In my experience, the notifications aren't reliable.
As for the insecurity: basically, if anyone every observes the traffic between your phone and Yahoo during authentication, they have all the information they need to access to your e-mail account. Yahoo invented their own authentication scheme, and it sucks. Badly. Plus, the connection is unencrypted.
Bottom line: if you ever use your iPhone on a public hotspot, you're a sitting duck.