4 ms·
> Today’s email protocols use the STARTTLS protocol for encryption; it is laughably easy to do a protocol downgrade attack that turns off the encryption. This
by imrejonk 5y ago
> Today’s email protocols use the STARTTLS protocol for encryption; it is laughably easy to do a protocol downgrade attack that turns off the encryption.
This can be solved with DANE, which is based on DNSSEC. When properly configured, the sending mailserver will force the use of STARTTLS with a trusted certificate. The STARTTLS+DANE combination has been a mandatory standard for governmental organizations in the Netherlands since 2016.
- philosopher1234 5y agoIs DANE @tptacek approved of? You say DNSSEC and it triggers my internal alarm bells.
- tptacek 5y agoNo, DANE is very bad. But it's a dead-letter standard, so I don't worry about much.
- AndyMcConachie 5y agoYou think no one is deploying DANE for SMTP? https://stats.dnssec-tools.org/images/domains.svg https://stats.dnssec-tools.org/images/domains.svg It's deployed on many more domains than MTA-STS.
- tptacek 5y agoOf course it is. There are only a couple of email providers that actually matter, but out in the long tail of domains that might never receive a single non-spam email, there are plenty that are auto-signed by registrars. It's telling that's the best evidence you have, and not, like, "Google Mail uses DANE".
- teddyh 5y ago