a recycled email address, but they can't honestly expect every webmaster in the world to start running additional checks on email addresses just because they've decided they want to offer this service.

 

I give it 3 months (from launch) before some major privacy breaches are reported because of somebody exploiting this service.

 

To be honest a gambling site would have their own controls to stop something like this - even with your own account you can't just go and deposit thousands straight away, you need to go through the whole 3D secure process to deposit money and I'm pretty sure a sudden £1000 deposit from a dormant account would flag up something on the betting sites fraud alerts

  • 2 weeks later...
Posted

Link: Microsoft is quietly recycling Outlook email accounts | PCWorld

 

...The Microsoft Services Agreement mentions that users are required to log in to their Microsoft accounts "periodically, at a minimum of every 270 days, to keep the Microsoft branded services portion of the services active." Otherwise "we may cancel your access" and "your data may be permanently deleted from our servers."

 

Microsoft does not mention the possibility that email account names will be recycled. The company confirms that this is the policy, however. When the account becomes inactive "the email account is automatically queued for deletion from our servers. Then, after a total of 360 days, the email account name is made available again," according to an email statement from Microsoft...

 

...Google, meanwhile, has confirmed to Webwereld that it does not recycle unused accounts. Users can delete their accounts, but this "won't free up your username. Once you delete your Gmail address, you won't be able to use that same username ([email protected]) in the future," Google says on its site...
Posted
I just put in for my 5.

I asked for 5 accounts that were all expletives. I will see if I get any!

 

Interesting: These 5 that you have requested: Did they exist before [have you asked for them to be recycled] or did you simply take this opportunity to ask for these expletive laden addresses to be created from new?

Posted

In regards to Debit/Credit card information, In theory it will depend on how long the account has been inactive before the card is removed. If I remember correct an active card only lasts around 3 years before you then get a new one so if someone was to leave the card details on an account then it would mean that it wouldn't be able to be used. The website that asks for such information, never gives the full details back to the owner of the account anyway it's always hidden apart from the last 4 digits of the card number & name of the account holder... so even if someone was to recover an account then they would not be able to do much in that sense.

 

It's the other information I would be more bothered about such as Address/Contact Number... If you registered your address and phone number... this could still be the same information although again someone can't really do much with it, knowing that some random person will know my address might be someone upsetting for some people?

 

Just saying... :-)

 

James.

Posted
@EduTech Your point about address is interesting. Imagine that a person had left home to escape their partner and the ex requested their person who had escaped email from yahoo and the escapee had abandoned their email? Then the escapee's partner would know their address and then be able to go 'round. I know someone who was in a similar state and found their information including their phone number on 192.com and the ex had found it. The ex of the escapee went 'round and tried to attack the escapee. Ended up calling the police and the police forcing the website to remove the data. (Sorry I got in to a ramble then!)
Posted
I know Yahoo claim they have measures in place to help sites recognise a recycled email address, but they can't honestly expect every webmaster in the world to start running additional checks on email addresses just because they've decided they want to offer this service.

All they would have to do is add an extra field to the e-mail's header, as per the RRVS IETF standard.

 

Reclaiming Yahoo! Usernames In A Way That’s Secure: Require-Recipient-Valid-Since « YDN Blog

 

As we move forward with making unused Yahoo! usernames available to new owners, we’ve always thought about making the process as secure as possible.

 

I wanted to share one measure we're taking to protect the privacy of our users who had an e-mail address that may be re-used, which is a very small percentage of the accounts that we will be recycling. We encourage anyone using e-mail to communicate with their users, especially for e-commerce and recovering their accounts, to adopt this measure to ensure the security of their users.

 

To communicate that a username has a new owner to e-commerce sites like “JoesAntiques.com,” or social networking sites like Facebook, we’ll allow them to “ask” for a new type of validation when sending an email to a specific Yahoo! user. The field, which can be requested via an email’s header is called “Require-Recipient-Valid-Since.”

 

We feel that our approach, which we've worked on with our friends at Facebook, is a good solution for both our users and our partners.

 

Here’s how it works:

If a Facebook user with a Yahoo! email account submits a request to reset their password, Facebook would add the Require-Recipient-Valid-Since header to the reset email, and the new header would signal to Yahoo! to check the age of the account before delivering the mail. Facebook users typically confirm their email when they sign up for the service or add new emails to their account, and if the “last confirmed” date that Facebook specifies in the Require-Recipient-Valid-Since header is before the date of the new Yahoo! username ownership, then the email will not be delivered and will instead bounce back to Facebook, who will then contact the user by other means.

 

This example illustrates how Facebook will do this – others will have their rules for determining their age requirement for the recipient / receiving account.

 

This is a new standard, being published with the IETF, that we’ll be working with partners to implement, and one that other email service providers can adopt for similar efforts of their own.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...