4 ms·
According to this: https://en.wikipedia.org/wiki/Comparison_of_mail_servers https://en.wikipedia.org/wiki/Comparison_of_mail_servers qmail doesn't support SMTP
by featherverse 9y ago
According to this: https://en.wikipedia.org/wiki/Comparison_of_mail_servers https://en.wikipedia.org/wiki/Comparison_of_mail_servers
qmail doesn't support SMTP over TLS or SSL. How is that "secure"?
- czep 9y agoSecurity of an email server has nothing to do with secure transport of emails. If you run qmail, nobody will ever root your server. Sure they'll be able to intercept and read your email, but they won't root your server! I did run qmail in 1998ish and it was quirky but rock solid. But that was coming from sendmail, which I'd never recommend. Now I'd say postfix is the way to go: quite secure and fully TLS capable.
- geocar 9y agoWell, if you sent an email to `|program` it didn't execute program. Seriously[1] [1]: https://www.tenable.com/plugins/index.php?view=single&id=10261 https://www.tenable.com/plugins/index.php?view=single&id=102... Indeed, many sysadmins of the time lauded qmail's lack of supporting "standard features" in the name of "security" which sadly was still a new concept on the Internet. Something to consider: SMTP over TLS offers some privacy and confidentiality between two mail servers that have established a trust relationship, but it offers no protection against an upstream network (who can simply fake some DNS records and get a letsencrypt certificate) or a state actor (who simply threatens the CA). I think referring to "SMTP over TLS" as "secure" is dangerous because it leads us to equate "more code" as providing security.
- ktRolster 9y agoTruly, the only way to have security is to encrypt the message with the receiver's public key.
- featherverse 9y agoI find it discouraging that it's almost 2018 and this function of E-mail has not been made standard in all clients yet. I understand the concerns about trust, but why not make trust the extra step for now, and make encryption the standard. And in time we can standardize trust as well. (I know it's pretty standard already but I'm thinking about 'the average user') "Well I can't trust the source so why bother with encryption" is what we have presently, and that's just ridiculous.
- geocar 9y ago"What's your email address" is about 90-120 bits of information -- a long way from the 2000-5000 bits that are in a public key. I figure if we solve this problem then we can make encrypting email the norm.
- JdeBP 9y agoWikipedia is misleading again. Notice that there are no sources for any of the claims made about several of the softwares, to check the article against. qmail does not, strictly speaking, even support SMTP over TCP. This is because it relies upon UCSPI tools to do the actual transport layer setup. UCSPI-TCP does the TCP part for qmail. And one can equally well layer it over UCSPI-SSL. People did. Erwin Hoffmann, one of the UCSPI-SSL authors, even wrote a lengthy article on the subject of SMTP over TSL/SSL with qmail. * http://jdebp.eu./FGA/UCSPI.html http://jdebp.eu./FGA/UCSPI.html * http://www.fehcom.de/qmail/smtptls.html http://www.fehcom.de/qmail/smtptls.html