On Monday 12 October 2020 13:04:17 CEST, Sam Varshavchik wrote:
On Mon, Oct 12, 2020 at 3:34 AM Claus Assmann <ietf-smtp(_at_)esmtp(_dot_)org>
wrote:
If STARTTLS is used, they shouldn't be able to do it, unless they
mess with SMTP (or much worse: with TLS), right?
They intercept outbound port 25, and simply don't advertise STARTTLS.
Only STS will catch that.
See https://toroid.org/vodafone-smtp-mitm for example. Vodafone India makes
it so that when mobile phones connect to SMTP servers outside Vodafone's
network, they simply don't receive any STARTTLS advertisement.
Arnt
_______________________________________________
ietf-smtp mailing list
ietf-smtp(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/ietf-smtp