|
|
|
|
|
by schoen
2918 days ago
|
|
> SSL is not mandatory on either port 25 or 587, and can not be made mandatory if you follow the RFCs. I'm well-aware of the RFC difficulty, but I don't think that the current approach of STARTTLS Everywhere is really a problem because it's effectively opt-in on both ends. The enforcement is requested by the receiving side and then implemented by the sending side. * The receiving MTA has to proactively choose to be listed. * The sending MTA has to proactively choose to make use of the list. So, with the current version of STARTTLS Everywhere, only sites that deliberately choose to enforce STARTTLS will do so, and they will only do it when communicating with sites that have specifically asked them to enforce it! This would only be an RFC violation if we thought that the RFC meant to categorically forbid sites from separately agreeing to a stricter security policy. This approach might have its scalability limitations, but I won't try to speak for my colleagues about any future steps. |
|
The problem is not the MTA who will chose to be listed, but those who won't be listed - the immense majority. "Scalability limitation" is certainly a more polite way to say that.
I'm sorry if my message was too blunt, but I am not sure it was worth downvoting my technical explanation just for this.