To folks going to 37C3: Don't visit the talk about SMTP smuggling. The authors of it have not done responsible disclosure to postfix about a security vulnerability with some configurations (default configurations, in fact). Let them have empty seats.
re: psa, 37C3
@joepie91 @ar Yes.
https://www.mail-archive.com/postfix-announce@postfix.org/msg00090.html
and of course, the blog of the wrongdoers: https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/