Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> the grocery store

Funny enough, the only digitally signed email I've ever (knowingly) received came from Aldi. I sent them a question about food waste and the response showed up in Apple Mail with a badge and signature validation notice that I'd never seen before.



That's most likely BIMI with DKIM (DKIM alone is relatively common) but it's unfortunately not S/MIME. Latter would actually be a "sender signed email" rather than former, "domain signed email".


I went back and searched my email. It was an RSA-2048 S/MIME certificate issued by Aldi Süd and Apple Mail now warns that the certificate is expired (the email was from a few years ago, when the certificate was valid). The email came from a supply chain person in their Hong Kong office - maybe that explains the level of security?


Huh, that is very interesting (and rare). Also highlights one flaw of S/MIME, there isn't any validity (OCSP) stapling equivalent for it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: