Yahoo Investigates Cookie Powered Password Bypass Hack
Yahoo is investigating a claim that a hacker created the means to access its users’ account data without needing their passwords.
In a filing to the US Securities and Exchange Commission Yahoo said that law enforcement agencies began sharing information they indicated was provided by the hacker who claimed it was account data from their users.
It is unclear whether this hacker and the data relates to the massive data leak Yahoo recently suffered or new leaked data. Yahoo said its investigation has it looking into whether the hacker could have gained access to the data by creating website ‘cookies’ that allowed normal password protection to be bypassed, though a according to the Financial Times, a source familiar with the issue said Yahoo does not believe it is possible for hackers to forge valid Yahoo Mail cookies.