Yahoo's Zimbra e-mail program exposes passwords

by RayBanBro66 | September 29, 2008 at 04:45 pm
194 views | 0 Recommendations | 3 comments

Photos

Yahoo's Zimbra e-mail program exposes passwords

Yahoo's Zimbra e-mail program exposes passwords

see larger image

uploaded by RayBanBro66

Yahoo's Zimbra e-mail program exposes passwords

Passwords used to access Yahoo mail through the Zimbra client are sent over the Internet in clear text, a Canadian programmer says.

Holden Karau stumbled upon this problem while participating in the Yahoo University Hack Day at the University of Waterloo last week.

"The Yahoo imap server's used by the Yahoo Desktop don't support SSL and the password was being transmitted in plain text," Karau wrote in a blog post on Friday.

"What does this mean for you? If you use Zimbra to access your Yahoo mail, you almost certainly need to change your password and stop using Zimbra immediately (especially if you've ever done so over wireless)," he writes.

He notified Yahoo about the problem during his presentation, but no one seemed concerned, he wrote in a post on Zimbra Forums.

A Zimbra representative wrote in a different post in that forum thread: "This problem has already been addressed in code, and fix is in the next release."

A Yahoo spokeswoman said she would check into the matter.

recommend This comment thread is now closed
0
Terri Potratz

Yikes!  What's up with email security these days?

0
RayBanBro66

I still don't trust wireless internet for "secure" transactions. This story seems to justify my fears about it.

0
kenyaoa

If SSL (https) is used then no one can see the data being transmitted.  The fault is Yahoo's and while passwords are no longer sent in clear text through their web interface, all the emails are.  So reading Yahoo mail at a wireless hotspot is not a good idea.

This story was created over 3 months ago, the comment thread is now closed.

closeSign in to NowPublic

is reporting from