Re: Man In The Middle Attacks and STARTTLS

Paul Hoffman / IMC <[email protected]> Thu, 15 Apr 1999 14:33:26 -0700
Newsgroups gmane.ietf.apps-tls
Message-ID <[email protected]>
At 02:01 PM 4/15/99 -0700, Dan Wing wrote:
>I think you can protect against this attack, but you do need to describe
>how in the security considerations section.
>
>To protect against the MITM attack you describe below, the client needs to
>treat "454 TLS not available due to temporary reason"  exactly the same as
>a missing "250 STARTTLS" from the EHLO response.

That's my conclusion. It also means that watching for the lack of "250 
STARTTLS" doesn't buy you anything.

--Paul Hoffman, Director
--Internet Mail Consortium