I guess the only way we will know that is if there’s ever a vulnerability in the session handling code of the mail server that they use also xD