Live data from Hacker News

Give to Thunderbird

give.thunderbird.net

101–110 of 129 posts

Re: Give to Thunderbird

#101

I used Thunderbird for a very long time but recently stopped. Every update has made it slower, breaks a host of extensions, and the Google Calendar integration is consistently broken no matter which solution I use. I really, really want to use Thunderbird but email and calendar need to Just Work. I can't keep fixing it every time they push out an update

This 13 year old bug in the calendar has been pretty frustrating. Would love to donate specifically towards a fix for that. But I guess that's not an option.

https://bugzilla.mozilla.org/show_bug.cgi?id=475886

Re: Give to Thunderbird

#102
post #69

Earlier quoted context omitted.

Did you get this extension audited by your security team? It sounds insane to me that you’re bypassing IMAP restrictions, with a plug-in that monitors and parses the entire O365 website…

That addon got the exact same stringent audit by my security team as did the Firefox web browser that I installed to browse the entire O365 website to begin with.

The trust level for Firefox as a browser, versus a random extension that parses O365, would be very different for me. And at the company I work at.

I’m surprised you got this one approved.

Re: Give to Thunderbird

#103
post #101

I used Thunderbird for a very long time but recently stopped. Every update has made it slower, breaks a host of extensions, and the Google Calendar integration is consistently broken no matter which solution I use. I really, really want to use Thunderbird but email and calendar need to Just Work. I can't keep fixing it every time they push out an update

This 13 year old bug in the calendar has been pretty frustrating. Would love to donate specifically towards a fix for that. But I guess that's not an option. https://bugzilla.mozilla.org/show_bug.cgi?id=475886

FWIW, for some accounts I use a second profile via `thunderbird --new-instance`.

Re: Give to Thunderbird

#104
post #102

Earlier quoted context omitted.

That addon got the exact same stringent audit by my security team as did the Firefox web browser that I installed to browse the entire O365 website to begin with.

The trust level for Firefox as a browser, versus a random extension that parses O365, would be very different for me. And at the company I work at. I’m surprised you got this one approved.

I interpreted his comment as saying he did not ask permission. Probably he'll be fine as long as nothing he did was explicitly against any rules, even if it is clearly against the spirit of the rules. More likely still, no one will ever find out.

Re: Give to Thunderbird

#105
post #102

Earlier quoted context omitted.

The trust level for Firefox as a browser, versus a random extension that parses O365, would be very different for me. And at the company I work at. I’m surprised you got this one approved.

I interpreted his comment as saying he did not ask permission. Probably he'll be fine as long as nothing he did was explicitly against any rules, even if it is clearly against the spirit of the rules. More likely still, no one will ever find out.

He’ll be fine as long as the extension doesn’t steal data. The moment that happens, his job is on the line.

Re: Give to Thunderbird

#106
I donate semi-regularly. Been using Thunderbird as my primary email client (almost) since its release. The installation has hundreds of thousands of mails across many folders, and yet, it is super fast and rock solid.

Re: Give to Thunderbird

#107
post #24

On GNU/Linux Thunderbird ist my favourite GUI mail client, offering support for a variety of standards, including e.g. CalDAV (CardDAV in Beta), OpenPGP and S/MIME. Not sure whether Chat should be part of it, currently offering Google Talk, IRC, Odnoklassniki, and XMPP (Twitter finally gone). Support for Usenet News is appreciated, though I enjoy Pan. On GNU/Linux I thus consider GNOME Evolution as best alternative.…

KMail used to be wonderful, but Akonadi has been a train wreck since day one. I had to switch to Thunderbird for work eventually because it just wasn't acceptable to not respond to urgent things because "sorry, my mail client decided to silently stop checking for mail again!".

Re: Give to Thunderbird

#108
post #83
post #71

Earlier quoted context omitted.

To be fair, it’s the security team’s idiotic position on IMAP that prompted the parent commenter to find a workaround. It’s like how having super draconian password reset and complexity requirements ends up being less secure because users will start writing their impossible-to-remember passwords on post-it notes.

There’s a big difference between password reset rules, and giving third-parties access to emails and calendar. There is nothing draconian about restricting IMAP - any app could exfiltrate confidential emails once granted access. It’s a very sane rule to disallow everything except webmail or first party apps.

It's a terrible process for the users. And as we can see what did it get them, a third party logging into there webmail.

The service is protected with a username and password, didn't matter if it was IMAP or webmail.

Re: Give to Thunderbird

#109
post #71

Earlier quoted context omitted.

To be fair, it’s the security team’s idiotic position on IMAP that prompted the parent commenter to find a workaround. It’s like how having super draconian password reset and complexity requirements ends up being less secure because users will start writing their impossible-to-remember passwords on post-it notes.

The IMAP blocking is for different draconian reasons. Office365 does not support Modern Auth with IMAP, which is considered a security baseline now.

It's the complete opposite, Office365 only supports OAuth with IMAP and is phasing out/has phased out Basic Auth for IMAP. Additionally more often than not organizations are actually running Microsoft Exchange under the hood -- the majority of MS Exchange servers have Basic Auth disabled for IMAP (I believe since 2017 it's been off by default).

Re: Give to Thunderbird

#110
post #83

Earlier quoted context omitted.

There’s a big difference between password reset rules, and giving third-parties access to emails and calendar. There is nothing draconian about restricting IMAP - any app could exfiltrate confidential emails once granted access. It’s a very sane rule to disallow everything except webmail or first party apps.

It's a terrible process for the users. And as we can see what did it get them, a third party logging into there webmail. The service is protected with a username and password, didn't matter if it was IMAP or webmail.

Of course it does matter! Webmail is quite restricted and optimized for viewing and replying to emails. IMAP is great for that, while also facilitating exporting (exfiltrating) the entire mailbox.
Post reply on HN