Re: [Imap-protocol] STARTTLS after PREAUTH

Joshua Cranmer <[email protected]>
Newsgroups gmane.mail.imap.general
Message-ID <[email protected]>
On 3/18/2014 10:46 PM, Bron Gondwana wrote:
> And then it fell back to the Mozilla ISP database, but there's no 
> reason I couldn't have MITMed that and stolen the gmail creds too. 
> Thunderbird is pretty trivially fooled at setup time. Bron. 
The ISP database requires an https connection IIRC, but that's a minor 
detail (I thought autoconfig also required https and not http, but 
again, that's minor).

You seem to be coming from the standpoint that a security system that 
can't protect against everything is no better than one that protects 
against most things. Autoconfiguration can be fooled, true (even if 
https were required--we fallback to guessing servers and trying 
commands, so a DNS hijack setup could easily screw it over). But you 
have a 5-second window (and I'm being generous here) to do it. And if 
you miss that chance, you've lost it for another 3 years.

It's like ssh: ssh is actually weak to being MITM'd on the first 
connection (based on how people use it): people don't remember the keys, 
so they'll always say "yes" to the question "are you sure this key is 
correct?" Does that mean that ssh provides no protection? Of course 
not--the difficulty of intercepting the ssh connection is made extremely 
harder and makes attackers pour much more resources into doing so.

-- 
Beware of bugs in the above code; I have only proved it correct, not tried it. -- Donald E. Knuth

_______________________________________________
Imap-protocol mailing list
[email protected]
http://mailman13.u.washington.edu/mailman/listinfo/imap-protocol
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.