Comment on STARTTLS Considered HarmfulparentComments−jgillich12yNot just applications, servers as well. My Postfix/Dovecot setup does support unencrypted connections, but will refuse to do authentication if the channel is not encrypted.−brongondwana12yWhich is pointless when the plaintext password has already been sent across the wire.
Comments
Not just applications, servers as well. My Postfix/Dovecot setup does support unencrypted connections, but will refuse to do authentication if the channel is not encrypted.
Which is pointless when the plaintext password has already been sent across the wire.