Having worked at Yahoo! and being directly involved with an instance of a few million phished accounts I can only say that they take this stuff very seriously. We had a team of 5 or 6 people working about 2 months to resolve this issue.<p>When you're the size of Yahoo! it's not just a simple code push. The process of letting users recover their accounts is very tricky.<p>Anyways, I have plenty of gripes about Yahoo! but how they deal with security is not one of them.