Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
×
Microsoft

Secure Windows E-mail Clients? 29

barbaBob asks: "I'm looking for a powerful and secure e-mail client that can handle large volumes of mail for multiple accounts (a mix of POP3 and IMAP). Since I don't want Outlook to be an option, I've been searching for alternatives (eMailMan is an excellent resource). Eudora Pro is a powerful client app, but isn't very stable running on Win2K so far. OpenSoft's ExpressMail seems to be an attractive option with its heavy focus on security and encryption. Netscape Mail is not up to the job, since it doesn't offer filtering. Pegasus Mail is another possibility. HP's OpenMail is very attractive in that if offers full compatability with Outlook/Exchange server-side-drop-in replacement, runs on Linux/Unix - but the client seems to be available to licensed users only so I can't try it yet. So what do you use when stuck with Windows for certain tasks?"
This discussion has been archived. No new comments can be posted.

Powerful/Secure Windows E-mail Clients?

Comments Filter:
  • >There is a setting in outlook which tells it to
    > use the "Internet Zone" security setting.

    Whoa! Use the "Restricted Sites" setting instead. By default this has high security and disables almost everything.
  • How could you guys forget the #1 Internet Service! With features like Child Protect and Buddy List, its super secure. I use it! Everyone I know does too, even my hot record producer. They say in their TOS (whatever that means) that they won't read my love letters, sounds secure to me! yup yup!
  • Are there any free email clients available for linux and/or windows that has support for outlook/exchange email servers?
  • You may want to try the following: Here is an extra [grande-prairie.ab.ca] link for some explanations of E-Mail.
  • by Mark A. Rhowe ( 216675 ) on Saturday July 29, 2000 @12:11PM (#894998) Homepage
    When implementing secure e-mail, organizations need to consider the kinds of transactions that need to be secure, along with five security requirements:

    (1) Confidentiality - Ensure unauthorized individuals cannot intercept and read your e-mail.

    (2) Integrity - Ensure that the contents of the message are not altered in transmission. The message received at the other end needs to be exactly the same as the message that you sent.

    (3) Authentication - Verify the identities of both the sender and receiver of a message. When you receive a message you need to be sure of the sender's identity.

    (4) Access control - Ensure that your messages are not accessible to unauthorized individuals. For example, when you walk away from your desk, leaving your e-mail application open, you need to know that the contents of your messages are protected.

    (5) Non-repudiation - The sender of a message should not be able to deny or repudiate signing a transaction. For example, the sender should not be able to deny signing a purchase order



  • by sniggly ( 216454 ) on Saturday July 29, 2000 @10:36AM (#894999) Journal
    Pegasus mail [usa.com] initial release was in 1990 - it was my first email client and still is my current email client on windows machines.

    I have tried other programs - I wrote an email to netscape in '98 asking them to implement multiple POP support and they believed very few people would ever use that. Perhaps that attitude got them to where the... never mind that one :)

    As far as i can tell pegasus was the first email client that implemented mail filtering rules, multiple accounts, and quite a few other goodies that are commonplace now. It's also been a free program since inception and the guy programming it seems to be a terribly smart aleck with great ideas and seems to listen to good ideas from the user community.

    If you wont end up using pegasus at least you will have been impressed with examining it.

    Too bad it isnt available for linux, however anyone willing enough to try seems welcome [usa.com] and seems to have to do a serious rewrite.

  • Lotus Notes.

    Encryption, PKI, Verisign certificates, different access levels (grant someone read-only, none, author, editor, etc.). Delegate email, delegate appointments, and do all sorts of stuff that takes VB6 and an SQL server.

    AND, the server portion runs on Linux. :-)

    And most other major brands. There used to be a *nix client, but Lotus has announced that the 4.6.7 version is the last one. (Though there was no 4.6 version for Macs, but that was when Apple was having problems, so a massive Linux interest might make a Linux client in the version 6 family available.)
  • 1. Not just a newsreader, it does email too.
    2. Been around for a lot of years and its very slick and smooth.
    try it
  • by BitMan ( 15055 ) on Saturday July 29, 2000 @02:26PM (#895002)

    My company refuses to drop the "Microsoft Virus Distribution System" (aka Outlook). After applying the security patch (that disables a crapload of its insecure features), we ran into various issues. Basically, I think the whole security patches for Outlook were specifically designed to force you to buy Exchange. Instead, we opted for HP OpenMail. It's free for upto 50 users and has a 6 month trial (unlimited users).

    It solved our shared Calendar and Contacts issues with its MAPI interface. Of course, none of these features of Outlook, even though they are stored on the server, are compatible with its included, native clients. We're still waiting for something better, but for free, it was a perfect fit (as my "cry baby" ignorant Office users complained after I installed the much needed Outlook fix when it came out). Hopefully the iCalendar and vCard standards in clients like Evolution will push Microsoft (among others) to support them (hopefully).

