Yahoo Debuts End-To-End Encryption Email Plugin, Password-Free Logins
An anonymous reader writes: Yahoo has released the source code for a plugin that will enable end-to-end encryption for their email service. They're soliciting feedback from the security community to make sure it's built properly. They plan to roll it out to users by the end of the year.
Yahoo also demonstrated a new authentication system that doesn't use permanent passwords. Instead, they allow you to associate your Yahoo account with your phone, and text you a code on demand any time you need to log in. It's basically just the second step of traditional two-step authentication by itself. But Yahoo says they think it's "the first step to eliminating passwords."
Yahoo also demonstrated a new authentication system that doesn't use permanent passwords. Instead, they allow you to associate your Yahoo account with your phone, and text you a code on demand any time you need to log in. It's basically just the second step of traditional two-step authentication by itself. But Yahoo says they think it's "the first step to eliminating passwords."
I hope that if the recipient gets an encrypted email, it shoves the plugin down their throat. Maybe that way people will start adopting encryption.
I don't. I tried to sign up with Yahoo a few weeks ago and got cockblocked by this. They required a mobile number.
Yahoo needs to understand that the purpose of 2-factor authentication was not to replace passwords, but rather to ... provide a second factor of authentication.
Remember ideally:
1. Something you know
2. Something you have
3. Something you are
Each is no more secure than the other, but together they form a far stronger system than any individual component.
What if your phone is dead/stolen and you desperately need to get a message out? You're fucked.
NOTE: They just killed Yahoo! Profiles. In short, they are collecting data for themselves while making it harder and harder for Yahoo! users to search each other out.
*** Don't be dull.***
SQRL completely eliminates the need for passwords https://www.grc.com/sqrl/sqrl....
Oh no, my phone is dead/stolen! Better email people and tell them not to phone me and I'll be reachable by email.
Just need to log into my email and ... ... shit...