[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: [tor-bugs] #10836 [TorBirdy]: Enable mail account autoconfig dialog in TorBirdy
#10836: Enable mail account autoconfig dialog in TorBirdy
-----------------------------+-----------------
Reporter: ben | Owner: ben
Type: enhancement | Status: new
Priority: normal | Milestone:
Component: TorBirdy | Version:
Resolution: | Keywords:
Actual Points: | Parent ID:
Points: |
-----------------------------+-----------------
Comment (by ben):
Please remember that
1) The user manually reviews and approves the config
2) We warn about insecure configs.
So, in order to successfully attack, you not only have to attach the
autoconfig algos, but *also* make your user a phishing victim, e.g. either
by him turning a blind eye on hostname 123.234.265.123 or registering a
real domain like googleemailservices.com . We put that user verification
in there quite deliberately as an additional security measure.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10836#comment:11>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs