Comcast Shot Themselves in the Foot with MTA-STS
https://www.agwa.name/blog/post/comcast_shot_themselves_in_the_foot_with_mta-sts

MTA-STS is a relatively new standard that allows domain owners such as Comcast 
to opt in to authenticated encryption for their mail servers. (By default, SMTP 
traffic between mail servers uses opportunistic encryption, which can be 
defeated by active attackers to intercept email.) MTA-STS requires the domain 
owner to duplicate their MX record (the DNS record that lists a domain's mail 
servers) in a text file served over HTTPS. Sending mail servers, like Alex's, 
refuse to contact mail servers that aren't listed in the MTA-STS text file. 
Since HTTPS uses authenticated encryption, the text file can't be altered by 
active attackers. (In contrast, the MX record is vulnerable to manipulation 
unless DNSSEC is used, but people don't like DNSSEC which is why MTA-STS was 
invented.)

The above error messages mean that although mx2h1.comcast.net and 
mx1a1.comcast.net are listed in comcast.net's MX record, they are not listed in 
comcast.net's MTA-STS policy file. Consequentially, Alex's mail server thinks 
that the MX record was altered by attackers, and is refusing to deliver mail to 
what it assumes are rogue mail servers.

However, mx2h1.comcast.net and mx1a1.comcast.net are not rogue mail servers. 
They are in fact listed in Comcast's current MTA-STS policy:

< - >

-- 
Iw mailing list
[email protected]
http://sticklist.org/mailman/listinfo/iw_sticklist.org

Reply via email to