i2pmail outdated and less secure
Posted: 18 Oct 2018 18:46
I have already spoke to postman before almost one month and hes aware of some of these points that's im going to mention, but its better if i profile it here so we can keep an eye/track to the progress of it.
- http://hq.postman.i2p/ the documentations are outdated, some links doesn't work, the email itself needs more security e.g:
* Doesn't support uploading pgp (disabled by default), which against this rule listed here
* Instructions for pop3 and smtp are outdated , not working for Thunderbird
* Passwords has huge issues as it only accept -30 characters AND it doesn't accept Extended ASCII Password e.g:
only accepting: ";QJma+R3" but NOT "çæ±ã¡Í½¸À¿ç®¨¾" which making the passwords very common and insecure for brute-force attack
* Having a public addressbook for users email is very bad for users , as they gonna be harmed through Email Spambot.
*Emails encrypted by default in the server?
* Feature Request a: Add keys revocation, in case someone forgot his real password then he can only use these keys to restore his passwords. otherwise no way to help (better to read Zero-knowledge password proof)
* Feature Request b: add a Multi-factur authentication to the user account, whether by uploaded a saved hash, or as tokens ...etc. (many options)
* outdated documentation like: http://hq.postman.i2p/?page_id=23 which refers the user for susi.i2p which is gone since ages, in meta you find "Valid XHTML" which is a W3C page but its gone, The SMIGACY Proxy its 2005 instructions? ...etc.
* Suggestion 1: modernize the i2pmail user login with Mail-in-a-Box a good example of successful mail to take notes from is Riseup.
* Suggestion 2: have a logo of i2pmail, so we can refer to it if someone want to refer/mention it or list it in wiki ..etc.
These changes will allow the extending the life and usage of i2pmail in more secure modernized way. Hope to see them soon.
Thank You!
- http://hq.postman.i2p/ the documentations are outdated, some links doesn't work, the email itself needs more security e.g:
* Doesn't support uploading pgp (disabled by default), which against this rule listed here
* Instructions for pop3 and smtp are outdated , not working for Thunderbird
* Passwords has huge issues as it only accept -30 characters AND it doesn't accept Extended ASCII Password e.g:
only accepting: ";QJma+R3" but NOT "çæ±ã¡Í½¸À¿ç®¨¾" which making the passwords very common and insecure for brute-force attack
* Having a public addressbook for users email is very bad for users , as they gonna be harmed through Email Spambot.
*Emails encrypted by default in the server?
* Feature Request a: Add keys revocation, in case someone forgot his real password then he can only use these keys to restore his passwords. otherwise no way to help (better to read Zero-knowledge password proof)
* Feature Request b: add a Multi-factur authentication to the user account, whether by uploaded a saved hash, or as tokens ...etc. (many options)
* outdated documentation like: http://hq.postman.i2p/?page_id=23 which refers the user for susi.i2p which is gone since ages, in meta you find "Valid XHTML" which is a W3C page but its gone, The SMIGACY Proxy its 2005 instructions? ...etc.
* Suggestion 1: modernize the i2pmail user login with Mail-in-a-Box a good example of successful mail to take notes from is Riseup.
* Suggestion 2: have a logo of i2pmail, so we can refer to it if someone want to refer/mention it or list it in wiki ..etc.
These changes will allow the extending the life and usage of i2pmail in more secure modernized way. Hope to see them soon.
Thank You!