ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Yahoo! Mail introduces two factor authentication

By | December 19, 2011, 12:58pm PST

Summary: In an attempt to offer layered security to its millions of Web users, Yahoo Inc. recently announced the availability of two factor authentication for Yahoo! Mail users.

In an attempt to offer layered security to its millions of Web users, Yahoo Inc. recently announced the availability of two factor authentication for Yahoo! Mail users.

More on the feature:

Once the feature is turned on, any suspicious account sign-in attempt will be challenged by a second sign-in verification beyond the initial password validation. To confirm the legitimacy of the sign-in attempt, you or the hijacker will have to answer your account security question or enter a verification code that will be sent to your mobile phone. Presumably, only you, as the legitimate user, can sign in. Account hijackers will be blocked since they neither know your security answer nor possess your mobile phone.

Users who wish to active the second sign-in verification can do it through the Yahoo! Account Info page. The feature is currently available to users residing in the United States, Canada, India, and the Philippines, with the feature extending gradually to all worldwide users by March 2012.

Related posts:

Google announced the availability of two factor authentication for Gmail users in February, 2011.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response.

Disclosure

Dancho Danchev

More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile.

Biography

Dancho Danchev

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog sharing real-time threats intelligence data with the rest of the community on a daily basis. More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile. You can also follow him on Twitter
14
Comments

Join the conversation!

Just In

Yahoo! Mail introduces two factor authentication
Bob luand 5th May
Some of the largest websites are starting to implement this 2FA technology, allowing their users to 'telesign' into their email accounts, social networks, online banking, etc. I definitely think this is the way of the future! As has been stated time and time again ???passwords simply aren???t enough anymore???. For me, the 30 seconds it takes to have the peace of mind that my account won't get hacked and my credit card and personal information isn't up for grabs is well worth it. I wish more organizations would start implementing 2FA.
0 Votes
+ -
Perhaps ZDNet will consider employing two-factor authentication.
Dietrich T. Schmitz * Your Linux Advocate Updated - 19th Dec
It would certainly elevate the quality of the TalkBacks, yes Dancho?
Great to see them taking security more seriously. I hope we get HTTPS soon (beyond the login).
@mttsmth
Absolutely. The one big thing missing with Yahoo Mail is HTTPS. But, it may be too late. I know so many people whose Yahoo Mail accounts have been hacked, and many switched to the biggest fad in town, Gmail, where you are guaranteed to be spied on.
@jorjitop

Gmail a fad? Do you know what a fad is?

What is your basis on the spying accusation? Ads are served up on both Yahoo and Gmail the exact same way.
@anonBNET

