Live data from Hacker News

Dropmyemail's security

blog.geeksphere.net

11–20 of 34 posts

Re: Dropmyemail's security

#11

Earlier quoted context omitted.

in fact, seeing how your account was created to post that comment and seeing how it doesn't make sense, i would suspect that you actually work for them.

Everything he said makes perfect sense and I agree with it. A brief look at my HN profile should tell you I don't work for them. (Never heard of them before in fact.) I think that you are practicing cargo cult security -- you're doing a cargo dance here over password storage mechanisms in a case where it doesn't apply.

how does it not apply?

Re: Dropmyemail's security

#12

Earlier quoted context omitted.

they can't, unless the email service gives them oauth. and even then allowing a 3rd party to backup your emails is a very dangerous thing to do. they say that credit card is more dangerous, i say no. for credit cards you can claim fraud. when your email gets hacked, potentially your whole digital life is gone

what they could have done is to allow users to autoforward their emails over to their servers or something. not impossible, but i'm not their employee and i'm not responsible for thinking up business strategies for them. so yea. not necessary

So what you're saying is that they should limit their market to those users that can successfully set up email forwarding, solely because storing passwords is bad.

Part of the service they're offering is that they'll restore the contents of your mailbox in case of accidental or malicious deletion. I have

    mail:/var/mail/associatedtechs.com/rob@associatedtechs.com# find . | wc -l
    24846
...almost 25,000 messages in my mailbox. How do you recommend that they restore 25,000 messages to my mailbox without my account credentials?

Re: Dropmyemail's security

#13

Earlier quoted context omitted.

Everything he said makes perfect sense and I agree with it. A brief look at my HN profile should tell you I don't work for them. (Never heard of them before in fact.) I think that you are practicing cargo cult security -- you're doing a cargo dance here over password storage mechanisms in a case where it doesn't apply.

how does it not apply?

http://news.ycombinator.com/item?id=4580204

Re: Dropmyemail's security

#14

Why does this still happen? Aren't security best practices still not wide spread enough to dissuade people form doing this?

because there's no way their service could ever work without storing passwords, a fact that this article completely ignores.

Re: Dropmyemail's security

#15

Earlier quoted context omitted.

they can't, unless the email service gives them oauth. and even then allowing a 3rd party to backup your emails is a very dangerous thing to do. they say that credit card is more dangerous, i say no. for credit cards you can claim fraud. when your email gets hacked, potentially your whole digital life is gone

what they could have done is to allow users to autoforward their emails over to their servers or something. not impossible, but i'm not their employee and i'm not responsible for thinking up business strategies for them. so yea. not necessary

and by storing the passwords, they are putting their users at risk. and we are in an era where email security means more than anything. it means access to all your services.

they should go think about how they can design a service securely before offering it.

Re: Dropmyemail's security

#16
This article is nonsense. The author isn't saying anything substantive about the "security" of this particular company. It should go without saying that email backup services will currently, in most cases, need to store your email login information in a retrievable way.

A slightly better post might have been,

"Beware unproven email backup services. Don't forget that if they make a mistake, potentially all of your email messages can be exposed to someone else. Since you probably have account credentials for other services stored in your email box, that situation can get ugly really fast."

Re: Dropmyemail's security

#17

This article is nonsense. The author isn't saying anything substantive about the "security" of this particular company. It should go without saying that email backup services will currently, in most cases, need to store your email login information in a retrievable way. A slightly better post might have been, "Beware unproven email backup services. Don't forget that if they make a mistake, potentially all of your ema…

so you do concede that it can get ugly really fast.

Re: Dropmyemail's security

#18

This article is nonsense. The author isn't saying anything substantive about the "security" of this particular company. It should go without saying that email backup services will currently, in most cases, need to store your email login information in a retrievable way. A slightly better post might have been, "Beware unproven email backup services. Don't forget that if they make a mistake, potentially all of your ema…

so you do concede that it can get ugly really fast.

I "concede" that they are doing nothing wrong and you are way out of your depth here.

I strongly suggest that you drop this before digging yourself an even deeper hole in front of the people following this from Twitter.

Re: Dropmyemail's security

#19

Earlier quoted context omitted.

what they could have done is to allow users to autoforward their emails over to their servers or something. not impossible, but i'm not their employee and i'm not responsible for thinking up business strategies for them. so yea. not necessary

and by storing the passwords, they are putting their users at risk. and we are in an era where email security means more than anything. it means access to all your services. they should go think about how they can design a service securely before offering it.

your argument is similar to: "it is impossible to design a bank that can be kept 100% secure from bank robbers, therefore we shouldn't use banks"

Re: Dropmyemail's security

#20

Earlier quoted context omitted.

they can't, unless the email service gives them oauth. and even then allowing a 3rd party to backup your emails is a very dangerous thing to do. they say that credit card is more dangerous, i say no. for credit cards you can claim fraud. when your email gets hacked, potentially your whole digital life is gone

what they could have done is to allow users to autoforward their emails over to their servers or something. not impossible, but i'm not their employee and i'm not responsible for thinking up business strategies for them. so yea. not necessary

You can only archive incoming e-mails via autoforward, not drafts and not outgoing email (unless you use their mailservers, which is something completely different). If I want archiving for my e-mails, I have to give up my account credentials. You could actually do sufficient mischief with the archived e-mails, you don't need the account credentials in the first place. That sucks, but it's not their fault, this kind of service is inherently insecure.

Now, if you can demonstrate that this particular company has a particularly unsafe way of storing the passwords or the retrieved e-mails, then you're getting closer to having a valid point.

Post reply on HN