Skip to Content [alt-c]
In reply to Comment by Reader Jarek
So am I right to understand that the DANE record would say "this SMTP server supports TLS" and therefore a client would not accept an unencrypted connection with this server even if the server responds it does not support TLS.
But the article says that "it's trivial for a properly-programmed client to protect against this downgrade attack". I presume the author wasn't referring to using DANE records (which as you point is not widely supported)?
Reply
Your comment will be public. To contact me privately, email me. Please keep your comment polite, on-topic, and comprehensible. Your comment may be held for moderation before being published.
Your Name: (Optional; will be published)
Your Email Address: (Optional; will not be published)
Your Website: (Optional; will be published)
>
monospaced
Post a Reply
Your comment will be public. To contact me privately, email me. Please keep your comment polite, on-topic, and comprehensible. Your comment may be held for moderation before being published.