zlacker

[parent] [thread] 0 comments
1. mike-c+(OP)[view] [source] 2012-09-04 10:04:53
Websites aren't sufficiently sandboxed from each other though. Otherwise we wouldn't have CSRF, XSS and Click Jacking attacks.

If you build a webmail client, you need to know all about these attack vectors, and you need to go out of your way to prevent your application from being susceptible to them. Websites are insecure by default.

I don't trust a web browser with my email at all. Not yet. If I were to use webmail, I'd make sure to set up a separate instance of Firefox to run it in, with it's own profile. I will continue to use Thunderbird for now though.

I'm not against the idea of using webmail, I just don't think the web is secure enough yet.

[go to top]