Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Yahoo has pulled some shady shit with how you sign in to email from Apple devices

Yahoo has pulled some shady shit with how you sign in to email from Apple devices

Scheduled Pinned Locked Moved Uncategorized
passkey
1 Posts 1 Posters 4 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • zcutlip@hachyderm.ioZ This user is from outside of this forum
    zcutlip@hachyderm.ioZ This user is from outside of this forum
    zcutlip@hachyderm.io
    wrote last edited by
    #1

    Yahoo has pulled some shady shit with how you sign in to email from Apple devices

    So my mom tells me she can't get email from any of her devices. Turns out Yahoo had signed her out everywhere: Mac, iPhone, iPad. I had to help tet her signed back in on everything

    It turns out they've broken the sign-in process in the following ways. Note this is *entirely* in the native account sign-in flow in Settings:

    - They've somehow broken password managers in the webview so 1Password won't fill username/password. You have to switch back & forth copying/pasting
    - They've broken #passkey support here as well, I'm guessing due to whatever they did to break password managers. So you get downgraded to a less secure 2FA mechanism like SMS
    - And here’s the kicker: they're injecting a super aggressive interstitial in the sign-in WebView that tries to trick you into downloading the Yahoo Mail app instead of signing in to Mail.app

    There's literally no way my mom could have navigated this. She 100% would have ended up installing an app she doesn't need because Yahoo told her to and because Apple Mail was "broken." I obviously don't *know* what's behind the forced sign-outs and the breaking of password managers and passkeys, but given the aggressive upselling of the Yahoo app, it really seems intentional

    cc @rmondello because passkeys

    1 Reply Last reply
    1
    0
    • R relay@relay.infosec.exchange shared this topic
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Tags
    • Popular
    • World
    • Users
    • Groups