Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Of course, you only want to do that for medium-security stuff - if banks mailed out unrestricted auto-login URLs, sniffing unencrypted POP/IMAP traffic at a coffee shop would be rather profitable...


Two points:

1. If you're not reading mail over SSL you've got bigger problems than this; and

2. The problem is also password reuse. No one can remember a totally separate password for the 9827342 sites they've registered on. There are patterns and reuse (or a password manager, which is a little more clumsy but much safer although it then introduces other security issues). So when a password list of hacked as in this case or with Gawker, you almost certainly have compromised users' credentials on completely unrelated sites.


Even if you read email over SSL, it's likely not transported that way.


Sniffing traffic on the internet backbone is orders of magnitude more difficult than sniffing traffic on an open access point. Even if you could do it, making it practical is a terrific challenge of scale.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: