Comment on STARTTLS Considered HarmfulparentComments−leni53612yConsidering every damn SMTP server out there that talks STARTTLS actually just accepts any certificate by default including self-signed ones, isn't this entire point moot?It's not a protocol but an implementation problem.−crpatino12ySTARTTLS is and implementation of SSL/TLS protocol−jvdh12yKudos for stating the obvious. Now how do we do something about this?
Comments
Considering every damn SMTP server out there that talks STARTTLS actually just accepts any certificate by default including self-signed ones, isn't this entire point moot?
It's not a protocol but an implementation problem.
STARTTLS is and implementation of SSL/TLS protocol
Kudos for stating the obvious. Now how do we do something about this?