OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Email Security Issue in Netscape Communicator 4.x
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Email Security Issue in Netscape Communicator 4.x


  • To: NTBUGTRAQLISTSERV.NTBUGTRAQ.COM
  • Subject: Re: Email Security Issue in Netscape Communicator 4.x
  • From: Russ <Russ.CooperRC.ON.CA>
  • Date: Tue, 2 Mar 1999 16:12:11 -0500
  • Approved-By: Russ.CooperRC.ON.CA
  • Comments: To: Alexandre Viale <alexandre.vialeESFRANCE.COM>
  • Reply-To: Russ <Russ.CooperRC.ON.CA>
  • Sender: Windows NT BugTraq Mailing List <NTBUGTRAQLISTSERV.NTBUGTRAQ.COM>

Regarding the exposure of password information from Netscape Mail
Notification to NT Administrators...

NTBugtraq repeatedly emphasizes that protecting against Administrators
is not easily done with NT. You must trust your Administrators.

However, this particular piece of information pertains to the
possibility that Administrators might easily obtain information
regarding your passwords to off-site POP3 accounts. This might not be
widely expected, or known. Think of it as a form of Key Escrow...;-]

It was passed along to NTBugtraq as informational, not to create yet
another debate about protecting against Administrators.

Netscape Mail Notification could probably have been written not to
require such permissions. Not using it will mean Administrators would
have to do "more" to get the same information (speculation not
required).

Cheers,
Russ - NTBugtraq moderator