cancel
Showing results for 
Search instead for 
Did you mean: 

SSL / TLS Email (again) - orphaned addresses - PayPal security worries

FIXED
spiralgalaxy5
Newbie
Posts: 3
Thanks: 2
Registered: ‎13-05-2020

SSL / TLS Email (again) - orphaned addresses - PayPal security worries

Hi everyone - I know this subject has been flogged a couple of times (I did have a look around before posting) but I see that webmail (Round Cube) has https:// login ...so...

When will standalone email client security for care4free>madasafish>plusnet accounts be available?

I have a bit of a problem:  PayPal has a legacy CFF (care4free) email address recorded for me that is still usable but that does not show up in my PayPal user interface any more. I don't know how it got orphaned at PayPal and they are impossible to deal with.  I've tried bouncing one of their emails to unsubscribe but I don't hold out much hope for that working.  I think that they have several servers - maybe one of them still has the old address and somehow the linkage back to the account detail is broken... I digress.

If I type in my old CFF address at the PayPal login, click on "Having trouble logging in"? and take up their offer to "Enter the email address you use for PayPal and we'll help you create a new password" I get an email at my CFF address with a code - "To reset your password, enter this verification code when prompted:"

I can't contact PayPal to get my CFF email address removed from the account.

The security issue:  there must be many old care4free (and other provider) accounts that have been migrated to plusnet that are dormant but still accessible and subject to brute force attack or simple guessing for their passwords. There are many possibilities - the problem I have with PayPal is one of them IMO.

My problem here of course lies with PayPal - I need that "invisible" address removed from my account - but as I say they are not reachable (not even the useless - sorry - customer-facing layers) and I've no confidence that they could actually sort out problems with their systems anyway. Closing down the account entirely is inconvenient (and might not purge the orphaned address and other data from their servers... better to have at least some visibility of what's happening).  I'll change my password again anyway, following the email experiments 🙂.

 

Questions:

1. Can Plusnet close / inhibit a legacy care4free account and mark it so that the email address cannot be re-used?

2. Is it possible for an ordinary user to create a new care4free email account? (Presumably a Plusnet employee with enough knowledge could do so as Plusnet owns / controls the care4free.net domain?)

 

Sorry for the lengthy post.  If anyone has any other suggestions about the PayPal thing please go ahead but the main question is about Plusnet SSL/TLS for remote client non-webmail access.

Cheers all

Tim

4 REPLIES 4
MisterW
Superuser
Superuser
Posts: 14,768
Thanks: 5,537
Fixes: 395
Registered: ‎30-07-2007

Re: SSL / TLS Email (again) - orphaned addresses - PayPal security worries

Fix

@spiralgalaxy5 SSL/TLS is available , see this thread https://community.plus.net/t5/Email/SSL-on-IMAP-POP3-SMTP-again/td-p/1643433

 

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

spiralgalaxy5
Newbie
Posts: 3
Thanks: 2
Registered: ‎13-05-2020

Re: SSL / TLS Email (again) - orphaned addresses - PayPal security worries

😀 Awesome - lightning quick response. I didn't see the other post in my search. Thanks MisterW.  Tested in Thunderbird 68.8.0 with care4free.net addresses; SSL/TLS on 995 for pop and SSL/TLS on 465 or STARTTLS on 587 work for smtp. Well that's another day I'll never get back but at least my paranoia is being dialled down now...

Nice community site here at Plusnet - good web browser interface.

Thanks again

MisterW
Superuser
Superuser
Posts: 14,768
Thanks: 5,537
Fixes: 395
Registered: ‎30-07-2007

Re: SSL / TLS Email (again) - orphaned addresses - PayPal security worries

Great to hear it worked. TBH I knew it worked on Plusnet, but wasnt sure about the care4free accounts.

I assumed it ought to work since they're almost certainly on the same servers.

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

spiralgalaxy5
Newbie
Posts: 3
Thanks: 2
Registered: ‎13-05-2020

Re: SSL / TLS Email (again) - orphaned addresses - PayPal security worries

I'm surprised (and grateful) that the old accounts still work as they do.  These are getting on for their silver jubilee after all... I might do some more digging / post a question on account password changes for care4free accounts as I don't have a Plusnet account to login for this kind of administration on the legacy accounts.  The webmail interface doesn't offer password changing that I could find.  I wonder how many still use care4free addresses?  Before them I was on virgin.net dial-up which was all the rage at that time... ah Netscape...

Maybe Sys Admins look at the stats and allow ones still in regular use to keep going.  Easy enough to look for accounts with rammed inboxes + no activity (i.e. no login) and then delete them.

I don't abuse my care4free emails for mass mailings etc. but I guess one day Plusnet could remove them without warning.  I was using pop.care4free.net to retrieve emails until today (with your help to change over).  Interestingly my aliases have now become acceptable mail logins on Plusnet whereas previously I was using the account names issued by care4free on their domain, which were aliased to usable names for email.  Amazing how it has all survived.