There's a Lesson About Yahoo! Security I Learned from Palin Today

Tagged:  

The lesson is this: Yahoo! doesn't use encryption on their webmail. I'll repeat that: YAHOO! DOESN'T USE ENCRYPTION ON THEIR WEBMAIL!

I'm nothing short of shocked. I could have sworn that Yahoo! was a $26B company. Surely, SURELY they, of all people would see the importance and value of secure email, right? Nope.

They've been offering free email since at least April of 1996 when they had their IPO. Somehow in the last 12 years they never secured the damned thing? What?

Note below the conspicuous use of http rather than https:

I found an article today that indicates that as of 2000 yahoo has been working on this problem. Still no solution though.

Here's the link, if you're interested: http://news.cnet.com/2100-1023-249140.html

FWIW, Gmail doesn't seem to use encryption, either. Both use https for authentication, though, which is perhaps the most important thing. Then they redirect to a non-encrypted URL for the mail session itself, which does leave you open to local sniffing or some man-in-the-middle trickery...

True, but you can turn it on by going into the Settings > Browser connection. It should be on by default though. No doubt about that.

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
  • You can enable syntax highlighting of source code with the following tags: <code>, <blockcode>.

More information about formatting options

By submitting this form, you accept the Mollom privacy policy.