Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Fri, 12 Feb 2016 05:30:31 +0300
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Subject: Re: STARTTLS for this list?

On Thu, Feb 11, 2016 at 06:05:26PM -0800, Seth Arnold wrote:
> It doesn't seem like a top priority to me: STARTTLS solves one set of
> problems and introduces a much larger set of problems. I'm not sure any of
> the solved problems are actually pressing problems to a public mail list.

That's my current feeling, too - for this mailing list at this time.

> Hosting a mail list is already miserable enough (for example, I don't
> think mail From: google addresses actually makes to Google users;

You're right - as discussed before, it does not, because of DMARC.
(This applies to senders from google.com and some other Google domains,
but luckily not yet to senders from gmail.com.  However, recipients at
gmail.com are also affected whenever someone posts from google.com.
Also, Yahoo's free e-mail and a few others are affected.)

Working around this is actually planned (especially as Google intends to
extend this to Gmail senders).  STARTTLS currently is not.

> also, I
> don't know how the moderators manage to keep this list spam-free with zero
> mistakes, either false positives or false negatives.) --

It's a combination of scripting and manual message moderation.  There
are occasional mistakes (I posted about a badly delayed wrong-charset
message not so long ago), but they are few (at least that I'm aware of).
I think we manage pretty well, considering that most messages arrive to
the list within minutes.

> adding a half-dozen
> more reasons why mail delivery can fail is surely not fun.

Right.  And supporting TLS, even if only client-side, also adds to the
server's attack surface.  That said, we might be forced to, eventually.

I am actually in favor of opportunistic encryption in general.

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.