Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

qmail itself is secure, but qmail without 3rd party patches is pretty much useless. This starts with qmail's delayed bounce behavior and continues with fact that patches are required for the integration of DNS-based blacklists or spam filters.

Once you start to integrate all the patches required to make qmail usable the security track record looks somewhat worse than the one bug found in qmail so far.



Two things.

One, I use DJB's qmail distro and it works fine for me. Yeah, I need a patch to get STARTTLS or (god help me) a DNS RBL. But it's not "pretty much useless" by itself; that's hyperbole.

Second, the semi-official collection of patches you're referring to is called "netqmail". What are the netqmail vulnerabilities to which you refer when you say "the security track record looks..."?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: