4 ms·
Yet another superb reason not to run your internal company comms on a publicly accessible email server. Or to replace email for internal use altogether. TMTP i
by networkimprov 6y ago
Yet another superb reason not to run your internal company comms on a publicly accessible email server.
Or to replace email for internal use altogether. TMTP is a new protocol with that goal:
https://mnmnotmail.org/ https://mnmnotmail.org/
https://twitter.com/mnmnotmail https://twitter.com/mnmnotmail
- closeparen 6y agoYou can publicly expose an SMTP relay while keeping Exchange itself private, right?
- EvanAnderson 6y agoAbsolutely. The parts of Exchange that got exploited are exposed because people want ActiveSync on their phones and web-based email. If you did without on those, or ran them over a VPN, just having SMTP exposed didn't make you vulnerable to this. Hardly anybody does that, though.
- Spooky23 6y agoYes totally. Most of the people running exchange now with this issue are cheapskates or attorneys. If defense contractors keeping exchange on prem for security/compliance reasons are offering OWA on the internet, obviously there’s a deeper problem.
- xbar 6y agoMy Exchange server avoided this mess by living in this state.
- bjarneh 6y ago> As more sites adopt TMTP for their own reasons Isn't this the problem in replacing almost any technology that we know is "broken", it is often too ingrained to be replaced easily.
- networkimprov 6y agoConsider the huge variety of messaging and discussion apps; it's relatively easy to embrace new communication tools. EDIT: you might never silence SMTP altogether, but a suitable protocol could supplant it for the great majority of its use cases.
- zerkten 6y agoYou can embrace new tools and replace the old new tools. What you generally aren't able to do is to replace email not matter how hard you try. The appearance of email being replaced exists in some places, but you find pretty quickly that you can't survive without it because it's still getting used for some critical communication or process.
- bjarneh 6y ago> What you generally aren't able to do is to replace email not matter how hard you try. The "new" email has been launched quite a few times now. It doesn't seem possible at this point unless all the major players agree on some new protocol which is seamlessly implemented in their mail services, while still allowing SMTP to function as a fallback to the improved protocol
- networkimprov 6y agoReferences? I'm not aware of any alternative email protocol that's implemented, except TMTP. I don't believe closed-source, walled-garden services, which don't allow third-party clients or servers, really count as legitimate alternatives. There's Matrix, but that's a synchronization protocol for chatrooms, not a store-and-forward messaging scheme.
- bjarneh 6y agoDMTP/DMAP https://en.wikipedia.org/wiki/Dark_Mail_Alliance https://en.wikipedia.org/wiki/Dark_Mail_Alliance The stuff Ladar Levinson created after the Lavabit takedown, (famed for begin Snowden's email provider). Although I'm not just talking about email protocols; but additions or other improvements that always have the same problems (PGP encrypted email, or whatever Facebook tried to do when they reinvented email...)
- shoo 6y agoI reckon that a new mail protocol with use cases of excluding unwanted communications may find it harder to gain adoption. It's like an anti-viral quality. I could see this being rolled out within an org where the one org can deploy clients & server to all internal users at once.
- adolph 6y agoWho needs a whole new protocol? Just type at each other with netcat. https://www.digitalocean.com/community/tutorials/how-to-use-netcat-to-establish-and-test-tcp-and-udp-connections-on-a-vps https://www.digitalocean.com/community/tutorials/how-to-use-...