Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FAQ: general security/privacy issues #20

Closed
ghost opened this issue Apr 1, 2023 · 1 comment
Closed

FAQ: general security/privacy issues #20

ghost opened this issue Apr 1, 2023 · 1 comment

Comments

@ghost
Copy link

ghost commented Apr 1, 2023

Hello everyone!

disclaimer

  • I would like to know how the aspect of the security layer, privacy of the tmtp protocol works. So, recently, I read some reports or experiences about the security layer of tmtp. And I would like to know if the reports or experiences shown here make sense.
  • I'm confused to understand how the tmtp protocol works, maybe I don't have much knowledge in networks or network protocols. I say that I'm confused, because I didn't find relevant information about the doubts I have here. Note: I plan to someday use the tmtp protocol for a use case.
  • Perhaps the security information is not enough to understand the security aspect of tmtp yet. I believe my question can help many users. If someone can answer my questions, I would be happy for any answer.
  • The purpose of my question being related to the report or experience I leave here is to bring useful information to anyone interested in the mnm protocol. I say this because I don't want you all to think that such a report or experience told here serves only as an empty or baseless criticism.
  • I would like to say that I have a genuine doubt to understand how things work, why they work and why they are important or not.
  • I searched the internet for everything I could find about reports or experiences with tmtp and found this one.

report and experience

"SMS is really any more secure than email with TLS. phone provider can read it as well, same as email providers when the emails are not encrypted.

Also you just need one malicious app on your phone that has the sms reading permission, or sometimes an attacker just needs one call to your tel-co provider to convince them to send them a replacement sim card which they can use to read all your sms and steal all your accounts that are foolish enough to consider SMS a second factor.

So no SMS is not really more secure or private than email with TLS transport encryption between providers (which is standard these days).

Now about tmtp, if you read their site you will notice that it’s completely different from email architecture wise. It’s not compatible with email the way POP and JMAP are. Also the companies can directly collect the user’s ip address (and thus also their rough location), because users connect directly to the companies server. Also TMTP is for business <-> customer, not for normal usage from what I can tell."

general questions

  1. Does this report or experience make sense?
  2. How is tmtp protocol better than email with tls?
  3. Is the tmtp network protocol an alternative to the smtp network protocol or is it similar to the smtp network protocol?
  4. Why cant tmtp be compatible with JMAP and POP?
  5. Is there any way to add pop and jmap compatibility to tmtp?
  6. Is the tmtp network protocol only for business? or could it be used for end users too?
  7. Can companies directly collect user's IP address and approximate location with tmtp?
  8. Is it possible to use things like proxy, vpn, tor in tmtp to avoid approximate location?
  9. What are tmtp security recommendations for better use?
  10. TMTP is more secure than email? if yes, why?
  11. What are the use cases that tmtp could not or should not be used?
  12. Is tmtp similar to IRC network protocol?
  13. tmtp is a non-realtime chat?
  14. how does tmtp prevent things like spam?
  15. what are the pros and cons of tmtp?
  16. Is it necessary to use Things like email use PGP: Pretty Good Privacy, for encrypting messages in tmtp?
  17. what are the algorithms used to encrypt messages in tmtp?

If anyone can answer one or more questions. I will be happy, for any answer.

@ghost ghost changed the title FAQ: mention security vs off-topic FAQ: mention security vs off-topic vs issues security/privacy Apr 1, 2023
@ghost ghost changed the title FAQ: mention security vs off-topic vs issues security/privacy FAQ: mention security and issues security/privacy Apr 1, 2023
@ghost ghost changed the title FAQ: mention security and issues security/privacy FAQ: mention security aspect and general security/privacy issues Apr 1, 2023
@ghost ghost changed the title FAQ: mention security aspect and general security/privacy issues FAQ: mention general security/privacy issues Apr 1, 2023
@ghost ghost changed the title FAQ: mention general security/privacy issues FAQ: general security/privacy issues Apr 1, 2023
@networkimprov
Copy link
Owner

Closed for post & ghost.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant