[Cryptography] ISPs caught in STARTTLS downgrade attacks

Viktor Dukhovni cryptography at dukhovni.org
Fri Nov 14 17:59:36 EST 2014

On Fri, Nov 14, 2014 at 05:37:52PM -0500, Paul Wouters wrote:

> Seriously, the crypto community has too many cry babies and not enough
> implementors. I'd be happy if someone designs and implements something
> that's better. Please obsolete me.

Yes, folks with gmail.com addresses complaining about providers
intruding on other users' privacy.  If you really want to walk the
walk, protect your own privacy first, run your own mail server,
then write-up and implement a usable design that starts solving
the problems.

I agree that Paul will be able and willing to use end-to-end
encrypted email, I might even send some to him some day, but I
still don't see mass adoption as very likely.


More information about the cryptography mailing list