
I am sure you have encountered this somewhere on the web. You’re on a social networking website, facebook maybe, and right after you register for an account, it asks you to enter your email address along with its password to send an invitation on your behalf to your friends.
I am sure lot of people are doing it, as I receive tons of invitations from my friends everyday! But have these people ever thought of the possibility that some of these websites might be storing their passwords?
At Facebook for instance, they clearly state that they won’t store any login info, but why should someone trust them?
It only takes an additional couple lines of code to store your username and password into a file or a database on the server! And don’t let the https or the lock sign in your browser trick you to think you’re 100% secure, this will actually insure your password is being sent to the server after encrypting it. But be sure that they’re decrypting it at the server side since they should forward it to your webmail, so it is being manipulated in clear text somewhere in their system.
Moreover, what about all the addresses they’re getting from your address book? If all these addresses are never to be used by spammers… then I am Donald Duck!
So next time, think twice before you grant any website the permission to access your email.
Recent Comments