TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Yahoo admits mangling e-mail (2002)

254 pointsby Andoryuutaalmost 3 years ago

24 comments

uudecodedalmost 3 years ago
This literally caused me to have a bad taste in my mouth when I was in high school:<p>My yearbook advisor sent yahoo mail and asked what I would like to be picked up at Starbucks for an early morning meeting the next day.<p>&quot;Caramel Mocha, thank you!&quot;, I replied.<p>The next morning, I was surprised with an undrinkable &quot;Caramel espresso&quot; - an espresso with a pump of caramel syrup. I thought she had made an innocent mistake and was shocked to see there was in fact a difference between my sent text and her received text. I had no explanation.<p>After some years in web dev, and encountering this article, I realized that, as the precursor to javascript - the script type &quot;mocha&quot; was valid, so yahoo just went ahead and replaced all references to mocha with something that probably seemed innocuous to a junior developer - except it wasn&#x27;t.
评论 #31964097 未加载
评论 #31964068 未加载
评论 #31961669 未加载
mr-ronalmost 3 years ago
Tangent related to this. I had an old yahoo mail address from late 90s till mid 00s before I switched to gmail. Lots of family &#x2F; high school &#x2F; college &#x2F; early professional emails were there.<p>The other month I logged in to view them as I do every so often and yahoo had purged the entire archive. Like 20MB worth of emails gone.<p>Apparently they have a policy if you do not log in in a year of time they will delete everything with no way to recover.<p>I can’t imagine the decision making to put this policy in nor could I ever imagine using yahoo email again for any purpose whatsoever.
评论 #31961514 未加载
评论 #31961163 未加载
评论 #31961276 未加载
评论 #31963696 未加载
评论 #31961739 未加载
评论 #31963397 未加载
评论 #31965612 未加载
评论 #31961543 未加载
评论 #31961298 未加载
评论 #31965689 未加载
评论 #31961457 未加载
评论 #31961289 未加载
评论 #31964888 未加载
评论 #31963614 未加载
评论 #31962266 未加载
评论 #31961764 未加载
robinhoustonalmost 3 years ago
This is very funny. At least one of the resulting words is sufficiently attested to have been recorded by Wiktionary.<p><a href="https:&#x2F;&#x2F;en.wiktionary.org&#x2F;wiki&#x2F;medireview" rel="nofollow">https:&#x2F;&#x2F;en.wiktionary.org&#x2F;wiki&#x2F;medireview</a><p>&gt; Etymology: Coined accidentally by Yahoo! Mail in 2001, from medieval by automated string substitution of review for eval, a Javascript command short for evaluate.
评论 #31961098 未加载
yvoschaapalmost 3 years ago
I remember sending fake Yahoo login forms as html attachments. eval() &amp; alert() fix:<p>`const ev = &#x27;ev&#x27;, al = &#x27;al&#x27;, ert = &#x27;ert&#x27;; window[ev + al](window[al + ert](&#x27;hi&#x27;))`
评论 #31964085 未加载
评论 #31962898 未加载
JohnJamesRamboalmost 3 years ago
I feel like my IQ increased 20 points just looking at a page laid out like this.
评论 #31960782 未加载
评论 #31960691 未加载
评论 #31960686 未加载
lbrineralmost 3 years ago
Yahoo&#x27;s latest tactic is just to insist on complete DMARC alignment to even stand a chance of being delivered. We have no problems with pretty much any other provider apart from them. And of course, they won&#x27;t help you understand what is wrong with a particular message and how to avoid spam traps because &quot;that would help phishing&quot;, which of course is patently nonsense since GMail pretty much tell you how to keep you mail acceptable.
评论 #31960368 未加载
评论 #31960384 未加载
kstrauseralmost 3 years ago
Clbuttic problem with content filtering.
评论 #31960724 未加载
bcravenalmost 3 years ago
Here&#x27;s a contemporary site where the users discuss their confusion.<p>&quot;When did &quot;Medireview&quot; = Medieval???&quot;<p><a href="https:&#x2F;&#x2F;www.enworld.org&#x2F;threads&#x2F;when-did-medireview-medieval.4600&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.enworld.org&#x2F;threads&#x2F;when-did-medireview-medieval...</a>
评论 #31961712 未加载
评论 #31961393 未加载
评论 #31960816 未加载
billpgalmost 3 years ago
I get not wanting to forward JS in email messages onto your customers whose browsers will run it and forward your login cookies to criminals.<p>I do not get thinking that replacing the word &quot;eval&quot; with &quot;review&quot; is a solution to that problem.
cookie_monstaalmost 3 years ago
Almost completely OT, but reminds me of a company I used to write for who for reasons decided that we weren&#x27;t authors any more, but writers. Somebody did a find n replace on the documentation which lead to some interesting constructions like &quot;if a piece has been writered by multiple writers...&quot;
unixbanealmost 3 years ago
Content modification usually leads to vulns (e.g, XSS filters, possible bitsquatting enabled here if they change URLs or breaking array bounds checks in programs). Classic 90s security. Too bad 90s security never went away.
d4aalmost 3 years ago
It&#x27;s the Sc**horpe problem all over again
brrrrrmalmost 3 years ago
Some of the phrasing is quite fascinating! E.g. “kidnap personal information”
Mo3almost 3 years ago
Simpler times.. sometimes I miss them.
starik36almost 3 years ago
They are still mangling it. If you are setting up IMAP, they only allow you to download the latest 10,000 messages.
annexrichmondalmost 3 years ago
Interesting that the article is filed under `Science&#x2F;Nature` instead of `Technology`
1vuio0pswjnm7almost 3 years ago
Dumb user question: Why is this URL redirecting to <a href="https:&#x2F;&#x2F;" rel="nofollow">https:&#x2F;&#x2F;</a> from <a href="http:&#x2F;&#x2F;" rel="nofollow">http:&#x2F;&#x2F;</a>
评论 #31963173 未加载
评论 #31965328 未加载
评论 #31964223 未加载
Andoryuutaalmost 3 years ago
Came across this and thought it was an... amusing filter.
Pakdefalmost 3 years ago
While not as bad, I lost my Rocketmail account because I didn&#x27;t login for a few months... haven&#x27;t used Yahoo since.
quickthrower2almost 3 years ago
&quot;Mocha to espresso&quot; ... well that is for the greater good.
cratermoonalmost 3 years ago
%s&#x2F;eval&#x2F;review&#x2F;g
iso1631almost 3 years ago
Obligatory Tom Scott video on the Scunthorpe problem<p><a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=CcZdwX4noCE" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=CcZdwX4noCE</a>
ThePowerOfFuetalmost 3 years ago
(2002)
haunteralmost 3 years ago
Why the Archive.org link?<p><a href="http:&#x2F;&#x2F;news.bbc.co.uk&#x2F;2&#x2F;hi&#x2F;science&#x2F;nature&#x2F;2138014.stm" rel="nofollow">http:&#x2F;&#x2F;news.bbc.co.uk&#x2F;2&#x2F;hi&#x2F;science&#x2F;nature&#x2F;2138014.stm</a>
评论 #31960659 未加载
评论 #31961444 未加载
评论 #31960615 未加载
评论 #31961282 未加载