12
email TLS question
(lemmy.ml)
I think they're saying that TLS isn't used for submitting an email for outbound delivery and that both the webmail and initial SMTP servers are on the same internal network.
Sounds reasonable to me. What would TLS gain there?
The gain would be that an attacker having a foothold on the internal network (by having a physical access or hacking a device on it) would be able to sniff and modify outgoing emails.
I'm a bit sceptical about the performance claim on modern hardware.
That said it's not a completely unreasonable tradeoff.
If an attacker is already inside and has access to a server, they have bigger problems to worry about.
A community for technical news and discussion of cybersecurity and closely related topics.