Skip to content

Comment on ETacts (YC W10) will help you manage your relationships

Comments

  (Why this is safe)
We use the latest in bank-level 256-bit SSL encryption to protect your information, and your passwords are securely encrypted.

Etacts will never email your contacts without your permission.

Your data is completely private and will not be shared with other users.

To help you keep track of who you haven't spoken with, we fetch your email headers. We don't store the content of your emails or attachments. When you view an email in etacts, we fetch the email directly from your Gmail server and don't store it on our servers.

Uh. Hey, Etacts. Are you storing my password long term or not? That's my question. Glad you're doing the bank security encrypty thing. But you can't keep my Gmail password.

we do keep your gmail password, but you have the ability at any time to delete your gmail password or your entire etacts account. We will try to make this more clear, thank you for the feedback.

Just throwing a thought out there: What about an option that allows people to use etacts without storing their password. So every time a user wants to "refresh" their data, they would have to re-enter their password.

The security advantages are limited– the password has to go through you guys either way– but there may be a difference psychologically.

I don't think mail2web would be as widely-used if they didn't have a policy against storing passwords.

this is a good idea, we'll talk to our users and see if this is a wanted feature.

It won't be. Don't bother.

You can't convince people like me to give you a gmail password. It's simply not going to happen.

Meanwhile, you could convince my mom to give up her gmail password with an animated GIF of a cartoon padlock.

What we can help you with here is how to communicate about security without setting off alarm bells. Your security page isn't awful; "bank security" is a security idiom, it's fine that you use it. But we can help you make it better. Make it clear that you're storing passwords so nobody can say they're surprised about, and make sure security researchers know how to contact you.

Yeah, that little notice didn't really inspire much confidence for me. The biggest question is whether you trust them with your email & password, but unfortunately there's not much they can do to alleviate this fear.

I thought you were going to go on one of your rants about how encrypting passwords is useless .. with which I happen to agree, btw.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.