3 ms·
They talk about privacy, but MTAs like Postfix can already encrypt mail via TLS when moving it to another host¹. GPG gives us a better guarantee, but more user
by sorbits 13y ago
They talk about privacy, but MTAs like Postfix can already encrypt mail via TLS when moving it to another host¹. GPG gives us a better guarantee, but more user overhead, and unreadable by many recipients.
Additionally SPF gives us a way to check if the sender address has been forged. GPG signing is more robust, but again, more user overhead.
Not to mention, I already have S/MIME support in my mail application and can get GPG support via a plug-in, but I use neither, because few recipients can handle it.
So what is new with Mailpile? What is it supposed to change?
In my opinion, if the goal is to make email more secure, we should look into ensuring that all MTAs is setup to support TLS and use it when delivering mail to other hosts (AFAIK Exim4 only announces STARTTLS when connecting to its submission port).
Getting SPF records setup would also be a plus.
This would go a long way in making email more secure, and only requires action from administrators of mail domains.
¹ http://www.postfix.org/postconf.5.html#smtp_tls_security_level http://www.postfix.org/postconf.5.html#smtp_tls_security_lev...
- alextingle 13y agoExim can announce TLS to all comers. Set the tls_advertise_hosts option to '*'. (I believe Debian sets this by default.) http://www.exim.org/exim-html-current/doc/html/spec_html/ch-encrypted_smtp_connections_using_tlsssl.html http://www.exim.org/exim-html-current/doc/html/spec_html/ch-...