3 ms·
If anything, a spammer or phiser has more motivation to deliver their mail over TLS because of this development, compared to some legitimate host. Whether the m
by andreasvc 11y ago
If anything, a spammer or phiser has more motivation to deliver their mail over TLS because of this development, compared to some legitimate host. Whether the mail was delivered via TLS provides no information on its legitimacy. That is why it is problematic that it could give a false sense of security.
- Karunamon 11y agoGetting the internet as a whole away from plaintext is more important than dealing with MITMs - you may or may not be subject to a MITM attack at any given time, you absolutely are subject to passive surveillance at all times. Don't let the perfect be the enemy of the better.
- AnimalMuppet 11y agoDepends on your threat model. Which do you consider more of a threat to you, the NSA or a corporate competitor who hired a black hat for some espionage? Whichever answer you give, there will be people to whom the answer is the opposite. It's not that they're being obtuse - that really is the answer for their situation. > Don't let the perfect be the enemy of the better. Think both/and, not either/or.
- deleted 11y ago[deleted]
- Karunamon 11y agoThis isn't a zero sum game. Removing the ability for people to passively spy on you doesn't mean you can't add MITM protection later. Having everything be encrypted by default is strictly more secure. There's no reason to avoid taking the first step in fear of the second one.
- jorangreef 11y agoIt actually can be zero sum. Solve the problem with a poor 50% solution which most people can't understand, and you may be stuck with it for another 20 years.
- andreasvc 11y agoI would encourage anyone to use TLS. However, I take issue with using it as an indicator of the trustworthiness of the sender or its host.
- scintill76 11y agoIt looks like Gmail is only adding a warning for non-TLS deliveries, not a green padlock (or whatever) for TLS deliveries. I'd be more worried about your point in the latter case. There are other systems in place (SPF, DKIM, DMARC) to identify fake mails.
- brobinson 11y agoMy guess is that they will simply start using free SSL certs from StartSSL or LetsEncrypt. Edit: reading the thread more, I guess it depends if they're actually gonna authenticate the certs: https://news.ycombinator.com/item?id=10556544 https://news.ycombinator.com/item?id=10556544