Mailbox.org

Why should this tool be removed?

Mailbox.org has several security issues and should be considered for removal as it is advertised to be a secure mailbox solution.

Issues:

  • Mailbox announced that the user now has the option to deactivate the password reset (and 2FA reset) via IMAP. However, the default setting is that a reset via IMAP is enabled and will reset the password and 2FA. Based on the Support it will stay that way
  • Far behind competitors regarding features
  • They don‘t have any security notification or dashboard where you can see sessions, failed logins, recent actions like password changes. No notification when 2FA was activated, when password was changed, when IMAP password has been created etc. unlike Tuta, Fastmail, Proton, etc.
  • No OAuth or YubiKey support for 2FA
  • No recovery codes possible for 2FA TOTP
  • No SPAM/Rejection-Log
  • Increase of vulnerabilities and minimal response provided by Mailbox team
  • No roadmap or timeline to implement anti-spoofing for custom domains

Related Thread:
https://discuss.privacyguides.net/t/mailbox-org-with-severe-authentication-vulnerability-through-password-reset/31846/16

2 Likes

4 posts were merged into an existing topic: Remove Mailbox.org

Not sure about all of the rest, but this is false (they do have both .deb and .rpm).


No carddav or caldav

Same for this, there is a contact + calendar part… :sweat_smile:

I am not trying to sell Proton specifically but having false claims is probably not the way to go either tbh.

1 Like

A recovery email is not required even when a verification email is. See this post on PG which also links to Proton official documentation for more info.

“Note that if you enter your email or mobile phone number, we only save a cryptographic hash of this personal data. It’s impossible to derive your phone number or email from that hash, and it’s not permanently associated with the account that you create.”

Am using Proton Unlimited and am more than happy with this service.

There is already a thread about removing mailbox.org here

3 Likes

As @any1 pointed out, there is already an existing thread. Please continue any discussion about Mailbox Mail there.