RE: Man In The Middle Attacks and STARTTLS

Dan Wing <[email protected]> Thu, 15 Apr 1999 17:11:01 -0700 (PDT)
Newsgroups gmane.ietf.apps-tls
Message-ID <[email protected]>
On Thu, 15 Apr 1999 16:20 -0700, Paul Hoffman / IMC wrote:

> At 03:54 PM 4/15/99 -0700, Scott Roberts (Exchange) wrote:
> >Bodo, your points are good. I would think that it is better to state that a
> >reasonable amount of time SHOULD pass before the message is returned to the
> >sender rather than stating a default time because of issues that might arise
> >in the future.
> 
> You are only seeing two options: use TLS or return to sender. The third 
> option, which I think will get used much of the time, is send anyway. That 
> is, various client-server pairs with lots of cycles to spare might be 
> willing to use STARTTLS to encrypt because it only causes a second or two 
> delay and, hey, why not. If TLS isn't available, they'd send the mail anyway.

I know STARTTLS has progressed beyond what I'm about to propose, but I'll
propose it in any event:

Why not use a technique similar to the DELIVER-BY extension where the
sender indicates their wishes ("Send NDN if you can't comply with my
wishes") instead of relying on the configuration or implementation of MTAs
along the message path?

-Dan Wing