• On GameSpot: So-called 'Halo killer' gets 23 to life
September 30, 2008 12:12 PM PDT

Yahoo to fix password exposure problem in Zimbra

by Elinor Mills
  • Font size
  • Print
  • 3 comments

New security features planned for Zimbra will resolve an issue responsible for passwords being transmitted as clear when accessing Yahoo Mail, a Yahoo spokeswoman said on Tuesday.

"Plain text authentication is an industry-wide challenge that major e-mail clients and providers face when providing the right balance of backward compatibility and security," a Yahoo spokeswoman said in an e-mail statement.

"Zimbra has plans as part of the next beta release to implement additional new security features to provide more secure authentication options. This approach will be in place in the next few weeks well before we launch the service out of beta," the statement said.

A Canadian programmer discovered the problem during a Yahoo University Hack Day at Waterloo University last week.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
Recent posts from Security
Log in with your face
See what's under McAfee's new interface
26 Windows, Office holes patched in 13 bulletins
McAfee: Spammers exploiting more news stories
Microsoft, Google split over browser bug bounty
Verizon temporarily blocks some 4chan sites
Security software maker Vitamin D exits beta
China breaks up Black Hawk hacking ring
Add a Comment (Log in or register) (3 Comments)
  • prev
  • next
by benjaminstraight September 30, 2008 12:22 PM PDT
security fixes are always good news.
Reply to this comment
by n3td3v September 30, 2008 12:23 PM PDT
Hip, hip hooray!!! Yahoo actually fix something.
Reply to this comment
by jnarvey September 30, 2008 2:58 PM PDT
The Sarah Palin password hack has certainly brought renewed attention to this security issue. Good to see this improvement for end users. Enterprise-class solutions for <a href="http://www.boonbox.net/passpro.htm">secure password self reset</a> exist as well, but it is up to management to ensure they are deployed.
Reply to this comment
(3 Comments)
  • prev
  • next
advertisement

Google's social side aims for some Buzz

Facebook and Twitter are the darlings of the social-media world, not Google--which hopes to change that with Buzz, betting it can organize your online social life.

Watching the birth of a gaming start-up

Stewart Butterfield and his friends are back at it with a new company. CNET's Daniel Terdiman was given exclusive, behind-the-scenes access as they built it from scratch.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right