Security Basics mailing list archives

Re: POP3 passwords


From: "Simon Gray" <simong () desktop-guardian com>
Date: Mon, 20 Oct 2003 16:31:10 +0100

Why has it not been a bigger problem that POP3 passwords are unencrypted
when sent over the public Internet? Seems like they would be pretty easy
for
a miscreant to steal.

Same could be said about FTP, many users are happy with it. Even though they
don't realise that its *completely* insecure.

An isp I've used in the past, insists that for shell access you must use ssh
instead of telnet, because its 'secure' although they are quite happy for
you to access the same box (using the same credentials) over ftp.

A little knowledge can be dangerous, passwords unencrypted is better than no
password  yet (insert large number here) number of times worse than without
a proper form of encryption.

*shrugs*

Simon


---------------------------------------------------------------------------
FREE Whitepaper: Better Management for Network Security

Looking for a better way to manage your IP security?
Learn how Solsoft can help you:
- Ensure robust IP security through policy-based management
- Make firewall, VPN, and NAT rules interoperable across heterogeneous
networks
- Quickly respond to network events from a central console

Download our FREE whitepaper at:
http://www.securityfocus.com/sponsor/Solsoft_security-basics_031015
----------------------------------------------------------------------------


Current thread: