Re: [ietf-smtp] [Shutup] Compressing SMTP streams

2016-02-09 11:35:56
John Levine <johnl(_at_)taugh(_dot_)com> wrote:
If you can identify an auto-responder which sends using SMTP AUTH PLAIN or
LOGIN, and if the SMTP AUTH and message envelope are in the same
compression context, you can use the coupling between the credentials and
your choice of recipient address to attack the credentials.

Wouldn't my CDAT that only compresses the data prevent that?

Yep! :-)

