Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm surprised that the other email providers have allowed the switch to be technically possible. Oversight by them, or intentional?


How could you possibly prevent this? If the user can access the emails at provider X, so can a webapp that has the username and the password.


Preventing it entirely would be difficult, but given a list of IPs belonging to Google and TrueSwitch, it would not be very hard to put some serious brakes on the feature. Even reverse DNS could mostly work.


Not necessarily. If they did do something like that it would be a pain to TrueSwitch but hardly the end of the line. All they'd have to do is embed a hidden a hidden iframe and parse with javascript. Then the webmail provider would have to implement iframe busting, then TrueSwitch would switch to an ajax request that parses the source and it would essentially turn into a massive arms race that I don't see the webmail provider winning.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: