Re: [Imap-protocol] STARTTLS after PREAUTH
Joshua Cranmer <[email protected]>
| Newsgroups | gmane.mail.imap.general |
|---|---|
| Message-ID | <[email protected]> |
On 3/18/2014 10:46 PM, Bron Gondwana wrote: > And then it fell back to the Mozilla ISP database, but there's no > reason I couldn't have MITMed that and stolen the gmail creds too. > Thunderbird is pretty trivially fooled at setup time. Bron. The ISP database requires an https connection IIRC, but that's a minor detail (I thought autoconfig also required https and not http, but again, that's minor). You seem to be coming from the standpoint that a security system that can't protect against everything is no better than one that protects against most things. Autoconfiguration can be fooled, true (even if https were required--we fallback to guessing servers and trying commands, so a DNS hijack setup could easily screw it over). But you have a 5-second window (and I'm being generous here) to do it. And if you miss that chance, you've lost it for another 3 years. It's like ssh: ssh is actually weak to being MITM'd on the first connection (based on how people use it): people don't remember the keys, so they'll always say "yes" to the question "are you sure this key is correct?" Does that mean that ssh provides no protection? Of course not--the difficulty of intercepting the ssh connection is made extremely harder and makes attackers pour much more resources into doing so. -- Beware of bugs in the above code; I have only proved it correct, not tried it. -- Donald E. Knuth _______________________________________________ Imap-protocol mailing list [email protected] http://mailman13.u.washington.edu/mailman/listinfo/imap-protocol