oss-sec mailing list archives

Re: STARTTLS for this list?


From: Solar Designer <solar () openwall com>
Date: Fri, 12 Feb 2016 05:30:31 +0300

On Thu, Feb 11, 2016 at 06:05:26PM -0800, Seth Arnold wrote:
It doesn't seem like a top priority to me: STARTTLS solves one set of
problems and introduces a much larger set of problems. I'm not sure any of
the solved problems are actually pressing problems to a public mail list.

That's my current feeling, too - for this mailing list at this time.

Hosting a mail list is already miserable enough (for example, I don't
think mail From: google addresses actually makes to Google users;

You're right - as discussed before, it does not, because of DMARC.
(This applies to senders from google.com and some other Google domains,
but luckily not yet to senders from gmail.com.  However, recipients at
gmail.com are also affected whenever someone posts from google.com.
Also, Yahoo's free e-mail and a few others are affected.)

Working around this is actually planned (especially as Google intends to
extend this to Gmail senders).  STARTTLS currently is not.

also, I
don't know how the moderators manage to keep this list spam-free with zero
mistakes, either false positives or false negatives.) --

It's a combination of scripting and manual message moderation.  There
are occasional mistakes (I posted about a badly delayed wrong-charset
message not so long ago), but they are few (at least that I'm aware of).
I think we manage pretty well, considering that most messages arrive to
the list within minutes.

adding a half-dozen
more reasons why mail delivery can fail is surely not fun.

Right.  And supporting TLS, even if only client-side, also adds to the
server's attack surface.  That said, we might be forced to, eventually.

I am actually in favor of opportunistic encryption in general.

Alexander


Current thread: