Boston Linux & UNIX was originally founded in 1994 as part of The Boston Computer Society. We meet on the third Wednesday of each month, online, via Jitsi Meet.

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] Discuss Digest, Vol 85, Issue 20



On 6/27/2018 4:38 PM, Rich Braun wrote:
> So? In order for anyone to mount a successful attack on my email
> stream, they'd have to first find out that you're one of my
> correspondents and then (somehow) correlate the 1-in-10,000 chance
> that your properly-configured email server fails STARTTLS on a stream
> between your server and one in Toronto somewhere--with my identity.
> I'm totally cool with that.

Or I become a MITM and force all STARTTLS attempts to fail, which is not
hard at all if "I" control any of the backbone providers carrying the
traffic (STRIPTLS, for example). You can mitigate this by requiring TLS
for all SMTP connections but doing this is a self-inflicted partial
denial of service attack.

> There are lots of other first-world problems that keep me up at night
> but prying eyes no longer are, since that 2002 federal-case.

Exactly, sort of. I've long since accepted the fact that email is not
private. Maybe someday it will be private but for that to requires RFC
2821 to be overhauled (again) to require trustworthy encryption and for
that overhaul to become ubiquitous. I'm not holding my breath :).

-- 
Rich P.



BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org