Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Could also be password guessing; lots of people use the "common word + number" pattern for their Yahoo! passwords.


If I remember correctly it was a random alpha-numeric password with both different cases and a special character or two, and I've never used the same password on a different service.

All I know is that I've never had this problem on competing services.


I've found XSS bugs that allow full account takeover being actively exploited on Yahoo! a couple of times. They have a lot of legacy crap that was written 15-20 years ago.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: