[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#769659: dolphin does not use TLS. No password protection by connecting imap service



Package: dolphin
Version: 4:4.14.2-1
Severity: wishlist

Dear Maintainer,

I use icedove for connection my email provider via TLS IMAP connection.

If I copy and paste a mail to dolphin window dolphin opens an window asking for
a password for the mail user I use in dolphin.

I checked now with tcpdump -i eth0 -A port imap2 the network traffic and was
surprised, that I can read my password in clear-text form so any user who watch
the connection can steal my login credentials.

There is no warning in icedove that the password will send in clear-text nor a
setting how I can disable this simple imap support to prevent me from such a
problem.

Please extend the the imap support for full encryption connection to a imap
service.
If not possible please allow to disable the use of imap service in dolphin.




-- System Information:
Debian Release: jessie/sid
  APT prefers testing
  APT policy: (600, 'testing'), (500, 'proposed-updates'), (500, 'stable'), (190, 'unstable'), (150, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.16-3-amd64 (SMP w/6 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages dolphin depends on:
ii  kde-runtime        4:4.14.2-1
ii  libbaloocore4      4:4.14.2-1
ii  libbaloofiles4     4:4.14.2-1
ii  libbaloowidgets4   4:4.14.0-1
ii  libc6              2.19-13
ii  libkactivities6    4:4.13.3-1
ii  libkcmutils4       4:4.14.2-3
ii  libkdecore5        4:4.14.2-3
ii  libkdeui5          4:4.14.2-3
ii  libkfile4          4:4.14.2-3
ii  libkfilemetadata4  4:4.14.0-1+b2
ii  libkio5            4:4.14.2-3
ii  libknewstuff3-4    4:4.14.2-3
ii  libkonq5abi1       4:4.14.2-1
ii  libkparts4         4:4.14.2-3
ii  libphonon4         4:4.8.0-3
ii  libplasma3         4:4.14.2-3
ii  libqt4-dbus        4:4.8.6+git64-g5dc8b2b+dfsg-2+b1
ii  libqt4-xml         4:4.8.6+git64-g5dc8b2b+dfsg-2+b1
ii  libqtcore4         4:4.8.6+git64-g5dc8b2b+dfsg-2+b1
ii  libqtgui4          4:4.8.6+git64-g5dc8b2b+dfsg-2+b1
ii  libsolid4          4:4.14.2-3
ii  libstdc++6         4.9.1-19
ii  libxrender1        1:0.9.8-1+b1
ii  phonon             4:4.8.0-3

Versions of packages dolphin recommends:
ii  ruby            1:2.1.0.4
ii  ruby1.8 [ruby]  1.8.7.358-7.1+deb7u1

Versions of packages dolphin suggests:
pn  kdesdk-dolphin-plugins  <none>

-- no debconf information


Reply to: