Earlier quoted context omitted.
in fact, seeing how your account was created to post that comment and seeing how it doesn't make sense, i would suspect that you actually work for them.
Everything he said makes perfect sense and I agree with it. A brief look at my HN profile should tell you I don't work for them. (Never heard of them before in fact.) I think that you are practicing cargo cult security -- you're doing a cargo dance here over password storage mechanisms in a case where it doesn't apply.
Dropmyemail's security
11–20 of 34 posts
Re: Dropmyemail's security
#12Earlier quoted context omitted.
they can't, unless the email service gives them oauth. and even then allowing a 3rd party to backup your emails is a very dangerous thing to do. they say that credit card is more dangerous, i say no. for credit cards you can claim fraud. when your email gets hacked, potentially your whole digital life is gone
what they could have done is to allow users to autoforward their emails over to their servers or something. not impossible, but i'm not their employee and i'm not responsible for thinking up business strategies for them. so yea. not necessary
Part of the service they're offering is that they'll restore the contents of your mailbox in case of accidental or malicious deletion. I have
mail:/var/mail/associatedtechs.com/rob@associatedtechs.com# find . | wc -l
24846
...almost 25,000 messages in my mailbox. How do you recommend that they restore 25,000 messages to my mailbox without my account credentials?Re: Dropmyemail's security
#13Earlier quoted context omitted.
Everything he said makes perfect sense and I agree with it. A brief look at my HN profile should tell you I don't work for them. (Never heard of them before in fact.) I think that you are practicing cargo cult security -- you're doing a cargo dance here over password storage mechanisms in a case where it doesn't apply.
how does it not apply?
Re: Dropmyemail's security
#14Why does this still happen? Aren't security best practices still not wide spread enough to dissuade people form doing this?
Re: Dropmyemail's security
#15Earlier quoted context omitted.
they can't, unless the email service gives them oauth. and even then allowing a 3rd party to backup your emails is a very dangerous thing to do. they say that credit card is more dangerous, i say no. for credit cards you can claim fraud. when your email gets hacked, potentially your whole digital life is gone
what they could have done is to allow users to autoforward their emails over to their servers or something. not impossible, but i'm not their employee and i'm not responsible for thinking up business strategies for them. so yea. not necessary
they should go think about how they can design a service securely before offering it.
Re: Dropmyemail's security
#16A slightly better post might have been,
"Beware unproven email backup services. Don't forget that if they make a mistake, potentially all of your email messages can be exposed to someone else. Since you probably have account credentials for other services stored in your email box, that situation can get ugly really fast."
Re: Dropmyemail's security
#17This article is nonsense. The author isn't saying anything substantive about the "security" of this particular company. It should go without saying that email backup services will currently, in most cases, need to store your email login information in a retrievable way. A slightly better post might have been, "Beware unproven email backup services. Don't forget that if they make a mistake, potentially all of your ema…
Re: Dropmyemail's security
#18This article is nonsense. The author isn't saying anything substantive about the "security" of this particular company. It should go without saying that email backup services will currently, in most cases, need to store your email login information in a retrievable way. A slightly better post might have been, "Beware unproven email backup services. Don't forget that if they make a mistake, potentially all of your ema…
so you do concede that it can get ugly really fast.
I strongly suggest that you drop this before digging yourself an even deeper hole in front of the people following this from Twitter.
Re: Dropmyemail's security
#19Earlier quoted context omitted.
what they could have done is to allow users to autoforward their emails over to their servers or something. not impossible, but i'm not their employee and i'm not responsible for thinking up business strategies for them. so yea. not necessary
and by storing the passwords, they are putting their users at risk. and we are in an era where email security means more than anything. it means access to all your services. they should go think about how they can design a service securely before offering it.
Re: Dropmyemail's security
#20Earlier quoted context omitted.
they can't, unless the email service gives them oauth. and even then allowing a 3rd party to backup your emails is a very dangerous thing to do. they say that credit card is more dangerous, i say no. for credit cards you can claim fraud. when your email gets hacked, potentially your whole digital life is gone
what they could have done is to allow users to autoforward their emails over to their servers or something. not impossible, but i'm not their employee and i'm not responsible for thinking up business strategies for them. so yea. not necessary
Now, if you can demonstrate that this particular company has a particularly unsafe way of storing the passwords or the retrieved e-mails, then you're getting closer to having a valid point.