3 ms·
That's not as secure as hibernation, because someone who can break into the running device can at least read all your new mail and if they aren't using an ad-ho
by devit 11y ago
That's not as secure as hibernation, because someone who can break into the running device can at least read all your new mail and if they aren't using an ad-hoc e-mail protocol or implemented it carelessly also read all mail and probably get the e-mail username and password too.
This also only really works for software specifically designed for this mode.
EDIT: it can actually be mostly secure if the client public key is sent before locking and then the encryption is done by the server: the attacker would only learn the number and timing of new messages and their size (assuming an ad-hoc protocol and very carefully implemented software).
It's also sort of possible to do it with generic software by simply dumping HTTPS TCP traffic to disk and decoding it once the system is unlocked (although it allows a MITM to fill up your disk unless the ciphersuite allows authentication with a key that doesn't allow decryption).