#STARTTLS

2025-05-27

Die kürzlich veröffentlichte Cyber-Sicherheitsempfehlung "Upgrade für die E-Mail-Sicherheit" ist ein Paradebeispiel für die lösungsorientierte Zusammenarbeit zwischen verschiedenen Abteilungen im BSI. Nur so konnten wir praxisnahe Empfehlungen aussprechen, die auf Beobachtungen der echten Welt da draußen beruhen. Oft können Unternehmen, die E-Mails über eine eigene Domain senden und empfangen, nämlich schon mit überschaubaren Aufwand ihre Sicherheit deutlich verbessern.

bsi.bund.de/DE/Service-Navi/Pr

#MailSecurity #TeamBSI #SPF #DKIM #DMARC #STARTTLS #DNSSEC #DANE #MTASTS #TLSRPT

2025-04-29

now also available in English:
Four modern mail systems for self-hosting -- Universal support for mail security standards
sidn.nl/en/news-and-blogs/four

An increasing number of mail software packages are now available that offer out-of-box support for all security standards, and are easy to set up as well. In this article, we consider four modern open-source packages for self-hosting: #Mox, #Chasquid, #Stalwart and #Maddy.

#SPF #DKIM #DMARC #DANE #STARTTLS #MTA-STS #InternetSecurity

@stalwartlabs

2025-04-28

op SIDN.nl:
Vier moderne mail-systemen voor self-hosting -- Beveiligingsstandaarden voor mail universeel ondersteund
sidn.nl/nieuws-en-blogs/vier-m

Inmiddels zijn er meerdere software-pakketten beschikbaar die én alle beveiligingsstandaarden out-of-the-box ondersteunen én makkelijk op te zetten zijn. In dit artikel bespreken we vier moderne open-source mail-pakketten voor self-hosting: #Mox, #Chasquid, #Stalwart en #Maddy.

#SPF #DKIM #DMARC #DANE #STARTTLS #MTA-STS #InternetSecurity

@stalwartlabs

2025-03-26

Letzte Woche fand das erste Treffen mit Mail-Providern zum E-Mail-Sicherheits-Jahr 2025 statt. Mit dabei war auch die Präsidentin des BSI, Claudia Plattner. Ich kann mich den Worten von Fabian Bock nur anschließen und freue mich schon auf die vielen weiteren Treffen und Aktionen, die wir für das Jahr geplant haben :blobcheer:

mail.de/de/blog/2025-03-unsere

#MailSecurity #TeamBSI #SPF #DKIM #DMARC #STARTTLS #DNSSEC #DANE

testssl.sh :verified:testssl@infosec.exchange
2025-01-29

testssl.sh now supports the #STARTTLS protocol #sieve

2024-07-23

also available in English on SIDN.nl:
Plenty of requirements about using security standards, but no enforcement or sanctions -- New powers for Authority for Digital Infrastructure may bring about change
sidn.nl/en/news-and-blogs/plen

Many municipal websites don't meet the security standards they're supposed to meet. The problem isn't a lack of regulation, but a lack of compliance and enforcement.

#InternetSecurity #infosec #DNSSEC #DMARC #STARTTLS
@internet_nl

2024-07-23

op SIDN.nl:
Een zee aan verplichtstellingen voor beveiligingsstandaarden, maar geen dwang of sancties -- Wellicht dat de Rijksinspectie voor Digitale Infrastructuur deze keer wel een verschil kan maken
sidn.nl/nieuws-en-blogs/een-ze

Een groot deel van de gemeentelijke websites voldoet niet aan de verplichte beveiligingsstandaarden. Probleem is niet een gebrek aan regelgeving, maar de naleving en handhaving daarvan.

#InternetSecurity #infosec #DNSSEC #DMARC #STARTTLS
@internet_nl

Aktuell auf der #SLAC2024: "Sicherheit von STARTTLS in E-Mail-Clients." mit Fabian Ising vom Fraunhofer Institute for Secure Information Technology SIT. Fabian stellt eine wissenschaftlichen Studie und strukturierte Sicherheitsanalyse von #STARTTLS in IMAP, SMTP und POP3 vor. Die Ergebnisse zeigen, dass Angriffe gegen STARTTLS noch immer aktuell und kritisch sind. Er erklärt die Mechanismen dahinter und zeigt konkrete Angriffe. Spannend!

#IMAP #SMTP #POP3 #Administration #Cybersicherheit

Wie sicher ist STARTTLS in IMAP, SMTP und POP3? Dr. Fabian Ising hat in einer Studie die erste strukturierte #Sicherheitsanalyse von STARTTLS in E-Mail-Clients mit durchgeführt.

Das Ergebnis: Angriffe gegen #STARTTLS sind aktuell & kritisch.

Im #SLAC-Vortrag zeigt er:

👉 den Mechanismen hinter der E-Mail-Client zu E-Mail-Server-Kommunikation
👉 dem STARTTLS-Mechanismus 👉 konkrete Angriffe aus der Praxis

🎟️ Tickets:
slac-2024.de

#IMAP #SMTP #POP3 #Administration #Cybersecurity

SLAC 2024 Vortrag: Sicherheit von STARTTLS in E-Mail-Clients
Todd A. Jacobs | Pragmatic Cybersecuritytodd_a_jacobs@infosec.exchange
2023-11-22

There's no shortage of #cybersecurity talent in the industry. However, like any domain where people over-specialize because of market conditions, you end up with questions like this one where people don't understand how application or session layer protocols actually work, and how a "security protocol" actually works.

Email is an outdated messaging protocol, but the transport layer is just as secure as #HTTPS when using #TLS. Most modern MTAs default to using #SMTP over TLS, or use opportunistic encryption with #STARTTLS. Both the client and server are usually configured to drop insecure connections before user authentication happens.

