If the passwords used are for POP3 only then I would say the risk is only as
high as the value of the privacy of the messages.  If the messages are
routine then who cares, but if they contain sensitive info than you should
decide how sensitive they are and therefore how valuable they are.  Robert
suggested some alternative clients to use that support encrypted password
transmission, but I think that would be tough to enforce (unless IMAIL can
enforce that, my next mail to Robert will ask that question so watch the
list).  I say either decide that being open is OK to get the functionality
you want, or require VPN endpoints to use the mail servers IP address when
accessed from the Internet.  This can easily be done with most modern
routers or can be accomplished by enabling PPTP filtering in the IP stack of
your IMAIL server (second option only works with all 32 bit MS clients).
Anything in between open and fully secure is not consistently enforceable
and should therefore be made a business decision rather than technical
decision.
Hope that helps,
-V
----- Original Message -----
From: "imfo" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Friday, November 05, 1999 10:02 AM
Subject: Re: [IMail Forum] Security Question


> Thanks Vaughan,
>
> Without labouring the point ...
> I can understand the folly of http:8181 web administration from the net
> unprotected.
> Focusing on POP3 - (assume passwords are mailbox only).
> Is there any exposure beyond individual mailboxes?
> Or should I be thinking along the lines of  'there may be some 'furtive
> lurker'
> parked outside our firewall 'sniffing' all packets and digesting ALL our
> (pop3) passwords?'
>
> Ronan
>
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

Reply via email to