• On TV.com: TRUE BLOOD Meets a Werewolf Biker Gang
September 30, 2008 12:12 PM PDT

Yahoo to fix password exposure problem in Zimbra

by Elinor Mills
  • Font size
  • Print
  • 3 comments
Share

New security features planned for Zimbra will resolve an issue responsible for passwords being transmitted as clear when accessing Yahoo Mail, a Yahoo spokeswoman said on Tuesday.

"Plain text authentication is an industry-wide challenge that major e-mail clients and providers face when providing the right balance of backward compatibility and security," a Yahoo spokeswoman said in an e-mail statement.

"Zimbra has plans as part of the next beta release to implement additional new security features to provide more secure authentication options. This approach will be in place in the next few weeks well before we launch the service out of beta," the statement said.

A Canadian programmer discovered the problem during a Yahoo University Hack Day at Waterloo University last week.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
advertisement
Click Here
Recent posts from Security
Defense Dept. pulls software over privacy issues
Microsoft to plug critical IE hole targeted by exploit code
Google wants to unclog Net's DNS plumbing
Avast update falsely flags good apps as malware
Character limitations in passwords considered harmful
McAfee uncovers riskiest domains
EFF sues feds for info on social-network surveillance
Microsoft: November security updates are fine
Add a Comment (Log in or register) (3 Comments)
  • prev
  • 1
  • next
by benjaminstraight September 30, 2008 12:22 PM PDT
security fixes are always good news.
Reply to this comment
by n3td3v September 30, 2008 12:23 PM PDT
Hip, hip hooray!!! Yahoo actually fix something.
Reply to this comment
by jnarvey September 30, 2008 2:58 PM PDT
The Sarah Palin password hack has certainly brought renewed attention to this security issue. Good to see this improvement for end users. Enterprise-class solutions for <a href="http://www.boonbox.net/passpro.htm">secure password self reset</a> exist as well, but it is up to management to ensure they are deployed.
Reply to this comment
(3 Comments)
  • prev
  • 1
  • next
advertisement

The yogurt makers of tech: Gadgets to avoid

Don't buy these one-trick ponies--unless you like gizmos that gather dust.

Google wants to unclog Net's DNS plumbing

The Net giant, ever eager for a faster Internet, debuts its Google Public DNS service. With it, Google could become even more central to the Net.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right