3 ms·
STARTTLS and its ilk are what happens when technology companies (& their minions) are pussies. It has been clear for decades that secure e-mail transport would
by throwaway20371 5y ago
STARTTLS and its ilk are what happens when technology companies (& their minions) are pussies. It has been clear for decades that secure e-mail transport would be a good idea, but not if we had to actually upgrade software / systems to get it. This bullshit is so endemic that Google Mail has actually released two new standards in 2019, that depend on two other protocol stacks, just to advertise to SMTP servers that they support secure mail.
Thankfully, in 2018 someone had the balls to release RFC8314, which explicitly obsoletes cleartext for MUA <-> MSS <-> MAS mail. So why did Google release standards in 2019 that presume that some servers still won't talk TLS? My guess is they're terrified someone won't send them mail, and they'd lose some of that sweet sweet analytics money.
We clearly have an endemic problem in our technology culture related to breaking changes in order to fix shit. This is going to keep happening, unless we come up with new industry principles and practices to enforce breaking upgrades of legacy systems. If your system doesn't have a sunset date of less than 8 years, it should be considered broken out of the box. If it doesn't expect major feature overhaul after 4 years, it should be abandoned in favor of a system that does. Not having zero-downtime upgrades and rollbacks should be a non-starter too. Basically we need a "12 factor app" for protocols and systems.