Re: [ietf-smtp] Compressing SMTP streams

2016-01-29 07:33:53
John Levine <johnl(_at_)taugh(_dot_)com> wrote:

I was hoping we could get this for free with TLS, but few libraries
implement it and seems to have made
them leary about it.  I don't think SMTP is implicated because it doesn't
use cookies/etc, but anyways.

I agree that the CRIME cookie issue seems irrelevant to SMTP since
there isn't any context saved from one session to the next.

I'm not so sure.

You might be able to perform a CRIME attack against SMTP AUTH if you can
cause an AUTH user to send messages with envelope addresses under your
control, for instance if the AUTH user has an auto-responder.

