Ask HN: How can you trust non open source, third party email clients? I might be over paranoid and correct me if wrong but as far as I understand, almost all the email clients out there either store your credentials or the access token to be able to send you push notifications for new emails. Once they have the credentials/token, they have full control over your emails, what happen if they get compromised or they leak your data? Even 2FA will not protect you in this case since you already give them the auth token after a successful 2FA auth, or a specific app password. Considering the email is used to reset almost all other accounts passwords, how can you trust a third party email clients? Am I missing something? Thanks. |