> However,  the  big  catch  here  is that in most cases doing this is
> silly  and pointless, except for the warm fuzzies that come with it.
> Typically  "The  Boss" loves hearing that he has a secure connection
> to  the  mailserver,  because he has no clue (and doesn't care) that
> the  E-mail  is not secure before it gets to the mailserver or while
> it is on the mailserver.

Y'know,  previously I felt this way, too. But for hosted environments,
whether  it's  very  stupid or semi-stupid depends on the state of the
client's  IT  infrastructure.  For  example, the clients' partners may
send  from  an  switched  LAN  to  your  hosting farm, so kiddie-level
sniffing  is  impossible so far and true compromise (or an inside job)
would  be  necessary.  If  the mail is then downloaded over individual
dialup,  it keeps that same level of vulnerability. BUT if the mail is
downloaded  into,  say, a 10Base-T network still running off unmanaged
hubs, wire sniffing is much, much easier and undetectable.

Of  course,  the  better  solution  there, if you're "the boss," is to
bring  your infrastructure up to a level where someone actually has to
make  a  concerted  effort  to  get the data, rather than just running
NetMon.

-Sandy


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to