3 ms·
I agree with much of the others commenting here. The IETF strict transport security draft is ridiculous. If every carrier who passes the message can #1 read it
by rubyfan 11y ago
I agree with much of the others commenting here. The IETF strict transport security draft is ridiculous. If every carrier who passes the message can #1 read it and #2 potentially change the content and #3 promiscuously route messages to each other then why does it really matter if they pass it amongst themselves securely? Line security is easily defeated by other 'features' of SMTP.
End to end encryption is the only thing that will really matter in email security. And even with end to end encryption email is a flawed medium, since it leaks meta data in the process of message delivery. That is kind of a barrier to secure messaging.
- azinman2 11y agoBecause if you trust your email provider(s) then big baddies can't manipulate it. It's about improving the threat model, not "solving it." Basically it cuts off the easiest attack angles from very sophisticated hackers and governments.
- sliverstorm 11y agoLine security is easily defeated by other 'features' of SMTP. I'm not enough of an SMTP/security guru to know what you're referencing. I'm curious, can you share?
- rubyfan 11y agoTLS Cipher downgrade and DNS weakness. SMTP and almost every protocol out there whether SSL/TLS enhanced are designed for least common denominator interoperability and legacy compatibility. SMTP and really email as we know it is inherently insecure. Without end to end encryption and relying on hosted mailboxes, we're inviting "service providers", government and hackers alike to read and tamper with our email.