4 ms·
I'm all for nostalgia, but I can't say I recommend putting your email credentials into 20-year-old software running on a 20-year-old OS connected to the interne
by TakeBlaster16 4y ago
I'm all for nostalgia, but I can't say I recommend putting your email credentials into 20-year-old software running on a 20-year-old OS connected to the internet.
EDIT: why the downvotes? Windows XP can be infected with malware merely by plugging in a network cable with no user action. If you follow this blog post you're likely to lose your account. https://security.stackexchange.com/questions/185642/how-can-malware-immediately-infect-a-windows-xp-computer-as-soon-as-it-goes-onli https://security.stackexchange.com/questions/185642/how-can-...
- giancarlostoro 4y agoOh what's the worse that could happen! :)
- superkuh 4y agoYour private data gets accessed by a random person instead of by a megacorp.
- ranger_danger 4y agoSame thing happens whenever you use any of those alternative "frontends" for sites like reddit, youtube, twitter etc.
- giancarlostoro 4y agoTwas sarcasm
- jcranmer 4y agoIf memory serves correctly, in the Thunderbird 1.0 era, all of the passwords would have been saved via encryption via NSS's secret decoder ring methods. So if you set up a master password, then the contents would be encrypted on-disk. (Even if you didn't, they're still not stored in plaintext--I just think it's encrypted with something like an empty password instead, but I'm not certain.) Additionally, I'm pretty sure even 20 years ago, Thunderbird would have still thrown up resistance at trying to connect to an email server without using STARTTLS or SSL.
- yjftsjthsd-h 4y agoI wouldn't worry too much about encryption at rest, if nothing else then because it's only being stored on a local device that you control. What I would worry about is that those credentials are then going to be sent to a server and a system of that age probably doesn't speak any modern version of TLS.
- TakeBlaster16 4y agoI wouldn't be worried about encryption. I'd be worried about any of the hundreds of widely-known vulnerabilities that were patched between 2002 and today. https://www.cvedetails.com/product/3678/Mozilla-Thunderbird.html?vendor_id=452 https://www.cvedetails.com/product/3678/Mozilla-Thunderbird.... https://www.cvedetails.com/product/739/Microsoft-Windows-Xp.html?vendor_id=26 https://www.cvedetails.com/product/739/Microsoft-Windows-Xp....
- badsectoracula 4y agoYes but there is a difference between possibility and probability: it is technically possible to hit these vulnerabilities, but the chances are practically zero, especially in the context here where someone might try it once like mentioned in the article. It isn't like there are many malware authors out there trying to infect people running 20 year old software (outside of targeted attacks). I think you are more likely to be affected by a vulnerability bug in some random modern macOS application with its own autoupdater than a vulnerability in a 20 year old Windows program. Remember that these issues existed when that software was actually mainstream and yet the overwhelming majority of people wasn't affected by them during the peak of their popularity.
- TakeBlaster16 4y agoThe difference is back then, the vulnerabilities weren't even discovered yet. Today, metasploit scanners are running 24/7 scanning the entire IPv4 address space for thousands of vulnerabilities at a time - including automated chaining of exploits through e.g. routers with misconfigured UPnP. You don't need to be targeted. As mentioned above, you can be exploited with no user action merely by plugging in an ethernet cable. But then again, I'm not your mom. If you really want to do this I can't stop you. Go ahead.
- Aeolun 4y agoAs opposed to say, logging into Google?
- mixmastamyk 4y agoTarget audience is likely running it in a VM and behind a NAT, if they even have a copy of XP. SP3 wasn't as bad as folks remember, look into "slipstream" for the install. Also, there are not swarms of infected XP machines around to attack as there were back in the day. Likely no active attacks for TB 1.0 as well. Worst case something might sniff an email password from an old version of SSL. Don't log in to important accounts I'd say.
- boomboomsubban 4y ago>why the downvotes? The blog post wasn't recommending putting your credentials into ancient software. It said if you're feeling adventurous you could fiddle around with it yourself by downloading it from the archives.
- TakeBlaster16 4y agoPerhaps, but I can't imagine how you would fiddle around with an email client without adding an account, unless you just wanted to look at an empty list.
- boomboomsubban 4y agoThe few interested are already willing to go through the trouble of setting up a VM with an ancient OS. Presumably they could find some old database or virtualize a mail server for it or some other workaround I'm not imagining. I doubt anyone is going to read that and say "what a good idea, let's install Windows 98 on my hardware and muck about."
- floren 4y agoIf you're a ProtonMail user, you could run the Proton Bridge on a Linux system in your network, then use PuTTY on Win XP to forward the ports from there to Windows. Then Thunderbird is only sending bridge-specific passwords unencrypted to localhost, and it's all modern encryption from there on out.