Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 
xlinknz

1115 posts

Uber Geek

Trusted

  #183051 9-Dec-2008 16:19
Send private message

nate: Yes that is true, but the data is only encrypted from your browser to the webmail server.  What Mauricio is talking about is the delivery of the email from the sender's computer to your email server.

My concern is what are you sending/receiving that is sensitive?  I've seen it too often, clients transferring sensitive info such as credit cards via email.  While the possibility of interception is low, it is still a very silly mistake to be making.


Nate I appreciate your [& Mauricio's?] point that the receipant may not be using a secure email such as https. s-mime or PGP end to end. Rest assured I would never send sensitive data such as a credit card or passwords via normal email.





 
 
 

GoodSync. Easily back up and sync your files with GoodSync. Simple and secure file backup and synchronisation software will ensure that your files are never lost (affiliate link).
PenultimateHop
637 posts

Ultimate Geek

Trusted

  #183084 9-Dec-2008 18:00
Send private message

There are two issues with non-encrypted webmail:

1. Transmitting your username and password in the clear - this is just pretty much unacceptable no matter whether your email is transmitted in the clear or not.  This is especially worrying if these credentials are used for other things (e.g. SIP username and password!).
2. While the majority of email on the internet is transmitted node-to-node in the clear, I have seen a reasonable uptake in TLS between mailservers over the last year or so.  Many linux distributions (for instance) include sendmail-tls, postfix-tls, or exim-tls by default.

The key issue to me is that while I don't mind my email zipping around the internet in the clear - because in general it's damn hard to observe that if you're just a casual end user - but I do mind accessing it over a non-encrypted or non-semi-trustable last mile, such as WiFi or a shared LAN (hotel, cybercafe) where you don't know who's doing what to it, particularly on a WiFi network.  It prevents the casual observer snooping around.  Think about how many interesting things are sent in your email unencrypted - banking statements, usernames and passwords to ecommerce accounts, etc.

Encrypting email access is a no-brainer, and should be offered by anyone who is providing webmail servers -- if you have economic issues with an SSL certificate (not that they are particularly expensive anyway), then use a self-signed certificate - at least it's encrypting the traffic!  I personally tunnel all my traffic when I am on a non-trusted connection, either via SSH or IPSec.

1 | 2 
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Synology Introduces BeeStation
Posted 23-Feb-2024 14:14


New One UI 6.1 Update Brings Galaxy AI to More Galaxy Devices
Posted 23-Feb-2024 10:50


Amazon Echo Hub Available in New Zealand
Posted 23-Feb-2024 10:40


InternetNZ Releases Internet Insights 2023
Posted 20-Feb-2024 10:31


Seagate Adds 24TB IronWolf Pro Hard Drives for Multi-user Commercial and Enterprise RAID Storage Solutions
Posted 19-Feb-2024 16:54


Seagate Skyhawk AI 24TB Elevates Edge Security Capacity and Performance
Posted 9-Feb-2024 17:18


GoPro Releases Quik Desktop App for macOS and Introduces Premium+ Subscription Tier
Posted 9-Feb-2024 17:14


Ring Introduces New Ring Battery Video Doorbell Pro
Posted 9-Feb-2024 16:51


Galaxy AI Transforms the new Galaxy S24 Series
Posted 18-Jan-2024 07:00


D-Link launches AI-Powered Aquila Pro M30 Wi-Fi 6 Mesh Systems
Posted 17-Jan-2024 20:02


Newest LG 4K Lifestyle Projector Doubles as Art Objet
Posted 9-Jan-2024 15:50


More LG Smart TV Owners Set To Enjoy the Latest webOS Upgrade
Posted 9-Jan-2024 15:45


Panasonic Announces the Z95A and Z93A With Fire TV Built In
Posted 9-Jan-2024 15:30


Amazon Echo Pop Review
Posted 8-Jan-2024 14:22


Samsung Tab S9 FE Review
Posted 17-Dec-2023 08:26









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.