You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It is very convenient to host yggmail on some VM, and be able to connect to it from any other device in Yggdrasil.
But yggmail is defenseless against brute-force attacks. Anyone can run some script and try to login to SMTP or IMAP part of the node. Moreover, if you connect to the node, it shows a valid login in the banner.
It would be very good to implement some rate-control to login mechanisms with some temporary ban measures.
And get rid of that public key in the banner :)
The text was updated successfully, but these errors were encountered:
It is very convenient to host
yggmail
on some VM, and be able to connect to it from any other device in Yggdrasil.But
yggmail
is defenseless against brute-force attacks. Anyone can run some script and try to login toSMTP
orIMAP
part of the node. Moreover, if you connect to the node, it shows a valid login in the banner.It would be very good to implement some rate-control to login mechanisms with some temporary ban measures.
And get rid of that public key in the banner :)
The text was updated successfully, but these errors were encountered: