Re: [Imap-protocol] STARTTLS after PREAUTH
Jan Kundrát <[email protected]>
| Newsgroups | gmane.mail.imap.general |
|---|---|
| Message-ID | <[email protected]> |
On Tuesday, 18 March 2014 23:01:12 CEST, Arnt Gulbrandsen wrote: > Think about it this way. As a client author, how do you handle > the case where the server sends you PREAUTH and you want to use > TLS? Oops. Thanks for an excellent suggestion, Arnt. It turns out that Trojita silenty fails to establish encryption when the remote server greets us with an initial PREAUTH. That might lead to information leak (APPEND of messages, confirmation of mailbox names), but never to credentials being transmitted in plaintext (Trojita understands what PREAUTH is, and won't attempt to LOGIN or AUTHENTICATE in that case). /me checks how to file a CVE... With kind regards, Jan -- Trojitá, a fast Qt IMAP e-mail client -- http://trojita.flaska.net/ _______________________________________________ Imap-protocol mailing list [email protected] http://mailman13.u.washington.edu/mailman/listinfo/imap-protocol