Hacker News new | past | comments | ask | show | jobs | submit login

Why? What benefit is there in starting plaintext, and as the post shows, allowing clients to transmit credentials?

And is IMAPS deprecated? Not that it matters -- the IETF or IANA deprecating something or unassigning a port is not really much of a justification.




It was unnecessary to split the protocol into two ports when STARTTLS came along shortly after. As for myself, I also thinks it's nice that you can partly identify the usage of a port by connecting to it.

https://en.wikipedia.org/wiki/SMTPS


Still doesn't address sending credentials plaintext or what benefit this has, at all. Adds another roundtrip for no benefit. Using TLS doesn't change the identification, just requires a few packets to be exchanged; not a huge deal.

So again, how did Lavabit help its customers by not forcing TLS for IMAP?




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: