logoalt Hacker News

paxystoday at 3:50 PM2 repliesview on HN

Cool try explaining any of these terms to the average sysadmin.

Email security is hopelessly broken, and the best you can do is try to limit exposure. Removing Gmail as an attack vector is one of those decisions.


Replies

john_strinlaitoday at 3:52 PM

>Cool try explaining any of these terms to the average sysadmin.

if someone is managing a mail system and doesn't know what spf is, they should be immediately fired.

i am also not convinced this will remove or limit exposure to anything. the attack vector lives in the protocol, not the service used.

this might end up as a tiny, tiny blip in some small percentage of spammer/phisher operations.

icedchaitoday at 4:13 PM

Yep, SMTP itself doesn't have any security.

Anyone else remember the open SMTP relays of the 90's?

show 1 reply