Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS Proposal

Alice Wonder <alice@domblogger.net> Tue, 08 January 2019 01:57 UTC

Return-Path: <alice@domblogger.net>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DA33A130E57 for <uta@ietfa.amsl.com>; Mon, 7 Jan 2019 17:57:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=domblogger.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xniexUZcHJQb for <uta@ietfa.amsl.com>; Mon, 7 Jan 2019 17:57:24 -0800 (PST)
Received: from mail.domblogger.net (mail.domblogger.net [IPv6:2600:3c00::f03c:91ff:fe56:d6a2]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 436C3130E67 for <uta@ietf.org>; Mon, 7 Jan 2019 17:57:24 -0800 (PST)
Received: from localhost.localdomain (c-73-15-182-232.hsd1.ca.comcast.net [73.15.182.232]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.domblogger.net (Postfix) with ESMTPSA id 853B81C17 for <uta@ietf.org>; Tue, 8 Jan 2019 01:57:23 +0000 (UTC)
DKIM-Filter: OpenDKIM Filter v2.11.0 mail.domblogger.net 853B81C17
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=domblogger.net; s=default2019; t=1546912643; bh=hm4xtATHAxxQZUEzan3Ywv4JIQSJ6IDzCxaVNP2kQSM=; h=Subject:To:References:From:Date:In-Reply-To:From; b=pIdkohOUe1c+adYcMzitO4qdeelR7bDigYbUeUGN5aBVTux6DaGPr1iiVCkq8VJt8 pJiuUk4czsvLyO59rdkyNrJcKq4oLGcO/dWPrb86etYfT/JfXzhaEfoJwdkRwzuR25 EZ5Eab8/3nVvo1h65J4cIASDuPr3AKZFXj+EOad3bmNaFWyW21SNEWiUB5m5QeEc06 axeP4oS+hD2fk8ymryrhoepNZAmGdtMpZkAgLsS8FxOZ2WMvE53muqXqPmwkRsY2AZ a4dAOacMGHbNjBez+ndjTSJaXJCmSYYHwrBxn8G5SK1eNQjEIIkqXJFFAQ0KFm0AuO aKtbjLpMzAp6w==
To: uta@ietf.org
References: <CAOEezJTyEf+Sn9ZqQPue1DFUSoFO211YogJ6ufYJxswWzXk=_A@mail.gmail.com> <20190106010828.CC431200C5ED52@ary.qy> <CAOEezJShOYkmy8-E+8zG=CPXxrWNcxf8q8W8MnW-v1RT0FzEWw@mail.gmail.com> <123cecc0-aba2-9530-c0d9-b6437f295140@domblogger.net> <88fad90d-24b6-fe4d-5df8-bc294c4f6b33@bluepopcorn.net> <CAOEezJS+T3pP-GqwJFeT=HGbOu1TkY6W0kyjP9_FcVsaJ=hw7A@mail.gmail.com> <b4fe2502-dc1e-5dea-8515-b69ed262ac8f@domblogger.net> <CAOEezJTFxhRYGKQD0a8LLEL7UTPKmfdF5uYLDpZdj3Zm9P+wZw@mail.gmail.com> <35456e82-c149-864f-3312-cff55af68551@domblogger.net> <CAOEezJTTp-VDvChuTcG5yD4yAVe9M0eKZnN11tKXV79O53ai5w@mail.gmail.com> <542346640.18156.1546871078489@appsuite.open-xchange.com> <98be93f5-a637-3b89-d376-46cb2bcf2f61@domblogger.net> <1546912211666.74241@cs.auckland.ac.nz>
From: Alice Wonder <alice@domblogger.net>
Message-ID: <9a932d9b-abbf-db61-0b98-1bd915e45353@domblogger.net>
Date: Mon, 07 Jan 2019 17:57:21 -0800
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.3.0
MIME-Version: 1.0
In-Reply-To: <1546912211666.74241@cs.auckland.ac.nz>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/uta/Rwg44jgQBlHlvZLdftk1KFVqpdY>
Subject: Re: [Uta] SMTP Over TLS on Port 26 - Implicit TLS Proposal
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 08 Jan 2019 01:57:26 -0000

On 1/7/19 5:50 PM, Peter Gutmann wrote:
> Alice Wonder <alice@domblogger.net> writes:
> 
>> If it were up to me, an RFC would be published deprecating opportunistic TLS
>> for SMTP.
> 
> Assuming you're actually serious, why?
> 
> Peter.
> 

I'm a privacy zealot and many people have trouble getting PGP or S/MIME 
to work. I've met Ph.Ds who couldn't figure it out.

Requiring TLS not only gives passive protection, but it also means we 
would have the assumption of privacy when communicating with e-mail 
which at least in the United States has legal ramifications for law 
enforcement snooping on e-mail w/o a warrant.