-
-
Notifications
You must be signed in to change notification settings - Fork 14.2k
Open
Labels
feature:authAuthentication and authorizationAuthentication and authorizationhosting:cloudOfficial LobeHub CloudOfficial LobeHub Cloudplatform:webWeb platformWeb platformpriority:highCritical issues requiring immediate attentionCritical issues requiring immediate attention
Description
Good afternoon,
As you may know, major email providers such as Microsoft have significantly tightened their guidelines for mail servers that send emails to e.g. Microsoft servers, in order to protect customers against phishing 😍.
Because the Lobechat Mail / DNS-Server have critical configuration errors 😞, E-Mails from [email protected] sent to e.g. Microsoft will be immediately deleted, so they do not reach the user's spam folder at all.
👌 The critical errors in the LobeChat mail server DNS records can be seen here:
https://mxtoolbox.com/emailhealth/lobechat.com/
The following records are missing: SPF, DMARC, and MX records.
😞 BTW: A login-link via email is extremely insecure and grossly negligent
- If one wants to protect customers, companies set up multi-factor authentication.
- Lobechat takes the opposite approach and even removes the password, so that any hacker who gains access to a mailbox can also access Lobechat customers' accounts completely anonymously: Lobechat users don't even notice that their account has been hacked.
- The fact that mailboxes are not secure is demonstrated by https://haveibeenpwned.com/ and the darknet with millions of access data.
Best regards,
Thomas
dosubotschittli
Metadata
Metadata
Assignees
Labels
feature:authAuthentication and authorizationAuthentication and authorizationhosting:cloudOfficial LobeHub CloudOfficial LobeHub Cloudplatform:webWeb platformWeb platformpriority:highCritical issues requiring immediate attentionCritical issues requiring immediate attention