oss-sec mailing list archives
Re: STARTTLS for this list?
From: Seth Arnold <seth.arnold () canonical com>
Date: Thu, 11 Feb 2016 18:05:26 -0800
On Thu, Feb 11, 2016 at 04:05:53PM -0500, Alex Gaynor wrote:
Not sure if anyone saw, but gmail has been rolling out UI indicators for MTAs which don't use TLS: https://gmailblog.blogspot.com/2016/02/making-email-safer-for-you-posted-by.html
This seems like shouting at the wrong person about a problem they can't address. What is the average gmail user supposed to do with this information? While it draws a parallel to the lock icon in browsers to indicate HTTPS is used I think this overstates how "secure" an email is just because it was sent over one hop using STARTTLS. If Google actually feels STARTTLS is important enough to users to show them an icon then they should use this as step one and announce step two is requiring STARTTLS on a specific date. That only works, of course, if they announce their intention _and_ a date.
I was surprised to see this indicator on mail from oss-security. Does anyone know who has the keys to `list.openwall.com` so they can turn on STARTTLS for outbound email?
That'd be "listadmin [at] oss [dash] security [dot] openwall [dot] org" http://oss-security.openwall.org/wiki/mailing-lists/oss-security Probably Alexander. :) It doesn't seem like a top priority to me: STARTTLS solves one set of problems and introduces a much larger set of problems. I'm not sure any of the solved problems are actually pressing problems to a public mail list. Hosting a mail list is already miserable enough (for example, I don't think mail From: google addresses actually makes to Google users; also, I don't know how the moderators manage to keep this list spam-free with zero mistakes, either false positives or false negatives.) -- adding a half-dozen more reasons why mail delivery can fail is surely not fun. Thanks
Attachment:
signature.asc
Description: Digital signature
Current thread:
- STARTTLS for this list? Alex Gaynor (Feb 11)
- Re: STARTTLS for this list? Noel Kuntze (Feb 11)
- Re: STARTTLS for this list? Seth Arnold (Feb 11)
- Re: STARTTLS for this list? Solar Designer (Feb 11)