D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Email and SSL

 

On 26/10/18 13:01, Neil wrote:
> I have just added a new email account for myself. (This is one way to
> keep things separate instead of too many filters.) Anyway, when I had a
> look at the manual settings I noticed that it was recommended to use the
> secure settings. I use IMAP and the only difference I could see was the
> port numbers for the incoming servers. On most of my email accounts I
> have port 143 set up for incoming emails. Just one account uses port 993.
> I have never noticed this before.
>
> Can anyone comment on this please? If is is better to use port 993
> because it is more secure, and I change that setting, will it cause me
> any problems? The outgoing server is set to port 587, whereas the
> recommendation is to use 465. I am using the Thunderbird client and there
> is only one outgoing server for all accounts. At least, if there is a way
> to have different outgoing servers for each account I have not found it.
>
> Or should I just not mess with it?
>
> Neil
>
The main problem from my PoV is that in the bare protocols, your
authentication password (yes, your email account password) is sent across
the internet in Plain Text, so a MitM attack could pick that up, and all
bets are off.

Email contents encryption is a process better handled by the likes of GnuPG
which is specifically set up for signing/encrypting data. The fact your
email is coming over a plain-text connection and you might not want it seen
by any Tom Dick or Harry is very secondary to having your account password
stolen in my opinion.

MJE

Attachment: signature.asc
Description: OpenPGP digital signature

-- 
The Mailing List for the Devon & Cornwall LUG
https://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq