SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Technology Stocks : Qualcomm Incorporated (QCOM) -- Ignore unavailable to you. Want to Upgrade?


To: lkj who wrote (33821)7/1/1999 4:31:00 PM
From: Scott Overholser  Read Replies (1) | Respond to of 152472
 
you are completely correct in this:
1. the user must login to the exchange server.
2. the exchange server must be exposed to the internet.

keep this in mind:
1. there are many new and promising secure authentication protocols that are finding application.
2. existing secure authentication protocols provide good security. two examples are ntlm (windows nt/lan manager) and kerberos (developed at mit i think.) only ntlm is supported out of the box by exchange and windows nt. windows 2000 will support ntlm and kerberos. there are prolly 3rd party packages also.

bottom line is that this arrangement is no less secure than the services provided by a multitude of online services today - online trading, e-commerce, etc...

I was worrying over security, because I thought that a user must log on to an Exchange server to access his Email. This logon would also be done over the Internet, which means the Exchange server must be open up to the Internet.