SushiEater wrote:
Yet, most spam I get is from Gmail people. I don't even remember getting one from Yahoo.
You must be living in a bubble, since compromises of Yahoo mail users have been in the news a lot over the past year.
Here's one article on the subject:
http://www.hotforsecurity.com/blog/yahoo-accounts-hijacked-via-xss-type-attack-5172.html
Here's another:
http://www.hotforsecurity.com/blog/yahoo-accounts-hijacked-via-xss-type-attack-5172.html
Those vulnerabilities were present for a number of months, even after they had supposedly fixed them the first time (there are earlier articles about the same kind of thing).
Criminals took advantage of the ability to hijack Yahoo e-mail accounts by the use a vulnerability to steal a cookie that tells yahoo you're already logged in to an account.
So, no cracking of passwords was needed. All they needed to do was get a yahoo user to click on a link in their e-mail and they could then get full access to that user's Yahoo account by stealing the cookie associated with login credentials.
Then, they'd send the same kind of mail to compromise other accounts. For example, you'd see an e-mail from someone you know (with an already compromised account, thanks to it being hijacked), and click on the link in it so that they'd compromise your e-mail account, too (and the problem continued to escalate for months, with more and more compromised Yahoo Mail accounts).
Sure, other sites have experienced problems with vulnerabilities, too.
But, Yahoo Mail has had more than other mail sites from what I've seen in the press.
As for Gmail, I suspect that someone had malware on their system stealing login credentials if you saw the same thing from Gmail users, as Google has been a lot better than Yahoo at keeping security from vulnerabilities tighter.
Or, another site the users were logging into was hacked and their e-mail credentials were stolen. That happens a lot anymore. But, Yahoo's reputation is pretty bad in that area.
Also, Gmail has one of the best spam filtering systems available (if not the best).
--
JimC
------