Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It would be nice to also consider completely dropping support for non-TLS SMTP.

Unlike HTTP where connecting to abandoned non-TLS websites can be useful, e-mail is only useful if someone is reading it, and if they are reading it they can take action to enable TLS.



Well, we missed out on mandatory encryption in HTTP/2, despite that requiring the webserver to turn it on, so for some reason we still have a lobby for unsecured communications.


Except browsers won't implement non-TLS HTTP2. So for all the use cases that matter, it's fine. Another good example of implementation trumping "standards".




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: