[tor-bugs] #10836 [TorBirdy]: Enable mail account autoconfig dialog in TorBirdy

Tor Bug Tracker & Wiki blackhole at torproject.org
Wed Feb 12 15:12:17 UTC 2014


#10836: Enable mail account autoconfig dialog in TorBirdy
-----------------------------+-----------------
     Reporter:  ben          |      Owner:  ben
         Type:  enhancement  |     Status:  new
     Priority:  normal       |  Milestone:
    Component:  TorBirdy     |    Version:
   Resolution:               |   Keywords:
Actual Points:               |  Parent ID:
       Points:               |
-----------------------------+-----------------

Comment (by ben):

 Please remember that
 1) The user manually reviews and approves the config
 2) We warn about insecure configs.

 So, in order to successfully attack, you not only have to attach the
 autoconfig algos, but *also* make your user a phishing victim, e.g. either
 by him turning a blind eye on hostname 123.234.265.123 or registering a
 real domain like googleemailservices.com . We put that user verification
 in there quite deliberately as an additional security measure.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10836#comment:11>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list