SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    Do Not Rely on STARTTLS to Automatically Encrypt Your Sensitive E-mails
Date    Monday November 02 2015, @01:19PM
Author    martyb
Topic   
from the ask-and-ye-might-not-receive dept.
https://soylentnews.org/article.pl?sid=15/11/01/1137221

darkfeline writes:

http://arstechnica.com/security/2015/10/dont-count-on-starttls-to-automatically-encrypt-your-sensitive-e-mails/

This isn't really new news, but improperly configured mail services result in lots of privacy holes across the Internet.

STARTTLS is used to upgrade an unencrypted connection to an encrypted SSL/TLS connection. The problem is that if the upgrade fails, many mail clients will proceed to send mail on the unencrypted connection.

For any sysadmins (technical info):

Unfortunately, the situation is somewhat sticky. I suggest reading carefully the TLS/SSL section of https://wiki.debian.org/PostfixAndSASL as well as the STARTTLS RFC http://tools.ietf.org/html/rfc2487

Public email servers should not require STARTTLS (that is, encryption) on port 25 (smtp). Furthermore, there is no guarantee that all of the mail servers during transit of an email use encryption. Thus, you should assume your email is transmitted unencrypted, until a better solution emerges. You can always use OpenPGP to encrypt the body of your email, which should become commonplace shortly after Hurd achieves market dominance.


Editors Note: How to articles for various flavors of Microsoft Exchange can be found at MSExchange.org.

Original Submission

Links

  1. "darkfeline" - https://soylentnews.org/~darkfeline/
  2. "MSExchange.org" - http://www.msexchange.org/articles-tutorials/exchange-server-2010/security-message-hygiene/exchange-2010-domain-security-part1.html
  3. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=10394

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, Do Not Rely on STARTTLS to Automatically Encrypt Your Sensitive E-mails on 2024-04-23 07:47:35