    I mean, E-mail shouldn't be this hard and Sendmail (once setup) has been running for us solid for 12 months non-stop. OpenMail is great because it uses Sendmail (or any other MTA) underneath so you're not at it's mercy. Although you can have all our company's mail get redirected to OpenMail (e.g., as a Sendmail rule), setting up a subdomain or other MX record keeps its crap separate (I don't like Outlook crap going around on my network any more than I have to).

    Anything to keep ignorant users (only about 20% of my company are these admin users, the rest are UNIX-using engineers) from screaming for Exchange is helpful. OpenMail is your ticket to keeping your servers Microsoft-free -- like ours where 90% of our work is UNIX-based and Samba handles the rest nicely. It is incredibly stable (even though the MAPI client for Outlook is only version 0.5 "preview release") and our server has been running for months now. Everytime I've dealt with an Exchange server, I expect no more than 60 days before a major corruption that keeps me busy for 48 hours straight. Not with OpenMail, it's rock-solid and has even survived someone twice accidently (and quite incorrectly) powering-off the Linux box where it is hosted.

    It also doesn't take a lot of resources to run. Figure about 1-2MB max per client. For ~50 clients, a Pentium with 128MB of RAM will do nicely. We use a Pentium II 400MHz with 384MB and this system also seconds as a secondary NFS/SMB server (to Solaris clients and NT workstations) and Intranet (informational) server. Gotta love Linux baby!

    -- Bryan "TheBS" Smith

  • Except for the rather large secu rity hole [securityfocus.com] :)

  • Whoops! I'll never get to informative that way.
    http://www.forteinc.com/ [forteinc.com]
  • Any e-mail client should work fine with an exchange server, as long as it is running pop3. At work we have exchange servers and I use Netscape Mail and it works just fine. If you are on one of those lame NT domains.. the pop username will be slightly different... and it will follow this order:
    Domain/Username/firstname_lastname
    so mine would be somethin like:
    group1/drew/drew_m.....
  • A major element of security (IMHO) would be not sending the password in plaintext over the wire. I use APOP, which uses an MD5 challenge/response based system (and is covienetly supported by fetchmail). IIRC some IMAP versions also support encrypted or challenge/response authentication (and maybe even encryption the data itself?).

    Eudora also supports APOP, IIRC. And with a PGP plugin you're not doing too bad.
  • It's slow It's ugly It's full of bugs It completely ignores all UI standards and guidelines GO FOR IT !!
  • Eudora Pro is a powerful client app, but isn't very stable running on Win2K so far

    Not to question your setup or anything, but are you running the latest version of Eudora? I'm running 4.3.2 on 2K, and it seems more stable than it was under Win98SE. Versions 4.1 and 4.2 were fairly unstable IMO, but 4.3 seems to have tightened things up.

    (FWIW: I recieve about 200 emails a day, mixed betwen two POP3 accounts, have about 30 filters and at least 10 mailboxes that recieve daily use.)

    Adam

  • Perhaps they've fixed this in the last few months, but I doubt it. They never responded and I don't use Eudora any more so I can't say. However, the last time I checked, HTML-mail from Outlook was sent without any terminating CR following the trailing /HTML tag. However, Eudora was too stupid to add its own CR, so the "From " separator at the beginning of the next message was APPENDED TO THE PRECEDING LINE! I had a suspicion that mail was leaking out my mailbox until I opened it in a text editor and discovered the problem. Their tech support never acknowledged the problem and presumably never fixed it. Don't use Eudora if you care about archiving your mail.
  • Yeah, know about that one, but hadn't realized it'd made it into the mainstream. Wrote an application last year to determine password strength based upon this information. It now, perpetually, nags users whose passwords fail a straight dictionary attack. Of course, if anyone's dumb enough to have their public directory available (equiv to having /etc visible on an anonymous FTP site), then they deserve it.

    Still, I'd take it over Exchange (and I used to be an Exchange admin). And the Execution Control List (ECL) prevents OutLook-virii from doing things. Unless the user blows past the warnings. Which they do. :-)
  • Note that PGP plugs into several Windows mail clients, including Eudora Pro. This can cover several of these concerns.

    --
  • I didn't bother to say this when the question was first posted because I thought it would be everyone's answer. Whatever flavor of emacs/XEmacs/ntemacs works best for you, and whatever email reader seems good.

    I would try a recent version of XEmacs or emacs, and vm. Gnus should also work, and might be a better mail reader for high volume people.

