Encrption of Verizon E mail
topdog
Specialist - Level 2

Is Verizon E mail encrypted as it should be?  I hope that some knowledgeable person would check that out.  Go to the url provided and read the debate!!

 http://www.dslreports.com/forum/r24816137-Is-Verizon-email-UNencrypted-~start=80

Re: Encrption of Verizon E mail
lasagna
Community Leader
Community Leader

No.

Verizon's web portal for email passes the signon credentials in an SSL encrypted form, but anyone using a PC based client (Outlook, Outlook Express, Thunderbird, etc.) to retrieve/send their mail does so over POP/SMTP and passes their credentials in the clear.

If you only ever do this from a home computer on the Verizon network, you are reasonably safe.  However, if you do so from a coffee shop or other public wifi, your credentials are subject to stolen by someone who is looking for them.

Re: Encrption of Verizon E mail
Holly1
Contributor - Level 3

Can you explain why?  Did you go to the url provided by topdog and read the page?  I am using Verizon webmail. Would I be better off changing my webmail provider to one that uses encryption ( that has a lock at the top of the sign in Page) for example Google, Yahoo, Hotmail, etc?.

Re: Encrption of Verizon E mail
lasagna
Community Leader
Community Leader

Actually, yes, I did read the page, but some of the advice given there is no entirely accurate.

The Verizon Webmail page itself is not secure, but the signin process is.   The form which underlies the signin process submits via an SSL encrypted post.   Now, the discussion on the posted link talks about why that supposedly insecure, but what they fail to disclose is that to exploit this exposure, you need to be able to modify the content on Verizon's server to insert a redirection for the post -- and well, if you're going that far, there are far easier ways of stealing passwords.

The important thing here however is that the session itself is NOT SSL encrypted.   So, once you're logged in, anything you look at in your email is not encrypted in transit meaning that someone who is eavesdropping on the public wifi connection could see anything you view -- which if that happened to be an email with, say, a password recovery in it, would mean they would see that information.   

For client based email, the entire session including the exchange of credentials is not encrypted.   If you use any unsecured path to transmit them, then they are subject to disclosure.

When I say you are reasonably safe if you only view this stuff from home, I am relying on the fact that your home wireless connection has been secured, that there is no common broadcast network which others can eavesdrop on between you and the Verizon switch fabric, and that Verizon's network itself has a level of integrity about it.  

Is it great, no.  I don't rely on Verizon's email to send/receive anything which is attached to a credential.    Using a different service to "retrieve" your mail doesn't make it secure either -- however it moves the exchange of credentials from occurring between your laptop and the server (over a suspect network) to occurring between two corporate networks (say Google and Verizon) whose network path is likely much more secure.  

Given that the single-signon credential that a person uses to access the verizon.net site, their email, forums, etc. is all the same, Verizon really should invest in supporting SSL secured signon for POP/SMTP.    The problem is, even if you support these capabilities, many people still use outdated software which is incapable of supporting this and will still potential divulge their credentials.

The recent rash of "password" breakins folks have been complaining about on Yahoo or other accounts has actually less to do with this particular exposure and more to do with using the SAME password for multiple sites.  If someone say, hacks your facebook account (easy to do with people routinely liking various applications and such which may be a password stealing application) and you use the same password, it's pretty each to figure out what to do to get into other sites.

Re: Encrption of Verizon E mail
dslr595148
Community Leader
Community Leader

@lasagna wrote:

You need to be able to modify the content on Verizon's server to insert a redirection for the post.


Oh, please..

How can you say that?

See the post in that thread by jdong ( DSLR user # 655964 ) on 2010-10-25 12:03:09

Direct Link.

http://www.dslreports.com/forum/r24978909-Is-Verizon-email-UNencrypted-

-

Firesheep a Firefox add-on, anyone?

Re: Encrption of Verizon E mail
Hubrisnxs
Legend

https://www.verizon.net/ssowebapp/protected/EmailLoginHelper

Wouldn't that be the link if someone wanted to use secure sign in?

0 Likes
Verizon E mail NOT encrypted between you and Verizon server
glnzglnz
Contributor - Level 3

I think this topic should be kept alive.  Please respond here or in my new post above at

(Verizon email NOT encrypted)

0 Likes