Thanks again for the reply, Faris.
Your first reply stirred some further thought. If webmail is just another piece of IMAP client software, then the insecurity lies within IMAP, not the webmail client. IMAP accounts can thus also be tried over and over again without any lockout or retry...
Thanks, Faris, for the explanation.
That means that webmail is basically a very insecure option. Anyone can script into an account because there's no limit on the number of retries; it's just a matter of time (and of choice of strong or weak passwords).
Is this something that is being...
Hello,
I am looking for answers to know whether password policies are adjustable in the Horde webmail module. I noticed that the server options available via the web interface do not include a lot, I wanted to know if a maximum amount of password retries could be configured, as well as a...