Hacker News new | past | comments | ask | show | jobs | submit login

All three of my email accounts (Outlook.com, Gmail, and AOL) require SSL, TLS, and STARTTLS (or any combination of the previous three) to send.

SMTP is nothing next to encryption, but it's not the equivalent of leaving papers in a filing cabinet.

Not even close.




Your SMTP server requires it to send email to prove it's really you and really them, yes, the mail server however sends your email to the recipient in clear text and can easily be intercepted if you happen to be inbetween the two servers.


>if you happen to be inbetween the two servers.

In which case you are a network administrator of a (probably tier 1) ISP and abusing your position of trust. As well as probably violating your contracts with the companies for which you have agreed to carry traffic.

It's also possible for me to read mail from my neighbors' mailboxes, and most of their PSTN demarcs are hanging off the side of the house and not protected by a fence or anything. Mail and voice calls are still private.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: