Thursday, July 9, 2009

Are all email server is providing security from keystroke logger?

No, and they can't.





Email servers take their data in over networks using standard protocols, they don't provide a user interface.





Since they don't interact with the user directly, nothing they could do could mitigate any keystroke logger installed on the users system.





In theory, a web mail system (which is an email client that runs in a web browser and is tied very tightly to a single mail server) could provide an on screen keyboard which the user could interact with using a mouse ... but I don't know of any that do since the cost:benefit ratio is swung too far towards the cost.

Are all email server is providing security from keystroke logger?
As I have already answered keystroke loggers are not on the servers but on your own computers. Certain Banking websites have taken up the virtual keyboard method so that the keystroke loggers do not log your keystrokes. I am not sure how many servers have taken up this method. But this is just a way to defend the keystroke logger, by not entering any keystrokes as they cannot log mouse strokes.Certain websites have also taken in methods by entering sensitive data by hovering the mouse over the virtual keyboard or by randomly changing the location of the buttons on the virtual keyboard.


No comments:

Post a Comment