Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
danmarg
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
danmarg
10y ago
But the private key is (of course) never sent to GitHub, so it's hard for me to imagine what kind of vuln this would help with. I can think of a few, but they're odd: 1. Some sort of remote memory leak that leaks the current priva
2.
▲
by
danmarg
11y ago
Is the mailer-daemon message from @googlemail.com or from recipient domains?
3.
▲
by
danmarg
11y ago
But I think the authentication problem is in fact the hard problem. Assuming we got rid of STARTTLS (the actual verb) and just always did TLS (say, on some other port), how do you propose to solve it?
4.
▲
by
danmarg
11y ago
If you required TLS on all SMTP, you would in fact end up having to fail a large number of messages. Even worse, of the domains that support STARTTLS, a sizable number either don't present certificates that chain to a widely trusted ro
5.
▲
by
danmarg
11y ago
I don't think the use of a single port is really at the heart of the problem. Even if SMTP with TLS ran over port 26 (say), you wouldn't know if a timeout on port 26 meant the server wasn't listening on port 26 or a MITM had