Doteasy Peer to Peer Support Forums

General Category => Doteasy Email Services => Topic started by: renowden on November 03, 2010, 03:37:08 PM

Title: SSL (https) secured web mail
Post by: renowden on November 03, 2010, 03:37:08 PM
I am sure that many people have heard of FireSheep by now - see this article http://www.schneier.com/blog/archives/2010/10/firesheep.html and discussion if you want to know more. In summary it says that if you are using an open unencrypted network (like StarBucks) then your secure sessions can be hijacked EVEN IF YOU USE SSL (HTTPS) FOR THE LOGIN. A cookie is written to the browser to say that authentication was successful and this can be trapped and used by other people.

Having taken advice from there and other places I have tried forcing all my logged in communication to use SSL (https). This works well for Google, Paypal, Twitter, and reasonably well for Facebook.

It fails miserably for DotEasy WebMail. Most of the DotEasy general pages are ok and the login is ok but as soon as it goes to the mail inbox, everything hangs.

What can we do to make this work please.
Title: Re: SSL (https) secured web mail
Post by: Doteasy on November 16, 2010, 01:28:07 AM
If you are using cpanel webmail service, your webmail is protected by the SSL connection. Please contact our support team so that we can check your account and give you more information. Thank you.