Public bug reported:

Suppose you have ~6-12 accounts all fetched over Tor.  If they all fetch
at the same time, the accounts could easily be correlated together --
which is particularly problematic if you hold multiple accounts at the
same provider.  And even if you only have one account, having a fixed
delay between fetches is also compromizing.

The "interval" option doesn't cut it because the first fetch still hits
all servers at once and the schedule is still predictable.  I therefore
propose expanding the "interval" parameter to fetch at random times if a
range is given.  E.g. "interval 5.3-25" means fetch as early as 5.3 min
& no later than 25 min since the last fetch, randomized after each
fetch.

** Affects: fetchmail (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1924622

Title:
  add a security feature to randomize the fetch schedule

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/fetchmail/+bug/1924622/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to