Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's a terrible process for the users. And as we can see what did it get them, a third party logging into there webmail.

The service is protected with a username and password, didn't matter if it was IMAP or webmail.



An employee who redirects company emails to get around a security rule becomes an ex-employee very quickly.


Of course it does matter! Webmail is quite restricted and optimized for viewing and replying to emails. IMAP is great for that, while also facilitating exporting (exfiltrating) the entire mailbox.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: