Hacker News new | ask | show | jobs
by beprogrammed 1774 days ago
It's a terrible process for the users. And as we can see what did it get them, a third party logging into there webmail.

The service is protected with a username and password, didn't matter if it was IMAP or webmail.

2 comments

An employee who redirects company emails to get around a security rule becomes an ex-employee very quickly.
Of course it does matter! Webmail is quite restricted and optimized for viewing and replying to emails. IMAP is great for that, while also facilitating exporting (exfiltrating) the entire mailbox.