Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> different users who are not, for a myriad of reasons, in a position to upgrade their software stack to TLS.

These people, who I am not convinced exist in 2019, would also be left behind by MTA-STS, which still requires participation in the commercial PKI pyramid of trust, TLS connections and all. What makes you think an entity that cannot tls-wrap their mail service can instead rewrite the mail service to issue web requests, parse the responses, and then reconfigure their MTA on the fly for each response?

Deprecating plaintext messaging is a perfectly achievable goal, and there's no real effort in the IETF to do so because every such effort is drowned at birth by the bizarre "just do everything over HTTPS" phalanxes.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: