Hacker News new | past | comments | ask | show | jobs | submit login

STARTTLS has risks over and above pure use of TLS - in particular where it's been used in IMAP and POP3, an attacker injecting plaintext commands before STARTTLS/STLS occurs, tricking an early (plaintext) login and other such shenanigans.

This is why the SMTPS port is being resurrected, and STARTTLS-type upgrades are not considered good practice in future - port assignments in future are likely to take that into account.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: