psa, 37C3 

To folks going to 37C3: Don't visit the talk about SMTP smuggling. The authors of it have not done responsible disclosure to postfix about a security vulnerability with some configurations (default configurations, in fact). Let them have empty seats.

re: psa, 37C3 

@kescher Like seriously, I'd respect them more if they wouldn't notify anyone, instead of only notifying the corpos…

re: psa, 37C3 

@ar @kescher Is there somewhere I can read more about this?

re: psa, 37C3 

@kescher @ar The "oh we didn't realize we had to look further after Cisco told us it's fine" seems extremely disingenuous given that the research specifically identifies postfix as a large affected implementations (and given that they seemed to disagree with Cisco's assessment anyway)

· · Web · 0 · 0 · 1
Sign in to participate in the conversation
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.