3 ms·
Why is it a hack job? I would say it’s patching a hole, and it’s the feasible way to make email secure, rather than throw it all out and convince the world to
by sorbits 13y ago
Why is it a hack job?
I would say it’s patching a hole, and it’s the feasible way to make email secure, rather than throw it all out and convince the world to switch to a new system.
Most (internet) standards evolve this way. That’s the curse of evolving a standard that is already in widespread use.
- harrytuttle 13y agoThe hack job comes from the fact that it's not universal, nor does it provide a holistic solution. It is literally a sticky plaster. The problem is that sometimes standards are no longer fit for purpose on multiple levels. At this point, migration is required to new standards. This does happen quite regularly. Look at IPv4 to IPv6. The change should be of the same magnitude. We've done this before. First UUCP, then SMTP, then XYZ.
- balabaster 13y agoMostly because it rests on CA's and if the government can compel the CA to give them a signed cert for something that your security relies on, all they have to do is pose a MITM attack and you're blissfully clueless that they're spying on you. The whole system is broken and if you don't fix the foundations upon which your house is built, no amount of band-aids are going to keep the walls standing.
- kyrias 13y agoNo, with DANE nothing rests on CA's. With DANE domain owners store their keys in the DNS, and the DNS records are signed with DNSSEC