Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm using a POP3 mailbox hosted by the registar of my custom domain and I download all the messages on my computer. No web mail. I'm trusting the DNS of my registar in the same way I would trust the one of FastMail, Zoho, etc. Is that any different?


That's kind of an "all your eggs in one basket" approach - you're relying completely on the security of one 3rd party (your registrar). Whether this is better or worse than relying on two 3rd parties (your registrar and a different email provider) is a good question.

Are you sure your POP3 mailbox is using encryption for the password? The original port 110 POP3 protocol sends it in cleartext unless there's an STLS command sent (which is MITM-able) - POP3S over port 995 (or 997?) will be encrypted (but then you need to consider whether all the software in the chain is actually checking SSL certs and their chains...)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: