top | item 43924039

(no title)

entropyie | 9 months ago

Unless folks are regularly sending 32GB emails, this CVE is not severe in this context.

discuss

order

jeroenhd|9 months ago

You don't need to send 32GB of emails, you only need to send 32GB of traffic. Setting up a TLS connection and sending EHLOs ad infinitum can generate traffic without hitting any "message size < 8MiB" filters.

jsnell|9 months ago

What's the threat model here? A scenario where the attacker controls the plaintext being sent but doesn't know what the plaintext is seems quite unlikely.

entropyie|9 months ago

If it's your connection, why on earth would you want to break the crypto? You already have the keys and the message...

danielbln|9 months ago

I try to keep all of my mails to just under 31GB.