Bug#769659: dolphin does not use TLS. No password protection by connecting imap service
Package: dolphin
Version: 4:4.14.2-1
Severity: wishlist
Dear Maintainer,
I use icedove for connection my email provider via TLS IMAP connection.
If I copy and paste a mail to dolphin window dolphin opens an window asking for
a password for the mail user I use in dolphin.
I checked now with tcpdump -i eth0 -A port imap2 the network traffic and was
surprised, that I can read my password in clear-text form so any user who watch
the connection can steal my login credentials.
There is no warning in icedove that the password will send in clear-text nor a
setting how I can disable this simple imap support to prevent me from such a
problem.
Please extend the the imap support for full encryption connection to a imap
service.
If not possible please allow to disable the use of imap service in dolphin.
-- System Information:
Debian Release: jessie/sid
APT prefers testing
APT policy: (600, 'testing'), (500, 'proposed-updates'), (500, 'stable'), (190, 'unstable'), (150, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386
Kernel: Linux 3.16-3-amd64 (SMP w/6 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Versions of packages dolphin depends on:
ii kde-runtime 4:4.14.2-1
ii libbaloocore4 4:4.14.2-1
ii libbaloofiles4 4:4.14.2-1
ii libbaloowidgets4 4:4.14.0-1
ii libc6 2.19-13
ii libkactivities6 4:4.13.3-1
ii libkcmutils4 4:4.14.2-3
ii libkdecore5 4:4.14.2-3
ii libkdeui5 4:4.14.2-3
ii libkfile4 4:4.14.2-3
ii libkfilemetadata4 4:4.14.0-1+b2
ii libkio5 4:4.14.2-3
ii libknewstuff3-4 4:4.14.2-3
ii libkonq5abi1 4:4.14.2-1
ii libkparts4 4:4.14.2-3
ii libphonon4 4:4.8.0-3
ii libplasma3 4:4.14.2-3
ii libqt4-dbus 4:4.8.6+git64-g5dc8b2b+dfsg-2+b1
ii libqt4-xml 4:4.8.6+git64-g5dc8b2b+dfsg-2+b1
ii libqtcore4 4:4.8.6+git64-g5dc8b2b+dfsg-2+b1
ii libqtgui4 4:4.8.6+git64-g5dc8b2b+dfsg-2+b1
ii libsolid4 4:4.14.2-3
ii libstdc++6 4.9.1-19
ii libxrender1 1:0.9.8-1+b1
ii phonon 4:4.8.0-3
Versions of packages dolphin recommends:
ii ruby 1:2.1.0.4
ii ruby1.8 [ruby] 1.8.7.358-7.1+deb7u1
Versions of packages dolphin suggests:
pn kdesdk-dolphin-plugins <none>
-- no debconf information
Reply to: