Giorgio, will you please forgive me if I unlock it just enough to get back *on* topic, since I use Yahoo mail?
therube wrote:Yahoo works without allowing yahoo.com. (I use Yahoo "Classic" version.) yimg.com is allowed. Not sure if it is actually needed or not.
I also use Classic Yahoo. (Warning: if you accept the invitation to "upgrade" to New Improved, it's irreversible, according to their fine print. Instructions on staying with Classic "will be posted soon" on their Help page.)
You can restrict the yimg.com to merely mail.yimg.com, depending on how much graphics you like. I prefer almost none.
yahooapis.com is annoying, with the "user status" (online/offline), the status of your contacts, etc. It can be left default-deny, then only temp-allow for tasks that need it, such as editing contacts list, certain account preferences/profile etc. It's off 99+% of the time when I'm in e-mail. "If you don't need it, don't let it run."
The guest who pointed out the dangers of single-sign-on effectively makes the argument against this security-vs-convenience tradeoff. Use separate IDs for each function. The Wikipedia link had Bob storing a bank login cookie on his machine. Terrible. Storing login cookies leads to precisely this danger. Session-only cookies for *everything*, and never have another browser window or tab open while doing banking or other sensitive activities.
If this is overwhelming,
Password Safe is a free, open-source tool that will generate strong passwords, store them for you securely (encrypted) *on your own machine*, not on someone else's server, browse to the site for you, and auto-type your login creds, if you like. Very compact, and the encrypted password file is only 10-20k, for easy backups. Can be put on USB flash and taken with you, without leaking data to the host machine. Disclaimer: I have no connection to Password Safe. My experience and opinion only. Use at your own risk.
Plus the ABE rules that Giorgio so kindly gave us.
Again, Giorgio, I hope you find the above information relevant enough to the topic of webmail security to forgive my adding this. Re-locking.