This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Scan SSL email?

I recently contacted support for two paid programs:  ESET and Bitdefender, and they both told me that their programs do not (cannot) scan inside SSL IMAP email (e.g., email received in my Mac Mail App from my Gmail account via SSL).  Wondering whether Sophos does.  Can't find any info on the web site.  (I was sort of surprised about ESET and Bitdefender, since they're highly rated and cost a lot.)

:1021028


This thread was automatically locked due to age.
Parents
  • Hello 593michael,

    programs do not (cannot) scan inside SSL IMAP email [...] I was sort of surprised

    one of the purposes of TLS (and its predecessor SSL) is to ensure message confidentiality and thus another program can't (in fact mustn't be able to) scan the data stream. It's not entirely impossible to intercept the traffic (if you are interested in the details and their implications please see Lenovo "Superfish" controversy on nakedsecurity). Otherwise the mail client would have to allow a plugin to access - and potentially modify without breaking the application - the unencrypted datastream.

    Christian

    :1021032
Reply
  • Hello 593michael,

    programs do not (cannot) scan inside SSL IMAP email [...] I was sort of surprised

    one of the purposes of TLS (and its predecessor SSL) is to ensure message confidentiality and thus another program can't (in fact mustn't be able to) scan the data stream. It's not entirely impossible to intercept the traffic (if you are interested in the details and their implications please see Lenovo "Superfish" controversy on nakedsecurity). Otherwise the mail client would have to allow a plugin to access - and potentially modify without breaking the application - the unencrypted datastream.

    Christian

    :1021032
Children
No Data