The only correct answer here is #SSL, which was deprecated more than nine years ago due to limitations and vulnerabilities in its supported ciphers. SMTP is not a security protocol, yet 68% of respondents apparently think it is. That's a problem.

No one should be expected to know everything, and not all security people focus on networking, encryption, or handshake protocols. However, if you don't want to be the next breach-in-the-news, please ensure your staff at least understands the basic controls used or needed for the systems you've hired them to protect!

linkedin.com/posts/the-cyber-s

Poll results from The Cyber Security Hub™ LinkedIn group, showing that as of 2023-11-22T01:47:36+00:00, 68% of respondents chose SMTP over SFTP, SSL, and HTTPS as the "least strong security protocol".
🛡 H3lium@infosec.exchange/:~# :blinking_cursor:​H3liumb0y@infosec.exchange
2023-10-24

"🚨 *Major lawful Interception *: Russian XMPP (Jabber) Service Under Attack! 🚨"

The largest Russian XMPP (Jabber) messaging service, jabber.ru (also known as xmpp.ru), has been targeted in a sophisticated Man-in-the-Middle (MiTM) attack. The attackers intercepted encrypted TLS connections on Hetzner and Linode hosting providers in Germany. 🇩🇪🔓

Several rogue TLS certificates were issued using the Let’s Encrypt service to hijack encrypted STARTTLS connections on port 5222. The attack was unveiled due to an expired MiTM certificate. The interception might have been ongoing for up to 6 months, with 90 days confirmed.

The attack seems to be a lawful interception that Hetzner and Linode might have been compelled to set up. The implications are severe: all communications between the affected dates could be compromised. Users are urged to check their accounts for unauthorized #OMEMO and #PGP keys and to change passwords. 🔑🚫

Author: ValdikSS, 21st October 2023
Source: ValdikSS's Notes

Tags: #XMPP #Jabber #MiTM #Cybersecurity #Hetzner #Linode #EncryptionBreach #TLS #STARTTLS #LetsEncrypt 🌐🔐🚫

2023-09-27

@brokenix Heads-up to all: The IETF has proposed implicit TLS (Port 465) as preferred over STARTTLS solutions. The previous confusion around Port 465 was cleared.

rfc-editor.org/rfc/rfc8314.htm

Wherever possible I use Port 465 over 587. Only one mail server I use doesn't offer implicit TLS, I have to contact them soon 😀

#smtp #tls #starttls

Joerg Jaspert :debian:Ganneff@fulda.social
2023-09-26

Oh man. #Grandstream, Access Point. You can configure to send alerts to a #mail recipient. Nice.

Except, whoever idiot implemented it, has been a *bit* to eager on "Lets force this secure".
The mail relay you want to use MUST support #STARTTLS. It MUST support #login with user/pass. You MAY skip validating the certificate.

NO way to tell it "Nope, mailrelay is local, it really does not need any login and no, it DOES NOT support tls". Just no way.

Useless.

Colin Cogle 🔵colincogle
2023-08-28

It took me far too long to get to validate records. Why? My cloud provider's DNS server doesn't support . It's 2023, come on! Hopefully using an external DNS server won't spike my bandwidth too much.

Todd A. Jacobs | Rubyisttodd_a_jacobs@ruby.social
2023-06-27

I need a dummy #RubyLang #IMAP server that can support #STARTTLS but otherwise treats most commands as no-ops. I couldn't find anything well-maintained via GitHub or Ruby Toolbox other than the gem from Ruby's #stdlib at:

ruby-doc.org/3.2.2/gems/net-im

Rather than gutting Net::IMAP, is there already a gem out there that can be used to support fetch-before-send clients like Apple's Mail that won't send email before completing POP3 or IMAP4 authentication?

Christian Pietsch (old acct.)chpietsch@digitalcourage.social
2022-09-04

One of my #GitLab instances was no longer able to send e-mails. (It tried to send almost empty e-mails, but its smarthost discarded those.)

It was the one that used #nullmailer as its #MTA. GitLab recommends either #Sendmail or #Postfix as an MTA. Switching to Postfix solved this issue for me.

Making sure that Postfix uses the #StartTLS capability of its smarthost took longer than expected.

It's also rather annoying that on Debian systems, postfix by default accepts connections from anywhere on the Internet even though I asked debconf to set up a “satellite system”.

When using Nullmailer, I just had to put the line “smtp.domain.tld smtp --port=25 --starttls” in /etc/nullmailer/remotes.

For Postfix, I need this:
inet_interfaces = loopback-only
smtp_tls_security_level = encrypt

Your mileage may vary.

Matthias Bachmarix@chaos.social
2022-01-26

Ich wüsste ja schon zu gerne, wieso mein #Postfix seit heute morgen auf einmal > 5 Sekunden braucht um einen #TLS-Handshake zu machen, sowohl auf 465 als auch bei #STARTTLS. 🤔

Geändert habe ich (bewusst) nichts, und die Nameserver hab ich schon getestet, die scheinen schnell zu sein.

heise online (inoffiziell)heiseonline@squeet.me
2021-12-07
heise+ | SMTP: E-Mails automatisch mit Python versenden

Python bietet nützliche Werkzeuge, um Mails einfach zu verschicken. Egal, ob es um Plaintext, HTML-Inhalte oder Dateianhänge geht.
SMTP: E-Mails automatisch mit Python versenden
luz1 :archlinux:luz1@social.tchncs.de
2020-06-06

Critical bug in Thunderbird.

CVE-2020-12398: Security downgrade with IMAP STARTTLS leads to information leakage

mozilla.org/en-US/security/adv

#mozilla #thunderbird #STARTTLS #security

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst