3 ms·
Not an expert, so perhaps this isn't the only way. But i could envisage a malicious DNS server (such as in a coffee shop or airport, perhaps even an AP run by
by toothbrush 10y ago
Not an expert, so perhaps this isn't the only way. But i could envisage a malicious DNS server (such as in a coffee shop or airport, perhaps even an AP run by a malicious user inside Starbucks called "Starbucks RLY SRSLY") serving up mail.gmail.com A records that point to their own server, which listens on IMAP ports and logs usernames and passwords. For this to work, the application in question (such as Mail.app) would have to do a poor job of certificate trust verification. I am not familiar with how that works on OS X, but i'm assuming that it'd be somewhat hard (although not impossible) to obtain an SSL certificate for mail.gmail.com that a usual OS X installation would accept. Personally i tend to prefer the TOFU (trust on first use) way of doing things, after having connected on a (relatively) trusted internet connection, e.g., at home. If someone is more knowledgeable feel free to weigh in.