Version: 2008
  • On The Insider: Britney's Bikini-Clad Top 10

Comments on: Yahoo's Zimbra e-mail program exposes passwords

Enterprising Canadian programmer exposes privacy issue for people using Zimbra to access Yahoo Mail during Yahoo university hack event.

Add a Comment (Log in or register) (5 Comments)
  • prev
  • 1
  • next
by Solaris_User September 29, 2008 4:50 PM PDT
..but Zimbra uses SSL by default.. doesn't it?
Reply to this comment
by crazyirishhobo September 29, 2008 5:06 PM PDT
Zimbra uses SSL by default for other providers (like Gmail), but for some unknown reason doesn't with Yahoo! Neither Yahoo! nor Zimbra have been clear on why Yahoo! Desktop doesn't use SSL with Yahoo! mail (but oddly enough will with say Gmail :P)
Reply to this comment
by Solaris_User September 29, 2008 5:14 PM PDT
That's pretty bad then, does yahoo use ssl at all?

I'm of the opinion that all e-mail should be encrypted always.
Reply to this comment
by crazyirishhobo September 30, 2008 4:09 AM PDT
p.s. you might want to update http://www.zimbra.com/forums/109994-post2.html to http://www.zimbra.com/forums/general-questions/22736-zimbra-desktop-sends-yahoo-password-clear-not-secure.html
Reply to this comment
by michaelawsutton September 30, 2008 5:14 AM PDT
http://research.zscaler.com/2008/09/trusting-cloud.html [zscaler.com] When leveraging cloud based apps, in this case webmail, security is vital not only in the cloud but during transmission to the cloud. While this is often the responsibility of the enterprise itself, here is a situation where Yahoo! was responsible for all components (client and server) and still didn't get it right. Cloud computing will not succeed unless enterprises are able to trust those making online services available to them. Situations such as this, where security was clearly an afterthought, do not help to build the trust required for cloud computing to succeed.
Reply to this comment
(5 Comments)
  • prev
  • 1
  • next
advertisement

The yogurt makers of tech: Gadgets to avoid

Don't buy these one-trick ponies--unless you like gizmos that gather dust.

Google wants to unclog Net's DNS plumbing

The Net giant, ever eager for a faster Internet, debuts its Google Public DNS service. With it, Google could become even more central to the Net.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement