Geekzone: technology news, blogs, forums
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.

View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 

997 posts

Ultimate Geek


  #183051 9-Dec-2008 16:19
Send private message

nate: Yes that is true, but the data is only encrypted from your browser to the webmail server.  What Mauricio is talking about is the delivery of the email from the sender's computer to your email server.

My concern is what are you sending/receiving that is sensitive?  I've seen it too often, clients transferring sensitive info such as credit cards via email.  While the possibility of interception is low, it is still a very silly mistake to be making.

Nate I appreciate your [& Mauricio's?] point that the receipant may not be using a secure email such as https. s-mime or PGP end to end. Rest assured I would never send sensitive data such as a credit card or passwords via normal email.

637 posts

Ultimate Geek


  #183084 9-Dec-2008 18:00
Send private message

There are two issues with non-encrypted webmail:

1. Transmitting your username and password in the clear - this is just pretty much unacceptable no matter whether your email is transmitted in the clear or not.  This is especially worrying if these credentials are used for other things (e.g. SIP username and password!).
2. While the majority of email on the internet is transmitted node-to-node in the clear, I have seen a reasonable uptake in TLS between mailservers over the last year or so.  Many linux distributions (for instance) include sendmail-tls, postfix-tls, or exim-tls by default.

The key issue to me is that while I don't mind my email zipping around the internet in the clear - because in general it's damn hard to observe that if you're just a casual end user - but I do mind accessing it over a non-encrypted or non-semi-trustable last mile, such as WiFi or a shared LAN (hotel, cybercafe) where you don't know who's doing what to it, particularly on a WiFi network.  It prevents the casual observer snooping around.  Think about how many interesting things are sent in your email unencrypted - banking statements, usernames and passwords to ecommerce accounts, etc.

Encrypting email access is a no-brainer, and should be offered by anyone who is providing webmail servers -- if you have economic issues with an SSL certificate (not that they are particularly expensive anyway), then use a self-signed certificate - at least it's encrypting the traffic!  I personally tunnel all my traffic when I am on a non-trusted connection, either via SSH or IPSec.

1 | 2 
View this topic in a long page with up to 500 replies per page Create new topic

News »

Nanoleaf enhances lighting line with launch of Triangles and Mini Triangles
Posted 17-Oct-2020 20:18

Synology unveils DS16211+
Posted 17-Oct-2020 20:12

Ingram Micro introduces FootfallCam to New Zealand channel
Posted 17-Oct-2020 20:06

Dropbox adopts Virtual First working policy
Posted 17-Oct-2020 19:47

OPPO announces Reno4 Series 5G line-up in NZ
Posted 16-Oct-2020 08:52

Microsoft Highway to a Hundred expands to Asia Pacific
Posted 14-Oct-2020 09:34

Spark turns on 5G in Auckland
Posted 14-Oct-2020 09:29

AMD Launches AMD Ryzen 5000 Series Desktop Processors
Posted 9-Oct-2020 10:13

Teletrac Navman launches integrated multi-camera solution for transport and logistics industry
Posted 8-Oct-2020 10:57

Farmside hits 10,000 RBI customers
Posted 7-Oct-2020 15:32

NordVPN starts deploying colocated servers
Posted 7-Oct-2020 09:00

Google introduces Nest Wifi routers in New Zealand
Posted 7-Oct-2020 05:00

Orcon to bundle Google Nest Wifi router with new accounts
Posted 7-Oct-2020 05:00

Epay and Centrapay partner to create digital gift cards
Posted 2-Oct-2020 17:34

Inseego launches 5G MiFi M2000 mobile hotspot
Posted 2-Oct-2020 14:53

Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Support Geekzone »

Our community of supporters help make Geekzone possible. Click the button below to join them.

Support Geezone on PressPatron

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.