> Although I'm satisfied that our new IMail server is secure, I
> have one user who sent me the following message when he found
> out what we were using...
>
>  " ... I would like to have security. POP3
>  exposes my password and my mail contents. "

That's because POP3, by default, will send passwords using plain text.  And, the 
E-mails are sent via plain text.  So, when a dumb web site that uses 128-bit SSL 
encryption E-mails a user their password on a "Lost your password?" link, it's easily 
intercepted if a hacker has access to the TCP/IP connection.

I believe that the only way for the mail contents to be secure would be to use SSL, 
using an SSL tunnelling program with IMail.  Very few people do this however.

Be aware that anytime a web site pops up a username/password box, if the connection 
isn't using SSL, the username/password are also sent in plain text.  It's just the 
nature of the Internet.


--
                      -Scott

Declude: Anti-virus and Anti-spam solutions for IMail.  http://www.declude.com
--

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to