On mySimon: Dragon Eye Oolong Tea
BNET Business Network:
BNET
TechRepublic
ZDNet

September 18th, 2008

Webmail and traditional e-mail face different threats

Posted by Adam O'Donnell @ 2:06 pm

Categories: Data theft, Governments, Passwords, United States of America, Web Applications

Tags: Hard Drive, E-mail, Desktops, Productivity, Security, Online Communications, Hardware, Adam O'Donnell

This week’s attack on Sarah Palin’s e-mail account highlights how the same application could have very different threat models depending on the technology used. While this is a general issue for all Software-as-a-Service offerings versus traditional desktop packages, let’s focus on just e-mail for now. Let’s first step into our adversary’s shoes and try to think like an attacker.

If your target is a webmail system, there are a variety of techniques you can use to compromise the account. You may attempt any of the following:

  • Using a targeted phishing attack to grab the individual’s username and password.
  • Requesting a password reset on the account.
  • Researching sophisticated web attacks, XSS/CSRF style exploits, hoping to find one that works against your target’s current webmail provider.

Attacking a desktop machine would require a somewhat different set of techniques, such as:

  • Stealing their computer.
  • Infecting their system with a piece of malware that provides access to their local hard drive.

It appears that desktop-based applications are more secure from face value, but our model discounts data loss from hard drive failures, bad backups, and all of the other means that isolated pieces of hardware can refuse to work. When you add in the added convenience of accessible-from-anywhere, continuously backed-up, low administration services, it is quite easy to see how many people prefer using webmail and equivalent systems.

You do need to appreciate, though, how the threat model changes when you choose one technology over the other.

Adam O'DonnellAdam J. O'Donnell, Ph.D. is an R&D engineer who has focused on computer security since 2000. He currently is the Director of Emerging Technologies at Cloudmark, a messaging security company located in San Francisco. See his full profile and disclosure of his industry affiliations.

Email Adam O'Donnell

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 19 Talkback(s)
Secure Data
Very True. I just became aware of using attachment
for secure data. (Read the rest)
Posted by: philscbx@... Posted on: 09/21/08 You are currently: a Guest | | Terms of Use
Email is insecure; webmail is more insecure  Taz_z | 09/18/08
Come on man, traditional email is also stored on a server attached to the  DonnieBoy | 09/18/08
yeah, but...  Taz_z | 09/19/08
Come on guys, traditional email is ALSO stored on a server. Attacking a  DonnieBoy | 09/18/08
Nobody knows that Palin's account was "hacked". Somebody probably just  DonnieBoy | 09/18/08
Don't read much, do you?  btidwell | 09/19/08
Palin's Hacker  philscbx@... | 09/21/08
NOT SAFE := Webmail, SOA, SaaS, Cloud, ...  joemartn | 09/19/08
Not even safe to hide your identity  Taz_z | 09/19/08
More importantly ...  mwagner@... | 09/19/08
How true you are  Taz_z | 09/19/08
RE: Webmail and Traditional E-Mail face different threats  mwagner@... | 09/19/08
My webmail has no restrictions that I know of...  JCitizen | 09/19/08
RE: Webmail and Traditional E-Mail face different threats  abear4562 | 09/19/08
RE: Webmail and Traditional E-Mail face different threats  leonelgan | 09/19/08
RE: Webmail and Traditional E-Mail face different threats  whizxp | 09/19/08
Secure Data  philscbx@... | 09/21/08
RE: email is insecure  erik.t | 09/19/08
RE: Webmail and Traditional E-Mail face different threats  philscbx@... | 09/21/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here