Dropmyemail's security
blog.geeksphere.net
Dropmyemail's security
1–10 of 34 posts
Re: Dropmyemail's security
#2Re: Dropmyemail's security
#3- The app checks your email on your behalf.
- You need the actual password to log into an IMAP server (android also stores your email passwords in clear text if you aren't using gmail http://code.google.com/p/android/issues/detail?id=10809).
- They clearly state this in their response, which the article completely ignores. They try to use OAuth where possible.
- They store the passwords encrypted via S3. Personally, I'd prefer that to MySQL on a VPS somewhere.
- See also: https://developer.pidgin.im/wiki/PlainTextPasswords
Re: Dropmyemail's security
#4Wow, either the author has a serious grudge against them, or isn't willing to at least fact-check their response. - The app checks your email on your behalf. - You need the actual password to log into an IMAP server (android also stores your email passwords in clear text if you aren't using gmail http://code.google.com/p/android/issues/detail?id=10809 ). - They clearly state this in their response, which the article…
1) The app downloads your emails into their server.
2) Yes, they store that actual password. Which is ridiculous.
3) Yes, good for them for that, but still there are others where they store passwords. And that is not acceptable.
4) But that also means that they outsource the security part of things. Which doesn't lend faith to the idea that they know about security. And if someone realises how to control their application, all the passwords will be hacked.
5) Pidgin is stored locally. There's a difference. Not that I support it, but it's still better than someone storing my passwords.
Re: Dropmyemail's security
#5Wow, either the author has a serious grudge against them, or isn't willing to at least fact-check their response. - The app checks your email on your behalf. - You need the actual password to log into an IMAP server (android also stores your email passwords in clear text if you aren't using gmail http://code.google.com/p/android/issues/detail?id=10809 ). - They clearly state this in their response, which the article…
I'm the author. 1) The app downloads your emails into their server. 2) Yes, they store that actual password. Which is ridiculous. 3) Yes, good for them for that, but still there are others where they store passwords. And that is not acceptable. 4) But that also means that they outsource the security part of things. Which doesn't lend faith to the idea that they know about security. And if someone realises how to cont…
Re: Dropmyemail's security
#6Earlier quoted context omitted.
I'm the author. 1) The app downloads your emails into their server. 2) Yes, they store that actual password. Which is ridiculous. 3) Yes, good for them for that, but still there are others where they store passwords. And that is not acceptable. 4) But that also means that they outsource the security part of things. Which doesn't lend faith to the idea that they know about security. And if someone realises how to cont…
How do you recommend that they regularly backup a user's email messages without storing that user's login credentials for that email service?
and even then allowing a 3rd party to backup your emails is a very dangerous thing to do. they say that credit card is more dangerous, i say no. for credit cards you can claim fraud.
when your email gets hacked, potentially your whole digital life is gone
Re: Dropmyemail's security
#7Earlier quoted context omitted.
How do you recommend that they regularly backup a user's email messages without storing that user's login credentials for that email service?
they can't, unless the email service gives them oauth. and even then allowing a 3rd party to backup your emails is a very dangerous thing to do. they say that credit card is more dangerous, i say no. for credit cards you can claim fraud. when your email gets hacked, potentially your whole digital life is gone
Re: Dropmyemail's security
#8Wow, either the author has a serious grudge against them, or isn't willing to at least fact-check their response. - The app checks your email on your behalf. - You need the actual password to log into an IMAP server (android also stores your email passwords in clear text if you aren't using gmail http://code.google.com/p/android/issues/detail?id=10809 ). - They clearly state this in their response, which the article…
Re: Dropmyemail's security
#9Wow, either the author has a serious grudge against them, or isn't willing to at least fact-check their response. - The app checks your email on your behalf. - You need the actual password to log into an IMAP server (android also stores your email passwords in clear text if you aren't using gmail http://code.google.com/p/android/issues/detail?id=10809 ). - They clearly state this in their response, which the article…
in fact, seeing how your account was created to post that comment and seeing how it doesn't make sense, i would suspect that you actually work for them.
I think that you are practicing cargo cult security -- you're doing a cargo dance here over password storage mechanisms in a case where it doesn't apply.
Re: Dropmyemail's security
#10Earlier quoted context omitted.
How do you recommend that they regularly backup a user's email messages without storing that user's login credentials for that email service?
they can't, unless the email service gives them oauth. and even then allowing a 3rd party to backup your emails is a very dangerous thing to do. they say that credit card is more dangerous, i say no. for credit cards you can claim fraud. when your email gets hacked, potentially your whole digital life is gone
so yea. not necessary