5 ms·
IRC sure, but the big win is email.
by esmi 7y ago
IRC sure, but the big win is email.
- SXX 7y agoMajority of email traffic is by now for sure use s2s encrypted. Also considering how big major players are most of mail never leave Google / Microsoft / etc servers anyway and connections between them always only ever go over TLS.
- schoen 7y agoYou can get some statistics from Google at https://transparencyreport.google.com/safer-email/overview https://transparencyreport.google.com/safer-email/overview They're a lot better than I thought! (over 90% in each direction, although no data here about certificate verification and the presence or absence of backbone downgrade attacks) If you run your own mail service, check out my colleague's project at https://starttls-everywhere.org/ https://starttls-everywhere.org/
- esmi 7y agoI was just about to post the same link. Outside the US the numbers are a lot lower. Outbound to some countries is 0%. South Africa wasn’t in the report though.
- tialaramex 7y agoAlmost all of the SMTP over TLS will be opportunistically encrypted only and usually with pretty bad protocol / cipher choices. It probably means your email to your aunt isn't intercepted and shoved onto an enormous pile of decrypted email to be parsed for keywords. Probably. But that's about all. Against an adversary determined to intercept: - They can probably just strip STARTTLS, so that everything happens in plaintext - Even if they can't do that because of MTA-STS or similar, they can probably just present self-signed certs and it'll pass the mandatory checks - If they can't do /that/ either (no idea what proportion of email but it may well be in the minority) they can downgrade because unlike in HTTPS nobody is just saying "Old garbage bad, never do that or we'll scream" and so people keep doing it. SSLv3 may even work with a lot of mail servers. Still, what we have now with opportunistic SMTP encryption is equivalent to what you get with snail mail. The spooks CAN read anybody's mail, but it's a hassle so they mostly don't read yours.