re: New version of TLS + IMAP/POP/ACAP draft

"Randall S. Winchester" <[email protected]> Sat, 28 Nov 1998 02:38:12 -0500 (EST)
Newsgroups gmane.ietf.apps-tls
Message-ID <[email protected]>
On Fri, 27 Nov 1998, Mark Crispin wrote:

: Like it or not, people are going to assume that SASL is safe, just as they
: assume that LOGIN/PASS are unsafe.  The standards-track form of SASL must
: be safe.  What's done in non-standard SASL is irrelevent.

If this is not the case, or the design, then why bother. The IETF must have
a strong stance on security. There is no reason to go forward with STARTTLS,
for anything, unless its' design is as trustworthy as the current dedicated
ports it is trying to superceed.

This should be very clear in everyones' mind. I hope I am stating the
obvious.

Randall