TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Gmail will soon stop support for the 3DES encryption cipher for incoming SMTP

48 点作者 gnabgib14 天前

6 条评论

londons_explore14 天前
Don&#x27;t worry - it only took 9 years between 3DES being publicly known to have severe vulnerabilities and Google deciding it isn&#x27;t appropriate for protecting perhaps the most sensitive dataset in the world (private emails).<p>CVE-2016-2183...
评论 #43923676 未加载
评论 #43923418 未加载
评论 #43923888 未加载
评论 #43926542 未加载
评论 #43924039 未加载
评论 #43923658 未加载
评论 #43923559 未加载
评论 #43925977 未加载
评论 #43923878 未加载
评论 #43924411 未加载
wcoenen14 天前
Related note for those surprised that 3DES is still a thing: the Mastercard specifications still use 3DES for pin block encryption. This is used each time you enter the pin for a Mastercard card!<p>There is no alternative yet. Support for AES &quot;coming soon&quot;.<p><a href="https:&#x2F;&#x2F;developer.mastercard.com&#x2F;card-management&#x2F;documentation&#x2F;pin-block-encryption-process&#x2F;" rel="nofollow">https:&#x2F;&#x2F;developer.mastercard.com&#x2F;card-management&#x2F;documentati...</a>
fishgoesblub14 天前
My reading has gotten worse over the years, it took me multiple times re-reading to realise this isn&#x27;t deprecating Gmail on the Nintendo 3DS.
评论 #43923830 未加载
评论 #43923847 未加载
Bender14 天前
Seems like they support more than 3DES. It might be interesting if they shared stats on how many legit MTA&#x27;s are using old ciphers. <i>Should exclude bots, scanners, etc...</i> There are of course other mitigating factors such as PGP encrypting emails, accepting that some information is still disclosed. That can be further mitigated by using gmail to only perform the initial communication then go out of band for anything sensitive.<p><pre><code> SSLv2 not offered (OK) SSLv3 not offered (OK) TLS 1 offered (deprecated) TLS 1.1 offered (deprecated) TLS 1.2 offered (OK) TLS 1.3 offered (OK): final Testing cipher categories NULL ciphers (no encryption) not offered (OK) Anonymous NULL Ciphers (no authentication) not offered (OK) Export ciphers (w&#x2F;o ADH+NULL) not offered (OK) LOW: 64 Bit + DES, RC[2,4], MD5 (w&#x2F;o export) not offered (OK) Triple DES Ciphers &#x2F; IDEA offered Obsoleted CBC ciphers (AES, ARIA etc.) offered Strong encryption (AEAD ciphers) with no FS offered (OK) Forward Secrecy strong encryption (AEAD ciphers) offered (OK) </code></pre> Tested with testssl.sh [1]<p>[1] - <a href="https:&#x2F;&#x2F;github.com&#x2F;testssl&#x2F;testssl.sh">https:&#x2F;&#x2F;github.com&#x2F;testssl&#x2F;testssl.sh</a>
Meekro14 天前
Can someone explain why this is important enough to land on the HN front page? Are people being inconvenienced by this or something?
评论 #43923603 未加载
评论 #43923669 未加载
评论 #43923682 未加载
评论 #43923670 未加载
评论 #43923591 未加载
评论 #43923582 未加载
gpvos14 天前
Does Gmail support receiving unencrypted SMTP? And can you see whether encryption was used during transport?
评论 #43924393 未加载