Добро пожаловать, Гость. Пожалуйста авторизуйтесь здесь.
FGHIGate на GaNJa NeTWoRK ST@Ti0N - Просмотр сообщения в эхоконференции FTSC_PUBLIC
Введите FGHI ссылку:


Присутствуют сообщения из эхоконференции FTSC_PUBLIC с датами от 13 Sep 13 18:57:24 до 01 Apr 24 01:17:44, всего сообщений: 7124
Ответить на сообщение К списку сообщений Предыдущее сообщение Следующее сообщение
= Сообщение: 4964 из 7124 ====================================== FTSC_PUBLIC =
От   : Alan Ianson                      1:153/757          22 Nov 19 13:16:22
Кому : Oli                                                 22 Nov 19 13:16:22
Тема : FTSC
FGHI : area://FTSC_PUBLIC?msgid=1:153/757+5dd85235
На   : area://FTSC_PUBLIC?msgid=2:280/464.47@fidonet+5dd84bdc
= Кодировка сообщения определена как: UTF-8 ==================================
Ответ: area://FTSC_PUBLIC?msgid=2:292/854+192b423a
Ответ: area://FTSC_PUBLIC?msgid=2:280/464.47@fidonet+5dd86046
==============================================================================
Hello Oli,

AI>> They do, and both mailers work very well with that encryption. Do
AI>> mailers that support CRYPT need to negotiate a session and
AI>> exchange passwords before the session can be encrypted?

Ol> Yes, you need a shared session password. It's also not a completely
Ol> encrypted transmission.

This was a good start at the time it was implemeneted.

AI>> Mystic has the ability to encrypt binkp sessions also (it uses
AI>> cryptlib) although it hasn't fully matured and needs work.

Ol> AFAIK it uses opportunistic TLS (like STARTTLS). The Internet is
Ol> moving away from opportunistic encryption (RFC 8314, "Cleartext
Ol> Considered Obsolete"). Mystics implementation is already a lame duck.

Ol> https://en.wikipedia.org/wiki/Opportunistic_TLS#Weaknesses_and_mitigat
Ol> ions

Yes, James said that he used this method as a start because we still need to
use the current method when encryption is not supported at both sides of the
link. The idea (when it's possible) is to move away from opportunitic TLS.

AI>> Would binkp over TLS (or really, any secure method) be a good
AI>> thing?

Ol> Why wouldn't it? :)

I can't think of a reason. If we could get something to test we could discover
what works, what doesn't, and in time a standard method of doing this could be
established.

Then the FTSC could publish a standard. :)

 Ttyl :-),
         Al

--- GoldED+/LNX 1.1.5-b20180707
* Origin: The Rusty MailBox - Penticton, BC Canada (1:153/757)

К главной странице гейта
Powered by NoSFeRaTU`s FGHIGate
Открытие страницы: 0.048459 секунды