UK government is trying to get into iCloud end-to-end encryption. (Again?)

Makes me think about email servers too. Most of my private information is in emails, and not only I use a service where the host machines access the email, so do almost everyone I email to/from.

you are viewing a single comment's thread
view the rest of the comments
[–] 2 points 2 years ago (1 child)

SMTP is only encrypted if the second server responds correctly to the first servers starttls.

The striptls type of attack, which prevents the servers from getting a valid starttls exchange, was in use over a decade ago by some telcom against its own customers.

Even if you know the person you’re emailing has a correctly configured client you can’t control a man in the middle attack between servers which has been in widespread use for years.

  • source
  • parent
  • hideshow 2 child comments