AfterDawn: Tech news

STARTTLS Everywhere: EFF wants to secure e-mail

Written by James Delahunty @ 27 Jun 2018 7:27

STARTTLS Everywhere: EFF wants to secure e-mail

The Electronic Frontier Foundation (EFF) is trying to make e-mail more secure and private by helping webmasters deploy properly configured STARTTLS on SMTP servers.
E-mails sent over the Internet use the SMTP protol for the most part. SMTP is older than the HTTP protocol, and like HTTP it was not developed with encryption and data privacy in mind. As the online environment changed and called for more secure e-mail transit, STARTTLS was developed to add a layer of security to protocol.

STARTTLS provides for hop-to-hop encryption that means e-mails are not sent in plaintext in transit. It should be noted that STARTTLS does not encrypt the e-mail on the server itself, just while in transit.

While STARTTLS is deployed on most mailservers these days, unfortunately it is not always configured properly and has some problems. The EFF notes that most do now not validate certificates. Just like in HTTPS, certificates are what a server uses to prove it really is who it says it is. Without certificate validation, an active attacker on the network can get between two servers and impersonate one or both, allowing that attacker to read and even modify emails sent through your supposedly "secure" connection.



There is also a problem called the "downgrade attack" in which the sending e-mail server's request to send over a secure channel is simply filtered out entirely, resulting in both the sending and receiving servers assuming that the other doesn't support STARTTLS.

STARTTLS Everywhere attempts to address all of these issues. It is software that a sysadmin can run on an email server to automatically get a valid certificate from Let's Encrypt. This software can also configure their email server software so that it uses STARTTLS, and presents the valid certificate to other email servers.

Additionally, STARTTLS Everywhere includes a "preload list" of email servers that have promised to support STARTTLS, which can help detect downgrade attacks.

If you want to read more about STARTTLS Everywhere, you can do so here.

Previous Next  
Comments have been disabled for this article.

Latest news

VLC hits milestone: over 5 billion downloads VLC hits milestone: over 5 billion downloads (16 Mar 2024 4:31)
VLC Media Player, the versatile video-software powerhouse, has achieved a remarkable feat: it has been downloaded over 5 billion times.
2 user comments
Sideloading apps to Android gets easier, as Google settles its lawsuit Sideloading apps to Android gets easier, as Google settles its lawsuit (19 Dec 2023 11:09)
Google settled its lawsuit in September 2023, and one of the settlement terms was that the way applications are installed on Android from outside the Google Play Store must become simpler. In the future, installing APK files will be easier.
8 user comments
Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets (06 Jun 2023 9:19)
Roomba Combo j7+ is the very first Roomba model to combine robot vacuum with mopping features. And Roomba Combo j7+ does all that with a very clever trick, which tackles the problem with mopping and carpets. But is it any good? We found out.
Neato, the robot vacuum company, ends its operations Neato, the robot vacuum company, ends its operations (02 May 2023 3:38)
Neato Robotics has ceased its operations. American robot vacuum pioneer founded in 2005 has finally called it quits and company will cease its operations and sales. Only a skeleton crew will remain who will keep the servers running until 2028.
5 user comments
How to Send Messages to Yourself on WhatsApp How to Send Messages to Yourself on WhatsApp (20 Mar 2023 1:25)
The world's most popular messaging platform, Meta-owned WhatsApp has enabled sending messages to yourself. While at first, this might seem like an odd feature, it can be very useful in a lot of situations. ....
18 user comments

News archive