Venafi Labs analyzed data from TrustNet, a global database of certificate intelligence, and found that 27% of the certificates on external Yahoo! websites have not been reissued since January, 2015. Only 2.5% of 519 certificates deployed have been issued within the last 90 days, so its likely Yahoo! does not have the ability to find and replace digital certificates quickly. 41% of Yahoo! certificates in the TrustNet data set use SHA-1, a hashing algorithm that is no longer considered secure against well-funded opponents.”]
Source: https://informationsecuritybuzz.com/articles/new-data-reveals-yahoos-post-breach-failings/