Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> won't be snooped on by any of the other parties involved in transporting it.

There was a time, long, long ago, when mail from your email provider to your recipient's provider would often go through other providers in transit. Nowadays (and for the last 20 years) all of the intermediary mail-servers in the Received: headers belong to either the sender's provider or the recipient's provider. They're usually spam-filters, application gateways, secondary servers.

I guess the major exception is people who use gmail or Mailchimp as an outbound relay. But that's deliberate, and entirely under the sender's control.



However, the wide use of MTA-STS is quite recent so downgrade attacks have been possible. In fact, Fastmail seems to currently be messing up MTA-STS, I'm not sure if they are intending to enable it or not.

https://www.mailhardener.com/kb/mta-sts




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: