Yahoo to fix password exposure problem in Zimbra
New security features planned for Zimbra will resolve an issue responsible for passwords being transmitted as clear when accessing Yahoo Mail, a Yahoo spokeswoman said on Tuesday.
"Plain text authentication is an industry-wide challenge that major e-mail clients and providers face when providing the right balance of backward compatibility and security," a Yahoo spokeswoman said in an e-mail statement.
"Zimbra has plans as part of the next beta release to implement additional new security features to provide more secure authentication options. This approach will be in place in the next few weeks well before we launch the service out of beta," the statement said.
A Canadian programmer discovered the problem during a Yahoo University Hack Day at Waterloo University last week.
Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor. 





- by jnarvey September 30, 2008 2:58 PM PDT
- The Sarah Palin password hack has certainly brought renewed attention to this security issue. Good to see this improvement for end users. Enterprise-class solutions for <a href="http://www.boonbox.net/passpro.htm">secure password self reset</a> exist as well, but it is up to management to ensure they are deployed.
- Like this Reply to this comment
-
(3 Comments)