Wired

Webmonkey

  • Web Dev & Design
    • Ajax
    • Backend
    • Blog Publishing
    • CSS
    • Databases
    • Fonts
    • Frameworks
    • HTML
    • HTML 5
    • JavaScript
    • Mobile
    • Multimedia
    • Programming
    • Security
    • UI/UX
    • Web Standards
  • Software & Apps
    • Browsers
    • Software
    • Web Apps
  • Platform & APIs
    • APIs
    • Identity
    • Location
    • Social
    • Web Services
  • Reference
    • Color Charts
    • HTML Cheat Sheets
    • Special Characters
    • Glossary
    • Templates
    • Code Snippets
  • twitter
  • facebook
  • RSS Feeds
Sep 29 2008
File Under: Software & Tools

Yahoo Mail Security Flaw Exposes Passwords

  • By Scott Gilbertson

ZimbraA hacker working on a way to access Yahoo Mail via IMAP, recently discovered that Yahoo’s desktop e-mail client is sending your password as plain text. That’s bad news for those of you using the desktop client over public wifi connections, where just about anyone with the know-how can see your unencrypted traffic.

Zimbra, creators of what is now the Yahoo Mail desktop client, responded to the news by assuring users that a fix is already in the code and just needs to be pushed out. The problem however seems to be primarily on Yahoo’s end, since the IMAP servers appear to refuse secure connections.

A Zimbra employee writes on the company’s forum site:

This issue has been addressed from Yahoo mail server side and the patches have just been rolled out to all servers. We added related support in desktop client code and it’s in the next release. Once we roll out the next release, server will phase out the old way of authentication. The new way of authentication will not send password over clear channels.

In the mean time we would suggest sticking with the web-based e-mail client when you’re working on public or otherwise insecure internet connections.

See Also:

  • Yahoo Mail Adds Free IMAP Access for Zimbra Users
  • Zimbra Office Suite Adds Offline Support
  • Yahoo Mail To Offer Unlimited Storage Space
  • Yahoo Mail Adds Phishing Protection
Tags: e-mail, Security
  • Post Comment  | 
  • Permalink

Comments (0)

All fields required

Webmonkey's Picks

Browse Our Tutorials

HTML, JavaScript, design and more

Cheat Sheets

HTML, CSS and special characters

Color Charts

Brighten up your pages

Cut & Paste Code

Templates and snippets you can steal

Recent Comments

  • Eldo Mendez on Thau’s JavaScript Tutorial
  • Lou on Verizon Makes Sure NYC Gets Plenty of Fiber
  • Casey on Amazon Is Building a Better Browser for Kindle
  • zannd on Win A Free Ticket to Google IO 2010
  • $name on Amazon Is Building a Better Browser for Kindle
  • Recent Articles

  • Google Launches Web Store for Cloud-Based Apps
  • Facebook Finds its Place in the Location-Sharing Landscape
  • Google Gets a New Geocoder
  • Amazon Is Building a Better Browser for Kindle
  • Meet the Winners of Webmonkey’s Google I/O Giveaway
  • Corrections | Sitemap | FAQ | Contact Us | Wired Staff | Advertising | Press Center | Subscription Services | Newsletter | RSS Feeds
    Condé Nast Web Sites:
    Webmonkey | Reddit | ArsTechnica | Details | Golf Digest | GQ | New Yorker

    Registration on or use of this site constitutes acceptance of our User Agreement (Revised 4/1/2009) and Privacy Policy (Revised 4/1/2009).

    Wired.com © 2010 Condé Nast Digital. All rights reserved.

    The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Condé Nast Digital.