LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-29-2017, 02:11 AM   #1
hazel
LQ Guru
 
Registered: Mar 2016
Location: Harrow, UK
Distribution: LFS, AntiX, Slackware
Posts: 7,567
Blog Entries: 19

Rep: Reputation: 4447Reputation: 4447Reputation: 4447Reputation: 4447Reputation: 4447Reputation: 4447Reputation: 4447Reputation: 4447Reputation: 4447Reputation: 4447Reputation: 4447
Not such a secure email server!


Some of you may have heard of nomx, a box that you plug in to act as a local email server. It can talk directly to other nomx boxes, bypassing the usual relay servers in the cloud. It's also supposed to be able to talk to standard email servers if the person you are sending to doesn't have a nomx.

Well, it's not what it's cracked up to be. Inside the nomx is a plain old raspberry pi. If you have physical access to the box, you can easily open it and do what you like with it. Worse still, it runs Raspbian Wheezy, so all the software is way out of date.

And if an unskilled person tries to use it, they won't be able to receive mail from any cloud email server because those all use port 25 for smtp and nomx, by default, doesn't. It gets worse: most email servers won't accept outgoing email from any would-be server that has a dynamic ip address. You get put straight on the Spamhaus list. So you can't send and you mostly can't receive either -- except when talking to other nomx users. Not much fun, hey?

I got this from the BBC's Click program, but you can read a full rundown on https://arstechnica.com/information-...ions-protocol/

Last edited by hazel; 04-29-2017 at 02:13 AM.
 
Old 04-29-2017, 05:56 AM   #2
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
nomx have posted an explanation on their website; it's really bad, the classical "our consumers don't need to worry their pretty little heads about this".
they also never really say who they're talking about, but it's pretty clear that it's all about the above arstechnica article.
the statement hinges on the argument that "this is not something a typical user would do" (i.e. unscrew the lid and take out the memory card).
they focus on the sole aspect of nomx being hackable only locally by a malicious hacker and completely ignore Scott Helme's main point, that nomx is simply an outdated linux mail server in a raspi, in other words they're selling hot air.

anyhow, read both - nomx charmingly unprofessional defense, and the arstechnica article. it's 3 pages, but there's some good giggles in it.
 
Old 04-29-2017, 07:24 AM   #3
hazel
LQ Guru
 
Registered: Mar 2016
Location: Harrow, UK
Distribution: LFS, AntiX, Slackware
Posts: 7,567

Original Poster
Blog Entries: 19

Rep: Reputation: 4447Reputation: 4447Reputation: 4447Reputation: 4447Reputation: 4447Reputation: 4447Reputation: 4447Reputation: 4447Reputation: 4447Reputation: 4447Reputation: 4447
The tone of the Nomex rebuttal reminds me irresistibly of Donald Trump!
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: How to configure and secure your postfix email server LXer Syndicated Linux News 0 08-26-2014 05:10 AM
Create secure email server jefro Linux - Server 7 03-31-2012 12:31 PM
Secure messaging using one single email server xri Linux - Software 1 10-30-2009 12:44 AM
Email Server for remote users, can it be secure? javiergt Linux - Software 2 02-04-2005 09:44 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:02 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration