oss-sec mailing list archives
Re: STARTTLS for this list?
From: Solar Designer <solar () openwall com>
Date: Fri, 12 Feb 2016 05:30:31 +0300
On Thu, Feb 11, 2016 at 06:05:26PM -0800, Seth Arnold wrote:
It doesn't seem like a top priority to me: STARTTLS solves one set of problems and introduces a much larger set of problems. I'm not sure any of the solved problems are actually pressing problems to a public mail list.
That's my current feeling, too - for this mailing list at this time.
Hosting a mail list is already miserable enough (for example, I don't think mail From: google addresses actually makes to Google users;
You're right - as discussed before, it does not, because of DMARC. (This applies to senders from google.com and some other Google domains, but luckily not yet to senders from gmail.com. However, recipients at gmail.com are also affected whenever someone posts from google.com. Also, Yahoo's free e-mail and a few others are affected.) Working around this is actually planned (especially as Google intends to extend this to Gmail senders). STARTTLS currently is not.
also, I don't know how the moderators manage to keep this list spam-free with zero mistakes, either false positives or false negatives.) --
It's a combination of scripting and manual message moderation. There are occasional mistakes (I posted about a badly delayed wrong-charset message not so long ago), but they are few (at least that I'm aware of). I think we manage pretty well, considering that most messages arrive to the list within minutes.
adding a half-dozen more reasons why mail delivery can fail is surely not fun.
Right. And supporting TLS, even if only client-side, also adds to the server's attack surface. That said, we might be forced to, eventually. I am actually in favor of opportunistic encryption in general. Alexander
Current thread:
- STARTTLS for this list? Alex Gaynor (Feb 11)
- Re: STARTTLS for this list? Noel Kuntze (Feb 11)
- Re: STARTTLS for this list? Seth Arnold (Feb 11)
- Re: STARTTLS for this list? Solar Designer (Feb 11)