3 ms·
Statistically, someone, somewhere, has a VAX box that hasn't been rebooted since before the fall of the Soviet Union, running their org's MTA with a comically o
by DaiPlusPlus 1y ago
Statistically, someone, somewhere, has a VAX box that hasn't been rebooted since before the fall of the Soviet Union, running their org's MTA with a comically outdated cryptosuite. Anyone running vaxen that old is bound to be a regular here on HN.
- Meekro 1y agoUnfortunately, that box is going to have increasing difficulty connecting to anyone at all. TLS 1.2 was added to OpenSSL around 2010, and de-facto mandated around 2020. Any SSL/TLS software from before that will increasingly find its connections rejected.
- jeroenhd 1y agoThe world of email is full of zombie servers that should've died years ago but still linger. Configuring your email server to require the security that was considered "modern" ten years ago in terms of websites will still get you delivery failures when you start dealing with email servers. There's a reason Google is deprecating 3DES now, and not ten years ago when they reasonably should've. Because email customers on all sides want email to arrive, there's little incentive to modernize configurations or requirements. When you disable ancient cryptography, you'll get blamed for your change making email from someobscurewebsite.gov no longer arriving. For a significant amount of mail servers, you can pick between "accept a random self-signed certificate using a cipher suite from the late 2000s" or "send email over unencrypted SMTP", and you just have to hope that the email server doesn't have your domain configured as "secure transmission required". I'm in favour of Google just breaking the old, broken mail servers, but I wouldn't assume that TLS 1.2 is available on email servers.