7 ms·
Mailbox.org discovers unencrypted password transmission in myMail
- autoexec 3y agoI'd never heard of myMail. Turns out it's a mobile only MUA made by a Russian company (https://en.wikipedia.org/wiki/Mail.Ru https://en.wikipedia.org/wiki/Mail.Ru) and they were seen collecting people's usernames and passwords and using those logins to read people's messages from their own servers almost a decade ago (https://old.reddit.com/r/Android/comments/20u712/beware_mymail_a_popular_mail_app_stores_your/ https://old.reddit.com/r/Android/comments/20u712/beware_myma...)
- joecool1029 3y ago>they were seen collecting people's usernames and passwords and using those logins to read people's messages from their own servers almost a decade ago To be fair microsoft's outlook ios and android clients does the same thing with external providers (like if you used it with fastmail). It is a common practice and something to be aware of when choosing an email app. EDIT: I'm specifically answering this comment. As for the submission, that was incredibly stupid for them to do in 2023. At this point it should only be opt-in to turn encryption off, not a default.
- oefrha 3y agoCollecting credentials and reading mail from server is standard practice across hosts of email clients, since it’s the only way to get push notification working. If you don’t trust their server you probably shouldn’t use their client anyway.
- housemusicfan 3y agoBlackBerry was doing this 20 years ago. That's how their push email service (BIS) worked. And yes I still lament the loss of the blinking red LED, a victim of phone makers today treating devices as if they were a piece of jewelry as opposed to the utilitarian tools they really are.
- autoexec 3y agoApps can't just send notifications? If I had a mail client installed, couldn't the app just periodically connect to my mail server using my internet connection, see new mail was available, and then pop up a notification so I'd know? That seems much more secure than having a third party collecting my passwords so they can connect to my mail server from their network using my password just to see if any new mail is there, read the messages, then send a notification to my phone to let me know about them. I'm perfectly happy to trust Thunderbird enough to configure it to check my mailbox, but I wouldn't feel as comfortable handing my login information directly to Mozilla so that they can log into my mailbox whenever they feel like it. I guess Mozilla could push an update that collects my stored login credentials and do that anyway, but if they did I think there would be a lot of folks who'd protest.
- oefrha 3y ago> If I had a mail client installed, couldn't the app just periodically connect to my mail server, see new mail was available, and then pop up a notification so I'd know? Desktop mail clients do. Phone mail clients can’t, so you either check on a server, or don’t get notifications on time.
- autoexec 3y agoMobile platforms seem a bit broken. Timer/alarm apps seem to be able to take actions and notify on a regular schedule, it is specifically scheduled network activity that's restricted?
- Dalton9 3y agoyes mobile OSes will delay and group background activity especially if it involves network access. But we're talking minutes, not hours of delay... Some phones are very aggressive and the app will need to show a persistent notification to keep background polling working, though. I've never used a mobile client that used a third party to monitor a mailbox, they all do polling as you suggest. I'm not sure the man in the middle approach it's as common as OP is implying here (for non-first party clients).
- leni536 3y agoWhy would this be the only way? I have IMAP push reliably working with k9mail on Android.
- hulitu 3y ago> Collecting credentials and reading mail from server is standard practice across hosts of email clients, In some countries this is "unauthorised access to computing systems". But Google and co. are above the law anyway.
- retox 3y agoI had an alert about 9 months ago that someone might have accessed my hotmail, I went to check the previous logins and did see some from places in SE Asia but from months ago. Mixed in were many logins from an IP address owned by the Microsoft campus at times when I would have been asleep. The account is a backup, and I don't have that mailbox attached to any apps. I emailed their security team asking what was going on but never got a response. After changing the password all the access was stopped. Though I should go back and re-check.
- hannob 3y agoInterestingly, this is another security issue with STARTTLS. The whole concept of first establishing an unencrypted connection and only then upgrading to encryption is fragile in multiple ways. Admittedly, this is a pet peeve of mine, as I've co-authored a paper about it. I wonder why mailbox.org does not recommend that users switch from STARTTLS to implicit TLS for SMTP/POP3/IMAP, as this would mitigate such issues more generally. This is also in line with current RFCs (RFC 8314). https://nostarttls.secvuln.info/ https://nostarttls.secvuln.info/
- hannob 3y agoAnd as one of my co-authors just pointed out to me, we also found a few security issues in mymail, yet they closed them as "not applicable"...
- Avamander 3y agoIt's not just explicit vs. implicit TLS that's an issue with MUAs. Assuming good implicit TLS configuration there's still no proper way to harden such connections against an active MITM - we don't have an usable MUA-STS standard.
- Tyr42 3y agoWas that the buffered input during starttls connection? Man thanks for that. I had to go and update my code due to that paper. And the mess I had unavoidably made around the sockets and starttls just made that worse. And there was no real way to unit test it.
- hardwaresofton 3y agoThank you for writing this, I use it as a reference when explaining the difference STARTTLS and implicit TLS and why people should choose one over the other. Another nice one is that implicit TLS is SNI routable (and thus much easier to route) -- this is the main reason for me, and I wish the standard had been updated to encourage more people to try 465 (or have a way to specify port in DNS records for example). Huge missed opportunity.
- justsomehnguy 3y ago