Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

can't you just disable ssl and sniff the password via wireshark?


No. It'll be a token.


Thunderbird will store the password in password manager though. It should be accessible.


What does it being a token have to do with anything?

An unencrypted token is just as vulnerable as an unencrypted password.


Tokens have defined scope and expire, so not the same as a password that doesn’t have these limitations.


If the stream is encrypted that's great. The token is likely to expire before the stream could be decrypted.

But if the stream isn't encrypted then it doesn't matter. A robot can easily collect the token and utilize it before the token expires.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: