[horde] Remote Mail Account in Horde / Password

Andreas Mauser andreas at mauser.info
Fri Jun 12 22:22:02 UTC 2015


----- Nachricht von Michael J Rubinsky <mrubinsk at horde.org> ---------
      Datum: Fri, 12 Jun 2015 18:17:13 -0400
        Von: Michael J Rubinsky <mrubinsk at horde.org>
Antwort an: mrubinsk at horde.org
    Betreff: Re: [horde] Remote Mail Account in Horde / Password
         An: horde at lists.horde.org


> Quoting Andreas Mauser <andreas at mauser.info>:
>
>> ----- Nachricht von Erling Preben Hansen <erling at eph.dk> ---------
>>     Datum: Fri, 12 Jun 2015 21:36:11 +0000
>>       Von: Erling Preben Hansen <erling at eph.dk>
>> Antwort an: erling at eph.dk
>>   Betreff: Re: [horde] Remote Mail Account in Horde / Password
>>        An: horde at lists.horde.org
>>
>>
>>> Citat af Andreas Mauser <andreas at mauser.info>:
>>>
>>>> Hi,
>>>>
>>>> I want to add a GMX Account in Horde. It works, but every time I log into
>>>> Horde I also have to put in password for my GMX Account.
>>>>
>>>> How to make it so that the GMX password is remembered?
>>>>
>>>> Thank you,Andreas
>>>
>>> Hey Andreas
>>>
>>> This has been discussed before..
>>> It is not possible.
>>> And in my opinion is a serious security risk.
>>> Since you as an admin will be responsible of storing and securing passwords
>>> of third party services.
>>> When this is a sensible personal service, as a mail account is.
>>> I wouldn't recommend it.
>>
>> I would recommend it, because the user must first authenticate via  
>> Horde Authentication, in any way.
>> So if I collect 3 external mail accounts, I need to log on 4 times.
>> If the password could be stored e.g. in the database only the well  
>> trusted administrator would have access to it. But I hope they are  
>> all Snowdens...
>
>
> ...and of course if that one account is compromised, this  
> compromises ALL your accounts. Kind of defeats the recommended  
> security practice of using different passwords for each account.

Would 2-factor auth help?

Andreas
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-keys
Size: 3871 bytes
Desc: ?ffentlicher PGP-Schl?ssel
URL: <http://lists.horde.org/archives/horde/attachments/20150613/b96b736c/attachment.bin>


More information about the horde mailing list