Skip to content

Comment on STARTTLS Considered Harmfulparent

Comments

Considering every damn SMTP server out there that talks STARTTLS actually just accepts any certificate by default including self-signed ones, isn't this entire point moot?

It's not a protocol but an implementation problem.

STARTTLS is and implementation of SSL/TLS protocol

Kudos for stating the obvious. Now how do we do something about this?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.