Menu
Reply
Highlighted
  • 16.77K
  • 922
  • 6.59K
Superuser
Superuser
270 Views
Message 1 of 4
Flag for a moderator

Mail2Web is it Safe?

In answering posts on here I've come across a number of users who've mentioned the site mail2web.com this is a site that ostensibly allows you to read your email from anywhere in the world.

You don't need an account with them, all you need is your email address and password.

What could be wrong with that?

Before I answer the question, I want to stress that I have no evidence to suggest that mail2web is run by scammers.  What I'm posting is legitimate concerns regarding security that apply to any such site.

Concern 1 - Logon is not secure by default.

If like many users you simply put mail2web in your browsers address then you'll see that the site is not secure.

mail2webdef.PNG

This means that if I enter my email address and password, they are sent in plain text across the internet, meaning that anyone who can intercept the packets can read them.  There is a Secure Login link, which switches the connection to HTTPS - but this link should not be needed.

It is child's play for someone who runs a web server to set up a redirect so HTTP connections are automatically redirected to HTTPS instead.  That this site has not done so is a red flag to me.

Concern 2 - Who are you giving your login details to?

With sites like this you have to ask, who is running the site?  What guarantees do I have that they are legitimate.  What are they doing with my data.

Why should you ask this.  Well for one thing, your trusting them with both your email address AND your login password.

This is the holy grail, once I have access to your email I can see what sites you deal with.  I can try and see if your one of the many web users who share passwords across multiple websites and even if you are not I can always send out a password reset request and do my best to make sure I delete the mail before you see it.

I should stress that I'm not a scammer myself, however I do try and think like one in order to look at concerns like this.

So with that in mind I'd have to ask - who exactly am I dealing with?

The site appears legitimate mail2web are owned by Softcom inc in Canada, and looking at their privacy policy they state the following:

The customized version of mail2web.com requires storing Your email address (“Personal Information”) to function, should You wish to provide it. However Your password associated with any email address stored is not collected at anytime

However I'd argue that that's not strictly true - they have to obtain your password in order to connect you to the server, so while it might not be STORED it is COLLECTED in order to facilitate the connection.

Personally I'd be wary sharing login details with any site on the internet other than the site those login details are meant for.  While Softcom appear legitimate, I would be very wary when using their site myself.

________________________________________


Only use Helpful answer if your problems been solved.

  • 3.09K
  • 337
  • 1.04K
Superuser
Superuser
175 Views
Message 2 of 4
Flag for a moderator

Re: Mail2Web is it Safe?

FYI, Softcom Inc is an Ingram Micro company and the parent company is HNA Technology, these are all established businesses however that does not mitigate the risks of trust mentioned in your post.

BTW, Facebook provided a timely reminder of why not to trust a third party with your email address and password, Facebook Got Caught Phishing For Friends.

0 Kudos
Reply
  • 16.77K
  • 922
  • 6.59K
Superuser
Superuser
164 Views
Message 3 of 4
Flag for a moderator

Re: Mail2Web is it Safe?

For me the worst thing about Facebook is the claim that they "unintentionally" uploaded the users contact details.

There's nothing unintentional about it.  You have to write the code that will get the users login details and the code that will obtain their contact information from their account.  I find it hard to believe that that code wouldn't have been written without the approval of some of the higher ups there.

What's fun about Softcom is that they are based in Canada, but they are now owned by a Chinese conglomerate.  Being as how were being told we can't trust China's Huwei corporation. I do find this ironic to say the least.

Tim

________________________________________


Only use Helpful answer if your problems been solved.

0 Kudos
Reply
  • 9.29K
  • 1.03K
  • 4.32K
Superuser
Superuser
149 Views
Message 4 of 4
Flag for a moderator

Re: Mail2Web is it Safe?

May be I'm missing something here but if your mail supplier offers a web mail service then why would you use mail2web at all with the attendant risks of giving third parties access to your credentials when you don't need to. I suppose that there are some iSPs that only offer client based e-mail but they must be few and far between now. I can't recall any in the UK?

-----------------------

Superuser since 2015/16
Use Kudos to say thanks
Tick an answer as "helpful" only when the problem is solved
Please don't send me private messages unless I ask you to.
I do not work for VM. The advice I give is based on my best understanding of VM policy and practice. You rely on it at your own risk.
0 Kudos
Reply