4 ms·
Yeah, so I guess there's no point in picking any of the low hanging fruit to make it more secure.
by xmodem 2y ago
Yeah, so I guess there's no point in picking any of the low hanging fruit to make it more secure.
- sam_lowry_ 2y agoEmail is actually quite secure, just in a different way that web. For instance, once you disregard so called transactional mail and spam, real email is almost all encrypted for all practical purposes. DKIM and DMARC also work quite well for spoofing protection, aside from the corner cases like the above. Average Software Engineers have an outdated idea of email, formed by 1990 era Internet.
- tredre3 2y agoI think your view of email is romanticized, or perhaps skewed because of your social circle. Email servers sometimes use TLS to talk with eachother, and emails are signed. But that's the extent of encryption when it comes to "real email". Email content is not encrypted in "almost all" of "real email" because almost nobody uses PGP.
- sam_lowry_ 2y agoI don't know what social circle I should be part of to consider email unsecure. Even Russian spies use mail.ru and their emails are compromised not by SMTP MitM but by weak passwords, google for "moscow1 moscow2 password" to see what I am talking about ) Anyway. Back to the technical point. Email servers pretty much always use TLS to talk to each other. The connection may degrade to non-encrypted for backwards compatibility, unlike HTTPS. But it's vanishingly rare. So, for all practical purposes that affect ordinary citizens: injection, scanning and sensitive information extraction, email in transit is quite secure.
- bell-cot 2y agoDepends on context. If you're in IT at a carefully run org: You ditched 512-bit keys years ago. This article is nothing but a 20-second story, to help explain to PHB's and noobs why they got an error message, or what sorta important stuff you're always busy keeping your org safe from. If you're in IT at a scraping-by org: Maybe today's a good day to ditch 512-bit keys. And if you get push-back...gosh, here's a how-to article, showing how a "forged corporate signature stamp" can be made for only $8. If you're trying to teach senior citizen how to avoid being scammed on the internet: You've got zero visibility or control, so you're stuck with "sometimes these can be forged, depending on technical details" generalities.