Re: [Imap-protocol] STARTTLS after PREAUTH
Bron Gondwana <[email protected]>
| Newsgroups | gmane.mail.imap.general |
|---|---|
| Message-ID | <[email protected]> |
On Wed, Mar 19, 2014, at 12:39 PM, Lyndon Nerenberg wrote: > On Mar 18, 2014, at 5:04 PM, Bron Gondwana <[email protected]> wrote: > > > I can't understand how STARTTLS ever got floated as an idea. It's totally insane. > > Damn you and your 20/20 hindsight! Care to lend us your waybac machine? :-) So why is 993 deprecated rather than STARTTLS deprecated now? STARTTLS is _still_ a bad idea. We don't need a wayback machine to fix the future. > Anyway, if you think STARTTLS is horrific, you really don't want to know about the adventures surrounding the early implementations of AUTH ... > > The bottom line is that breaking every existing IMAP client and server wasn't a practical way to move forward. And the various authentication bits in IMAP rolled out just at the end of the 'naive' age of the 'we are all friends' internet. They were (are) incremental improvements to the situation as it existed. Breaking existing clients/servers was not an option. The best you can hope for is to offer better alternatives, encourage adoption, and hope attrition eventually solves the problem. > > Which it never will, but almost two decades after the fact, anyone using, or inflicting upon someone, an IMAP client that blindly issues LOGIN is perhaps deserving of their fate. C'est la vie. Sadly, they're still out there - which is why FastMail doesn't allow port 143 at all. Port 993 appears to be working in the real world[tm]. I'd be interested in seeing the actual stats for which clients can be convinced by a MITM to give up their credentials in plaintext in their default configuration. Don't give me a checkbox which requires the user to actively increase the security level, because that won't work. In fact, don't even give the user a dialog which allows them to send the password insecurely, because they will. Not responding to a SYN on port 143 with an ACK... Bron. -- Bron Gondwana [email protected] _______________________________________________ Imap-protocol mailing list [email protected] http://mailman13.u.washington.edu/mailman/listinfo/imap-protocol