I think he's referring to *Google* spying on the emails, as opposed to the 3rd-party advertisers. Not the "we're storing your emails, so there's the possibility that someone might access it accidentally, or in response to a government subpoena" type, but the "We want to target our ads to you based on what you do online, so we're going to look at what you're talking about in your emails, in addition to tracking what you look for with our search engine" type.
-1 Votes
+ -
@spdragoo@... Well you clearly missed the news release about how Yahoo does the exact same thing, as Yahoo has a search engine too, which does the same. If you really don't want to be "spied on" you need something like Hushmail.
-1 Votes
+ -
sdfsdd
jywhy888 7th Mar
Giveaway Material http://www.chinawholesaletown.com/wholesale-Portfolio/ Poncho Raincoat Ice Bottle
Badge Reel http://www.chinawholesaletown.com/wholesale-Digital-Money-Bank/ Car Mini Refrigerator Car Mini Refrigerator
Wholesale Raincoat http://www.chinawholesaletown.com/wholesale-Bottle-Opener-Keychain/ Water Bottle Beach Towel
Cake Towel http://www.chinawholesaletown.com/wholesale-Digital-Spoon-Scale/ Wholesale Memory Card Wholesale Calculator
Pen Holder http://www.chinawholesaletown.com/wholesale-Clip-Dispenser/ Name Card Holder Frosty Beer Mug
Wholesale Bangle http://www.chinawholesaletown.com/wholesale-Stapless-Stapler/ Money Clip Lady Beauty Care
Wholesale Cooler http://www.chinawholesaletown.com/wholesale-Car-Spare-Wheel-Cover/ Wholesale Socks Pen Holder
Wholesale Massager http://www.chinawholesaletown.com/wholesale-Foam--Hand/ Personal Safety Products Hair Products
Bottle Holder http://www.chinawholesaletown.com/wholesale-LED-Flashing-Cap/ China Wholesale Crystal Gifts
Wholesale Fan http://www.chinawholesaletown.com/wholesale-Ring-Opener/ Corner Flag Wholesale Binoculars
Wholesale Ruler http://www.chinawholesaletown.com/wholesale-Electric-Heating-Mugs/ Wholesale Scissors Wholesale Frisbee
Wholesale Hardware Tools http://www.chinawholesaletown.com/wholesale-Training-Clicker-Whistle/ Wholesale Compass Wholesale Lighter
Wholesale Album http://www.chinawholesaletown.com/wholesale-Lunch-Box/ Wholesale Waterproof Case Bottle Opener
Muslim Products http://www.chinawholesaletown.com/wholesale-CD-Cleaner/ Glass Rimmers Wholesale Cup
Wholesale Badge http://www.chinawholesaletown.com/wholesale-Stethoscope-ID-Tag---Opaque_66398/ Wholesale Clothes Rack Wholesale Flashlight
Wholesale Vase http://www.chinawholesaletown.com/wholesale-Desk-Calendars/ Wholesale Kitchenware Wholesale Furniture
Vibram Five Finger Shoe http://www.chinawholesaletown.com/wholesale-Home-Team-Handz-Sports-Gloves-Clapper_108983/ Wholesale Mobile Phone Eye Mask
Wholesale Socks http://www.chinawholesaletown.com/wholesale-Hand-Sanitizer/ Wholesale Keychain Health Care Products
Tire Tote http://www.chinawholesaletown.com/wholesale-Magnifier-Ruler/ Beauty Equipment Wholesale Tag
Wholesale Toys http://www.chinawholesaletown.com/wholesale-Silicone-Wallet/ Money Bank Wholesale Accessories
Pet Waste Bag Dispenser http://www.chinawholesaletown.com/wholesale-Golf-Pouches-and-Bags/ Giveaway Material Silicone Products
Cleaner Products http://www.chinawholesaletown.com/wholesale-Bag-Clip/ Wholesale Calendar Pet Waste Bag Dispenser
Wholesale Keychain http://www.chinawholesaletown.com/wholesale-Fruitpick/ Wholesale Glass Wholesale Camera
Water Filter Bottle http://www.chinawholesaletown.com/wholesale-Survival-Card/ Digital Spoon Scale Glass Rimmers
Bottle Opener http://www.chinawholesaletown.com/wholesale-Pet-Poo-Pick-Bag/ Advertising Material Wine Bottle Cove
Wholesale Stapler http://www.chinawholesaletown.com/wholesale-Cooler-Bag/ Wholesale Mouse Wholesale Scarf
Digital Spoon Scale http://www.chinawholesaletown.com/wholesale-Referee-Ring-Whistle_116906/ Garden Decorations Wholesale Tableware
And what about those of us that do not have a mobile phone and cannot send or receive text messages????
-1 Votes
+ -
@Anynamesleft Then you answer the security question.
I view any Company wanting your cell phone number (NO matter what reason they claim it's for) VERY suspiciously. Many (most) companies SELL your number and/or other info to whomever (mostly spammers) wants to pay for it. Even your own Bank will do it. Last I've read, Yahoo could use the extra money. I suggest using a "Security question" rather than giving your cell number to receive a PIN.
0 Votes
+ -
nice....
Two-factor authentication has overpowered the traditional method of authenticating users, such as hardware tokens which are not scalable when deployed across a large.

To avoid online fraud need has arise to increase some more layers of security to protect your online accounts. Keeping myself updated with such trend, I activated two-factor authentication on my online accounts. The service is good however; at the time of hurry it is a bit annoying. But as far as security is concern it???s great.

Primarily, I read about two-factor authentication method offered by http://www.telesign.com/. Their two-factor authentication works with any phone and can be easily deployed worldwide.

Know more about their two-factor authentication product by visiting them at http://www.telesign.com/products-demos/two-factor-authentication/ and follow TeleSign at Facebook.
0 Votes
+ -
yahoo fails as gmail did
smsfail 24th Mar
mobile carrier is ___NOT___ the only way to receive SMS

I don't want them to have my my mobile number much less sms me

I want the other factor to be XMPP

Since they have all been busily adding XMPP (JabbeR) this ought not be a challege.

I expect to see yahoo mail 2-factor authentication with XMPP before 2013

xmpp: wiping out sms profits the world over

xmpp: free, actually fast, secure, private, open standards
Some of the largest websites are starting to implement this 2FA technology, allowing their users to 'telesign' into their email accounts, social networks, online banking, etc. I definitely think this is the way of the future! As has been stated time and time again ???passwords simply aren???t enough anymore???. For me, the 30 seconds it takes to have the peace of mind that my account won't get hacked and my credit card and personal information isn't up for grabs is well worth it. I wish more organizations would start implementing 2FA.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix