A Technical Deep Dive into STARTTLS Everywhere

Although many mailservers enable STARTTLS, most still do not validate certificates. Without certificate validation, an active attacker on the network can read and even modify emails sent through your supposedly “secure” connection.

Read full news article on Electronic Frontier Foundation