Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×
Bug Cellphones Communications Encryption Portables (Apple) Security Hardware

Tapping the IPhone, Courtesy of Yahoo! 27

tdalek writes "You may remember the recent Slashdot article about Yahoo! Zimbra Desktop exposing authentication information. It turns out that more Yahoo! applications are affected, although to a lesser degree. With Yahoo!'s desktop program, it transmitted the usernames and passwords in plaintext. Yahoo! is one of the lucky few default e-mail providers on the iPhone; sadly it looks like Apple didn't insist on encryption from Yahoo! On the iPhone, authentication is encrypted, but you can see all the messages sent and received in plaintext. Incoming messages are downloaded in plaintext over the standard imap port. Outgoing mail is a bit harder to find, it is apparently sent by an HTTP post request wrapped up inside a bundle of XML, but security through obscurity isn't very effective. If you have Yahoo! mail on your iPhone (and since its one of the default accounts, I'm assuming quite a few do), now would be a good time to forward it elsewhere for the time being."
This discussion has been archived. No new comments can be posted.

Tapping the IPhone, Courtesy of Yahoo!

Comments Filter:

The use of money is all the advantage there is to having money. -- B. Franklin

Working...