Cisco Learning Network Store Promotions Page
Showing posts with label Yahoo Mail. Show all posts
Showing posts with label Yahoo Mail. Show all posts

3.16.2015

Yahoo introduces On-demand passwords and demoes end-to-end-encryption

 
The idea of forgetting the password for your email account might seem odd, but it happens. You might be one of those people who signed up for a Yahoo email address years ago, moved on to something better, and now only check in every few months to see if you've missed anything.
 
To combat the problem of forgotten passwords, Yahoo is introducing a new feature called On-demand passwords. There's no need to battle through the process of answering security questions to reset your password when you forget it; now you can create a temporary password that gets sent to your phone.
 
Chris Stoner, Director of Product Management, explains that the new feature eliminates the stress and anxiety that goes hand in hand with forgetting a password. It’s an option that’s only available in the US for the time being, but it's hard to imagine that it wouldn’t roll out to other parts of the world if it proved successful. In a blog post, Stoner wrote:
Today, we’re hoping to make that process less anxiety-inducing by introducing On-demand passwords, which are texted to your mobile phone when you need them. You no longer have to memorize a difficult password to sign in to your account -- what a relief!
In order to get the feature set up, you will have to remember your password at least once so you can log in and access your account settings. Head to the Account Security section of settings, activate the On-demand passwords feature, and confirm your phone number.
 
Yahoo also announced a preview of a new end-to-end encryption system. The feature will come to Yahoo Mail, and it is hoped that it will be implemented by the end of the year. The source code is available on GitHub and the video below was shown at SXSW by way of an introduction:
 
 
Photo credit: Brt / Shutterstock
 
~ Mark Wilson

1.08.2014

Yahoo finally enables HTTPS encryption for email by default

Summary: Yahoo webmail users will get a significant security benefit with the company enabling encryption by default. 
 
From today, Yahoo will begin encrypting all email connections by default, offering its users the same additional security that Google rolled out for Gmail in 2010.
 
Meeting the January 8 deadline it announced last October, Yahoo has enabled Secure Sockets Layer (SSL) — denoted by 'HTTPS' in browsers' URL bar — encryption by default for its roughly 200 million Yahoo Mail users.
 
The change means that Yahoo Mail users no longer need to manually configure their accounts to enable SSL encryption for mail, which encrypts communications between the browser and Yahoo's web servers and is meant to ensure to the user the site they're communicating with really is what it claims to be.
 
"Anytime you use Yahoo Mail — whether it's on the web, mobile web, mobile apps, or via IMAP, POP or SMTP — it is 100 percent encrypted by default and protected with 2,048 bit certificates," Jeff Bonforte, Yahoo SVP of communication products, wrote in a company blog post.
 
Yahoo initially outlined plans to enable HTTPS by default, but later confirmed it would implement it with 2048-bit certificates, which is the minimum others, led by Google and Microsoft, have moved towards. So, while HTTPS by default is good news for Yahoo users, it's also come to Yahoo quite late compared to other webmail providers.
 
Google enabled SSL by default for Gmail in 2010, SSL by default in search (for signed-in users) in 2011 and now makes all searches SSL by default. Also, in November it completed its upgrade of all SSL certificates to 2048-bit RSA, with the longer key lengths making it harder to crack SSL connections.
 
Yahoo's plans to encrypt mail by default came after the first leaks from Edward Snowden, revealing the US National Security Agency (NSA) spy programs that targeted major US internet companies.
 
The NSA has also prompted a bigger response from Yahoo, which since pledged to encrypt all data moving from the internet to its servers and all data moving between its datacentres, with the latter being a response to revelations of the NSA's 'Muscular' program, which exploited unencrypted links between datacentres of Yahoo and Google.
 
~ Liam Tung