Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The reason I call STARTTLS "stupid" is because it superceded a perfectly good, fully encrypted, transport layer protocol: SMTP over SSL/TLS on port 465.

That was 16 years ago. Even back then, plenty of people seem to have been on the right track when it comes to how to encrypt a stream. People back then were also aware of the difference between the needs of mail transport and the needs of mail submission; the distinction was codified in RFC 2476 in 1998. Despite all of this, some people went ahead and implemented an "if available" encrypted protocol in the name of compatibility, deprecated the fully encrypted and widely supported alternative, and even went so far as to revoke port 465.

Two years ago, it may have sounded crazy to suggest that some three-letter agency was behind this. Now, I'm not so sure.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: