Categories: Tech

Millions of email users at risk: passwords could be exposed to hackers, experts warn

New research by security experts has found that more than 3 million email servers are still using an aging protocol without encryption enabled, leaving millions of usernames and passwords vulnerable to hackers.

This week, the Shadowserver Foundation, a nonprofit security organization, issued an alert on X and discovered that 3.3 million POP3 and IMAP servers are operating without Transport Layer Security (TLS) encryption enabled. . To translate, POP3 (Post Office Protocol version 3) is an aging protocol used by email clients to access email from an email server, and it is often used alongside the newer IMAP (Internet Message Access Protocol). TLS encryption, on the other hand, is a protocol that encrypts communication between web applications and servers, preventing hackers from intercepting potentially sensitive information while you chat or check email.

Without TLS encryption enabled during transmission, the content of your messages and your login information such as username and password are sent in plain text, leaving this information accessible to any malicious actor using network networks. eavesdropping.

https://twitter.com/cantworkitout/status/1874034572088033524″ data-url=”https://twitter.com/cantworkitout/status/1874034572088033524″ target=”_blank” referrerpolicy=”no-referrer-when-downgrade” data-hl-processed=”none

“We have begun reporting hosts running POP3/IMAP services without TLS enabled, meaning usernames/passwords are not encrypted when transmitted,” the ShadowServer Foundation said.

Nearly 900,000 of these sites are based in the United States, with 560,000 and 380,000 in Germany and Poland, respectively, the organization found, adding: “We are seeing approximately 3.3 million such cases with POP3 and a similar number with IMAP (most overlap). It’s time to remove them! » You can view vulnerability reports for POP3 mail servers and IMAP mail hosts on the Shadowserver Foundation site.

How to Stay Safe Against the Threat of Email Password Exposure

Email service providers have used TLS to encrypt messages for decades, and Microsoft began enabling the latest version, TLS 1.3, by default with Windows 11. Although the Shadowserver Foundation warned that “whether or not TLS is enabled , exposing the service may enable password guessing attacks against the server.

The organization advised all email users to check with their email service provider to ensure TLS is enabled and the latest version of the protocol is used. Fortunately, the latest versions of Apple, Google, Microsoft, and Mozilla email platforms all enable TLS, so users can rest assured that their information is already protected.

When it comes to general online security tips, it’s always a good idea to make sure you’re using the best antivirus software to protect your PC, the best Mac antivirus software to protect your Mac, and one of the best apps Android antivirus to protect your Android phone. .

Learn more about Tom’s Guide

remon Buul

Share
Published by
remon Buul

Recent Posts

The prices of bananas, coffee, hygienic paper could increase

A customer is producing products in a weekly grocery store in Austin, Texas, February 12,…

3 minutes ago

The judge says that the American government may have “acted in bad faith” when he weighs contempt rather than the expulsion order

By Lindsay Whitehurst, Michael Kunzelman and Alanna Durkin RicherWashington (AP) - A federal judge said…

4 minutes ago

Updates live from Trump: national security officials have been dismissed at the request of Laura Loomer

President Trump dismissed six officials of the National Security Council after an extraordinary meeting at…

6 minutes ago

Resurrections’ but the team “did not answer well”

Laurence Fishburne does not know if he will resume her role as Morpheus in The…

7 minutes ago

Raiders, QB Geno Smith accepts an extension of two years of value up to $ 85.5 million: sources

Las Vegas Raiders and the quarter-Arrière Geno Smith accepted an extension of two years worth…

8 minutes ago

CEO accused of having smothered Man and threatened to kill him on a cruise ship on a dancing incident with bare feet

The CEO of a California -based financial service company faces an accusation of federal assault…

9 minutes ago