BugTraq
Web Tool Announcement: ismymailsecure.com Aug 18 2010 09:59AM
Holger Rabbach (hrabbach crossroad-networks com) (2 replies)
Re: Web Tool Announcement: ismymailsecure.com Aug 25 2010 07:59AM
Kari Hurtta hurtta+bugtraq (at) leija.mh.fmi (dot) fi [email concealed] (hurtta+bugtraq leija mh fmi fi) (1 replies)
Re: Web Tool Announcement: ismymailsecure.com Aug 25 2010 08:39AM
Holger Rabbach (hrabbach crossroad-networks com) (2 replies)
Re: Web Tool Announcement: ismymailsecure.com Aug 25 2010 05:23PM
Tim (tim-security sentinelchicken org)
Re: Web Tool Announcement: ismymailsecure.com Aug 25 2010 09:30AM
Kari Hurtta hurtta+bugtraq (at) leija.mh.fmi (dot) fi [email concealed] (hurtta+bugtraq leija mh fmi fi) (1 replies)
Re: Web Tool Announcement: ismymailsecure.com Aug 25 2010 11:48AM
Holger Rabbach (hrabbach crossroad-networks com) (1 replies)
Re: Web Tool Announcement: ismymailsecure.com Aug 25 2010 06:02PM
Tim (tim-security sentinelchicken org) (1 replies)
Re: Web Tool Announcement: ismymailsecure.com Aug 25 2010 08:56PM
Brian Behlendorf (brian behlendorf com)
On Wed, 25 Aug 2010, Tim wrote:
> It's unfortunate that STARTTLS is currently a disaster to configure
> securely, particularly because it is just a point-to-point encryption
> mechanism and all of this complexity has to be addressed at every hop.
> I think as a security community we'd be a lot better off putting our
> efforts into encouraging end-to-end encryption with S/MIME or
> PGP/MIME.

That's the conclusion we came to in the NHIN Direct project
(http://nhindirect.org/, secure messaging for the health IT industry)
though server-server TLS with agreed-upon CAs (establishing "trust
circles") are helpful. What TLS didn't appear to allow is negotiation of
CAs - which ones do I trust, which ones do you have signatures from,
what's the intersection. That would allow it to grow more intelligently
than the "trust this long list of root CAs" model that web browsers use.
In our case it's useful to also encrypt the server-server link, even if
you are S/MIME encrypting the message content, because From/To/Subject
data can be pretty sensitive. Seeing encrypted SSL traffic between
suttermentalhealth.com and healthvault.com is a lot less revealing than
From: drbob (at) suttermentalhealth (dot) com [email concealed] To: brian (at) healthvault (dot) com [email concealed] Subject: Are
you taking your meds?

Brian

[ reply ]
Re: Web Tool Announcement: ismymailsecure.com Aug 19 2010 10:11PM
Chuck Swiger (cswiger mac com)


 

Privacy Statement
Copyright 2010, SecurityFocus