<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Plusnet Security - My Rude Awakening in Plusnet Feedback</title>
    <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Security-My-Rude-Awakening/m-p/1605335#M83821</link>
    <description>&lt;P&gt;It's not quite that bad - wifi is moderately well encrypted.&lt;/P&gt;
&lt;P&gt;If you want proper end-to-end encryption I'd consider signing up at &lt;A href="https://protonmail.com/signup" target="_blank"&gt;https://protonmail.com/signup&lt;/A&gt; - you can get a single email account for free without any adverts etc.&lt;/P&gt;</description>
    <pubDate>Sun, 13 Jan 2019 15:37:50 GMT</pubDate>
    <dc:creator>VileReynard</dc:creator>
    <dc:date>2019-01-13T15:37:50Z</dc:date>
    <item>
      <title>Plusnet Security - My Rude Awakening</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Security-My-Rude-Awakening/m-p/1605327#M83820</link>
      <description>&lt;P&gt;I have known for a long time that Plusnet do not use an encrypted link for connections to IMAP or POP3 email clients but have just had a light bulb moment regarding this shortcoming. Being bored I have had a play with Wireshark. This has brought home to me the implications of a third party getting access to my wireless network. This could be leaked by various ways, for example a quick look (or snap from a camera phone) at the rear of the router is all that's required.&lt;/P&gt;
&lt;P&gt;Anyway, what I have suddenly realised is that if some-one can connect to your wireless network, every time you check for incoming emails your user name and password can be easily extracted as it's shown in plain test. As the same details are used to access your Plusnet Account, every time emails are checked, in my case Outlook is set to do this every 30 minutes, your account user name and password is being transmitted in plain text for a snooper to pick up. This of course gives them full access to account details, telephone records, any security bolt settings, etc.&lt;/P&gt;
&lt;P&gt;My solution is to change my wireless password from that on the router label and use my other secure non-Plusnet email account. I have forwarded any emails addressed to my Plusnet mailbox to the other account and deleted the Plusnet settings from my Email client.&lt;/P&gt;
&lt;P&gt;I note that webmail can be accessed via a secure https link and hence is not exposed to this security flaw.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Jan 2019 14:33:01 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Security-My-Rude-Awakening/m-p/1605327#M83820</guid>
      <dc:creator>Baldrick1</dc:creator>
      <dc:date>2019-01-13T14:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: Plusnet Security - My Rude Awakening</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Security-My-Rude-Awakening/m-p/1605335#M83821</link>
      <description>&lt;P&gt;It's not quite that bad - wifi is moderately well encrypted.&lt;/P&gt;
&lt;P&gt;If you want proper end-to-end encryption I'd consider signing up at &lt;A href="https://protonmail.com/signup" target="_blank"&gt;https://protonmail.com/signup&lt;/A&gt; - you can get a single email account for free without any adverts etc.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Jan 2019 15:37:50 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Security-My-Rude-Awakening/m-p/1605335#M83821</guid>
      <dc:creator>VileReynard</dc:creator>
      <dc:date>2019-01-13T15:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: Plusnet Security - My Rude Awakening</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Security-My-Rude-Awakening/m-p/1605336#M83822</link>
      <description>&lt;P&gt;Were you running wireshark on the computer accessing the email, or on a different device?&lt;/P&gt;
&lt;P&gt;It is possible to view such traffic from another device, but perhaps not quite as easy as you suggest.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Jan 2019 15:39:47 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Security-My-Rude-Awakening/m-p/1605336#M83822</guid>
      <dc:creator>ejs</dc:creator>
      <dc:date>2019-01-13T15:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Plusnet Security - My Rude Awakening</title>
      <link>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Security-My-Rude-Awakening/m-p/1605338#M83823</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;every time you check for incoming emails your user name and password can be easily extracted as it's shown in plain test. As the same details are used to access your Plusnet Account&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;That's only true for the default mailbox. You can mitigate the problem by using additional mailboxes instead with their own passwords.&amp;nbsp; When/if you need to access the default one, do it from webmail, that's what I do.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Jan 2019 15:46:51 GMT</pubDate>
      <guid>https://community.plus.net/t5/Plusnet-Feedback/Plusnet-Security-My-Rude-Awakening/m-p/1605338#M83823</guid>
      <dc:creator>MisterW</dc:creator>
      <dc:date>2019-01-13T15:46:51Z</dc:date>
    </item>
  </channel>
</rss>

