Yahoo wants to kill off email passwords
Forget passwords: Yahoo will send one-time codes to your phone instead

You needn't fear about forgetting your password anymore, with Yahoo getting rid of them for users of its email service.
Instead, the tech giant hopes to provide greater security by texting one-time passwords to customers' phones, so all they have to remember is their log-in username.
Yahoo hopes to make its free email less susceptible to hackers, with Password' and 123456' proving to be the most popular passwords in 2014, according to security firm SplashData's latest annual survey.
Chris Stoner, director of product management at Yahoo, said in a blog post: "We're hoping to make that [log-in] process less anxiety-inducing by introducing on-demand passwords, which are texted to your mobile phone when you need them.
"You no longer have to memorise a difficult password to sign in to your account - what a relief!"
The opt-in service is currently only available in the US, where customers wishing to try it out must sign into their Yahoo email account as normal. Then, they can go into their account information listed under their profile, click on "security" and choose to enable "on-demand passwords".
By entering their phone number, users receive a verification code that sets them up to use the new service.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The next time users sign in, instead of a password box, there will be a button saying "send my password" clicking it will prompt Yahoo to text you a four-character password.
But security analyst Graham Cluley was less than impressed, warning that your email could be hacked simply by you misplacing your phone.
"Personally I would baulk at the idea of my online bank offering access via that method," he told IT Pro. "After all, if access to your account is only controlled by who has access to your phone that's not a good thing.
"How many of us can put our hands on our hearts and say that we have never left our smartphone unattended somewhere, even for a short time?"
He predicted that there would be "a spate of pranksters" trying to abuse the system, adding: "What's so wrong with telling people to have a strong password instead - and perhaps promoting a password manager like 1Password and LastPass to users to encourage them to use a different, complex password for every site they use?"
The news comes after Visa announced it was working with MasterCard last year to eradicate extra passwords account holders currently must enter when making online transactions.
In contrast to Cluley, Chris Boyd, malware intelligence analyst at security firm Malwarebytes, welcomed Yahoo's move to get rid of existing password technology.
"It remains to be seen how vulnerable to attack the service is, but it can only be a good thing that a well-known brand in the technology field is seeking different ways to revamp the password," he said.
But he questioned whether it would improve on two-factor authentication, where users must provide two proofs of their identity by, for example, providing a password and a fingerprint.
"Anything that simplifies the log-in process is always potentially a good thing, though I'd choose two factor over so-called one factor' any day," said Boyd.
He added that Yahoo now boasts as secure a free email service as any rival, with the new tool in addition to other security measures it already has, including two-factor authentication and unusual log-in activity detection.
-
Blackouts in Spain and Portugal could be a cyber attack
Both countries are "paralyzed" by nationwide power outages
By Jane McCallion
-
Cisco takes aim at AI security at RSAC with ServiceNow partnership
News The companies claim Cisco AI Defense and ServiceNow SecOps will help address new challenges raised by AI
By Jane McCallion
-
I love magic links – why aren’t more services using them?
Opinion Using magic links instead of passwords is safe and easy but they’re still infuriatingly underused by businesses
By Solomon Klappholz
-
Password management startup Passbolt secures $8 million to shake up credential security
News Password management startup Passbolt has secured $8 million in funding as part of a Series A investment round.
By Ross Kelly
-
LastPass breach comes back to haunt users as hackers steal $12 million in cryptocurrency
News The hackers behind the LastPass breach are on a rampage two years after their initial attack
By Solomon Klappholz
-
GitHub launches passkeys beta for passwordless authentication
News Users can now opt-in to using passkeys, replacing their password and 2FA method
By Daniel Todd
-
Microsoft SQL password-guessing attacks rising as hackers pivot from OneNote vectors
News Database admins are advised to enforce better controls as attacks ending in ransomware are being observed
By Rory Bathgate
-
No, Microsoft SharePoint isn’t cracking users’ passwords
News The discovery sparked concerns over potentially invasive antivirus scanning practices by Microsoft
By Ross Kelly
-
Microsoft Authenticator mandates number matching to counter MFA fatigue attacks
News The added layer of complexity aims to keep social engineering at bay
By Connor Jones
-
As Google launches passwordless authentication for all, what are the business benefits of passkeys?
News Google follows Apple in its latest shift to passwordless authentication, but what are the benefits?
By Ross Kelly