Re: [Imap-protocol] STARTTLS after PREAUTH

Dave Cridland <[email protected]>
Newsgroups gmane.mail.imap.general
Message-ID <CAKHUCzwNErGDPtn8nt-LdPHXQy1E2n5=mwCHiQZ87nD0eYWGQA@mail.gmail.com>
On 19 March 2014 03:00, Lyndon Nerenberg <[email protected]> wrote:

>
> On Mar 18, 2014, at 7:23 PM, Bron Gondwana <[email protected]> wrote:
>
> > So why is 993 deprecated rather than STARTTLS deprecated now?  STARTTLS
> is _still_ a bad idea.
>
> That seemed to be a political argument within disparate IETF WGs.
>  Begrudgingly I would nominate Chris to talk about that history, as I
> recall he was involved (or argued) during the period.  But I also know many
> people want to forget about it.  I just ignored the whole thing due to the
> in-fighting.
>
> Okay, not completely.  I was discouraging against SSL on 993 for one main
> reason:
>
> If SSL is proven broken, where do we go?  Another port for another
> encryption layer?  How does that scale?
>
> And I think that was the crux of the overall IETF argument against
> allocating dedicated ports to dedicated SSL versions of the existing
> protocols.  SRV was supposed to mitigate against that, but SRV hasn't taken
> over the protocol developer community.
>
>
The main argument was mostly that TLS wasn't seen as the sole encryption
method, and it was possible (and in fact quite common at one stage) to find
better security via SASL security layers than by (export grade) TLS.

That argument has gone, I think.

The other argument relates to port number exhaustion, which turned out to
be unimportant because everyone uses either 80 or 443 these days.

It's possible that revisiting the issue might prove interesting.

I don't think that it's worth worrying over TLS breaking, though, I think
the custodians of that protocol are well able to maintain some kind of
upgrade path.

Dave.

_______________________________________________
Imap-protocol mailing list
[email protected]
http://mailman13.u.washington.edu/mailman/listinfo/imap-protocol
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.