    ( If you use vm and you received a huge amount of email, then you may want a good way of auto-archiving mail. I have some elisp that will save off the first 1000 messages in an archive folder, when the number of messages reaches 2000. It names the archive folder with the date of the first and last messages in the file name, to assist in finding stuff. If somebody wants it they can email me at rgristroph@yahoo.com. )

    Of course, looking on the practical side, you may have trouble convincing some windows people to use it. I think the fact that it works pretty much the same on windows and unix should help convince people to fight their way up the learning curve. Keep in mind that windows people are used to learning a new tool or application not by reading documentation, but by pulling down the menus to see what is there. So XEmacs in the default configration with those buttons and menus might be a good idea.
  • When you're stuck with windows for certain tasks, you should:
    a) Get underneath your desk
    b) Assume a fetal position
    c) Cry
    d) Get back on your chair
    e) Change your mind and start crying again
    f) Compose yourself
    g) Go get some tissue to wipe all of the snot away
    h) Ponder the meaning of life
    i) Muster the courage to face all of those skeletons in your closet
    j) Take control and install Linux on your machine

    Note: If step j is not possible, follow steps a-d and repeat steps e-g for eternity, throwing in step h during Windows reboots.
  • oops, your right. I should have looked first. The two choices in Outlook Express are "Internet Zone" and "Restricted Zone". "Restricted Zone" is the one to use.

    ----------
    AbiWord [abisource.com]: The BEST opensource word processor
  • Hmmm. Weird. I'm not entirely sure and can't check right now, but I think I've got the latest version available. It generates exceptions and other errors, after which it Win2K closes the program.

    Maybe it has something to do with the fact that I'm IMAPing on an Exchange server ;)

    Cya,
    bBob

    --

  • take a look at www.ritlabs.com [ritlabs.com] - they have a piece of software called The Bat. It's a small, very fast and unbelievably powerful win32 e-mail client. POP/IMAP/PGP/filters/muliple accounts/templates just to name a few features.

    s0lar

  • As a Principal Lotus Notes Certified Developer (R4 & R5) I can unequivocally state that Notes blows as a mail client. It should be the basic messaging system for any company that plans to make use of Notes applications, but as a stand-alone client, it is the worst possible choice. Whatever security holes it has are minor compared to Outlook, but I would chose a well-configured Outlook over client only Notes. This does not change the fact that Notes and Domino can do wonderful things.
  • Calypso ( http://www.mcsdallas.com ) is the best I have ever found. Easily supports multiple email accounts, and has lot of features. You can get the full version for 30 days I belive before it turns into Calypso Lite which still has alot of features. Of course I loved it so much I bought it.

    -
  • There is a plugin that integrates Netscape Messenger with PGP, unfortunately, there is a catch (isn't there always?): it's only available for Windows. Maybe some kind hacker out there can take a look at this program and come up with something functionaly equivalent for Linux.

    You can find it's homepage at Bear Software [freeservers.com].

    It's another option if you are comfortable with Netscape and just want to quickly fire off an encrypted message.

  • I've been looking at Windows mail clients lately. The best I've found is Pocomail http://www.pocomail.com/

  • by MrEfficient ( 82395 ) on Sunday July 30, 2000 @04:38AM (#895021)
    I don't expect to change your mind about outlook, but I think a few things need to be mentioned about security. I think the two main reasons people have problems with outlook is because they don't make use of the security settings and they don't keep on top of updates and patches. These are two things you have to keep on top of with any program, not just outlook. Remember the latest problem with FTP, even OpenBSD suffered from that.

    There is a setting in outlook which tells it to use the "Internet Zone" security setting. This should be the default but I don't think it is. This is what I have my Outlook security set to. You also have to adjust the "Internet Zone" settings to not allow scripting of any kind. I suspect that if everyone had the correct security settings, the Melissa and ILoveYou viruses would never have caused any damage whatsoever. I'm not saying that outlook is perfect (Scripting in email is a dangerous thing and should be turned off by default) but I think it gets a bad rap because its from Microsoft. Remember, basic security principles must be followed no matter what program or OS you're using.

    PS: One advantage of Outlook, is that it integrates fairly easily with PGP. Eudora also does this. One note about Pegasus, we have it at work and its the ugliest most user unfriendly email program I've ever used. And this is coming from a person whose first email program was Pegasus.

    ----------
    AbiWord [abisource.com]: The BEST opensource word processor

  • As I recall the "Internet Zone" has scripting enabled, I suppose because MS thinks everyone wants a "rich internet experience."

    I use the "Restricted Sites Zone" in Outlook 98, which has more "safe" things enabled by default, but I still had to turn off Javascript, VBscript, and other crap by hand.

    sulli

And it should be the law: If you use the word `paradigm' without knowing what the dictionary says it means, you go to jail. No exceptions. -- David Jones

Working...