Tired of ads? Enjoy an ad-free experience by signing up.
Laurence Putra · · 5 min read

Dropmyemail not a secure way to back up your email? (Dropmyemail responds)

Note: Scroll down to see Dropmyemail’s response to the article.

Dropmyemail

A couple of weeks ago, the internet was abuzz with news about how Whatsapp was insecure and users should not be using it.

I did a bit of checking and found that a couple of local startups may have potential security problems as well. In the field of computer security, one of the biggest no-nos is to store a user’s password in a way that could be regenerated easily, either by the system administrator, or by rogue hackers on the internet.

And as it turns out, a local startup, Dropmyemail, is a gold mine for such attacks. Users are required to give Dropmyemail their username and passwords to store. Dropmyemail will use them to log in to their email accounts and grab all their emails over to its servers.

With over half a million users, Dropmyemail’s database is sure to be a treasure trove for hackers and the like. In any case, even if Dropmyemail does encrypt the passwords, they still have the key to decrypt the passwords somewhere on their server. And their developers will be able to see your passwords.

To add on, despite holding on to your sensitive data, in their terms of service, there’s this line:

Dropmyemail cannot be held responsible for any breach of security and the possible compromise of your data as no means of virtual data storage is 100% safe. By use of the Service you expressly accept that Dropmyemail (its employees, affiliates agents, sub contractors) has no liability in the event of a security breach or compromise or loss of your data

Just to recap, storing passwords of users is something that is a complete no-no in the tech world. And despite doing so, they are saying that they are not liable if your passwords ever do get hacked out of their system. So, what can you do if you still want to back up your email securely?

For one, most email providers have an autoforwarding function for every email that comes in. What you can do is to autoforward it to another email address by another provider, for example, Gmail.com, Outlook.com, Hotmail.com. If you really want to let the other provider grab email for you on a regular basis, GMail and Outlookdoes this for free too.

And in all honesty, I’d rather trust Microsoft and Google with my password than some startup that tells me that it’s not liable if my password is ever released to the public.

Dropmyemail publicist Peter Yu responds:

1) On how storing user passwords is discouraged and that it is disingenuous for Dropmyemail’s terms of service to say that the company cannot be held responsible for breach of security despite going against recommended practice.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

Community Writer

Laurence Putra

Laurence is a hacker who organizes the region's largest all-geek event, GeekcampSG, and is particularly passionate in the fields of Distributed Systems and Computer Security. In his free time, he hacks out tools to solve his personal pain points, including Instasyncer. More about him over at Geeksphere.net.