Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is what I was trying to get at. It's silly to even offer plaintext communications in the first place.


We were talking about a theoretical bad client. No client I have ever used to talk to port 587 would behave that way. They would all encrypt or fail. Regardless of if "AUTH PLAIN" was inserted prior to encryption and/or STARTTLS removed.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: