back to article SecurEnvoy SecurMail, you say? Only after this patch is applied, though

Recently resolved vulnerabilities in SecurEnvoy's encrypted email transfer SecurMail created a way for encrypted emails in users' inboxes to be read, overwritten and deleted by others. The flaws – uncovered by Austrian security firm SEC Consult during a crash test – included cross-site scripting, cross-site request forgery, …

  1. clocKwize

    Baking in encryption does not mean something is secure. Who'd have thought?

  2. Anonymous Coward
    Anonymous Coward

    Messages readable in plaintext from the server? Authentication bypass?

    Sounds like a regular IMAP server using TLS is far more secure than this. Especially if you use PGP on top of it.

