NDSS 2025 – A Multifaceted Study On The Use of TLS And Auto-detect In Email Ecosystems
ID: 60d3cf91-c9b0-51ae-ae9a-120b4ca0b936
STIX ID: report--60d3cf91-c9b0-51ae-ae9a-120b4ca0b936
Feed Name: Security Boulevard
This paper presents a multifaceted study of TLS usage and "auto-detect" configuration in email clients: the authors tested 49 clients, analyzed 1,102 institutional email setup guides, and assessed server-side TLS and certificate characteristics. They uncovered client-side implementation flaws and widespread insecure deployment practices that can lead to covert downgrade attacks and potential exposure of user credentials, and recommend organizations provide concrete, detailed manual configuration guidance to avoid these pitfalls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
