Dear Kim,
Thanks a lot for your reply. Your answer once again underscores that there are real people behind runbox :)!
I am happy to hear that you approved of my suggestions and added them to your internal pipeline.
Let me make one more comment: My first point (OTPs) is of top priority for me. That would be almost a unique feature to runbox -- not many other services support that. As soon as you implement that, you'll see me sign up ;)!
<edit> Ease of use of the OTP/hardware token solution seems crucial to me. It wouldn't be much help if one had to install drivers or use specific programs when checking mails from a public cyber cafe. What comes to my mind are solutions as known from internet banking -- tokens generating OTPs or even simpler lists with OTPs that you can print from inside your runbox account when logged in from a trusted terminal. Ultimate security cannot be achieved anyway, but these measures would make it a lot harder to phish your login credentials or have them unintentionally stored in the browser's auto-complete feature (have you ever tried to clear the browser's history on a terminal whose language you cannot even decipher ;)? )</edit>
Keep up the good work!
Regards,
gecko
Last edited by gecko : 12 Feb 2010 at 05:58 PM.
|