Re: [Imap-protocol] STARTTLS after PREAUTH

Bron Gondwana <[email protected]>
Newsgroups gmane.mail.imap.general
Message-ID <[email protected]>
On Wed, Mar 19, 2014, at 12:39 PM, Lyndon Nerenberg wrote:
> On Mar 18, 2014, at 5:04 PM, Bron Gondwana <[email protected]> wrote:
> 
> > I can't understand how STARTTLS ever got floated as an idea.  It's totally insane.
> 
> Damn you and your 20/20 hindsight!  Care to lend us your waybac machine?  :-)

So why is 993 deprecated rather than STARTTLS deprecated now?  STARTTLS is _still_ a bad idea.

We don't need a wayback machine to fix the future.

> Anyway, if you think STARTTLS is horrific, you really don't want to know about the adventures surrounding the early implementations of AUTH ...
> 
> The bottom line is that breaking every existing IMAP client and server wasn't a practical way to move forward.  And the various authentication bits in IMAP rolled out just at the end of the 'naive' age of the 'we are all friends' internet.  They were (are) incremental improvements to the situation as it existed.  Breaking existing clients/servers was not an option.  The best you can hope for is to offer better alternatives, encourage adoption, and hope attrition eventually solves the problem.
> 
> Which it never will, but almost two decades after the fact, anyone using, or inflicting upon someone, an IMAP client that blindly issues LOGIN is perhaps deserving of their fate.  C'est la vie.

Sadly, they're still out there - which is why FastMail doesn't allow port 143 at all.  Port 993 appears to be working in the real world[tm].

I'd be interested in seeing the actual stats for which clients can be convinced by a MITM to give up their credentials in plaintext in their default configuration.  Don't give me a checkbox which requires the user to actively increase the security level, because that won't work.  In fact, don't even give the user a dialog which allows them to send the password insecurely, because they will.

Not responding to a SYN on port 143 with an ACK...

Bron.

-- 
  Bron Gondwana
  [email protected]
_______________________________________________
Imap-protocol mailing list
[email protected]
http://mailman13.u.washington.edu/mailman/listinfo/imap-protocol
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.