D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] .bad apple.

 

 On 28/03/2013 09:04, Brad Rogers wrote:
On Thu, 28 Mar 2013 00:03:13 +0000
bad apple<ifindthatinteresting@xxxxxxxxx>  wrote:

Hello bad,

My only guess is that yahoo are leaking unsalted and perhaps even
The problem is, was, and ever will be yahoo.  They appear to have no
interest in closing their security holes.

Over the past few months I've seen, literally, hundreds of yahoo
accounts compromised.  Many, like yours, can't be as a result of duped
account holders;  The account holders are simply too astute to fall for
that trick.
Agreed. I have a Yahoo account, which I have actually only ever used *once*. It only exists because I subscribe to a couple of Yahoo Groups and you seem to automatically get a Yahoo email address. It was used on that occasion to sign up to one of them. Lo and behold a month or so ago I got a spam mail from that account - I think I'd copied my main address on the sign up mail - and the only other recipient of the mail was the person I had sent the sign up email to. At that point the list admin had been telling everyone the problem was clicking on links in emails and getting hacked that way. I pointed out my Yahoo account is *never* used so that was impossible and restated that Yahoo/GMail/Hotmail etc regularly get hacked simply because they are attractive targets with a potentially large payload. He amended his advice to the group, although of course kept the standard advice not to click on links etc as well.

Depending on how much people use their accounts, one almost foolproof way to prevent spam that was suggested is to empty the address book. Then keep a separate text file of addresses and copy/paste them as required into emails, and of course periodically empty the address book of collected addresses. It won't stop you getting hacked but it will stop your account being used to spam your contacts.

Alternatively put a rubbish address at the top of your address book, so if it *is* used for spam that one will bounce first and you'll get fairly quick notice as it will bounce back to you.

Julian

--
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq