MTA-STS
Security
Email security mechanism allowing domains to publish policy requiring TLS for SMTP delivery and preventing downgrade attacks.
Glossary
Plain-language explanations for encryption, tracking, compliance, and security concepts.
Security
Email security mechanism allowing domains to publish policy requiring TLS for SMTP delivery and preventing downgrade attacks.
Authentication
Authentication using multiple factor categories.
Network Privacy
Chained VPN routing through multiple gateways.
Encryption
TLS configuration requiring client certificates, providing strong transport-layer mutual authentication.
Network Privacy
Controls that limit observability and linkability at the network layer and related metadata.
Network Privacy
Protocols, addressing, routing, and transport used to move data between systems (TCP/IP, DNS, TLS, etc.).
Network Privacy
Operational claim limiting retention of identifiable logs.
Authentication
Authorization framework that issues scoped access tokens to clients instead of sharing user credentials.
Encryption
Online Certificate Status Protocol; privacy mitigations include OCSP stapling and short-lived certificates.
Data Management
Backup stored on disconnected media or isolated storage to reduce exposure to online attacks and ransomware.
Security
Software with publicly available source code under an open license; enables review and reuse.
Authentication
Identity layer on OAuth 2.0 providing authentication via ID tokens (typically JWT) from an IdP.
Consent
Consent model where processing occurs only after explicit affirmative action.
Consent
Consent model where processing is enabled by default and users must disable it to stop processing.
Authentication
Passwordless credential based on public-key cryptography, typically stored on a device or synced securely.
Authentication
FIDO/WebAuthn credentials using public-key cryptography for phishing-resistant authentication (often synced across devices).
Threats
Exposure of password material or password hashes.
Security Techniques
Storing and handling passwords securely.
Authentication
Encrypted credential vault and generator.
Authentication
Account recovery flow to set a new credential; must resist takeover via token theft, email compromise, and social engineering.
Security
Credential re-use across relying parties.
Authentication
Authentication model that avoids shared secrets; typically uses public-key credentials or magic links.
Security
Remediation update for known vulnerabilities.
Privacy
US statute expanding investigative authorities; relevant to legal access risk discussions.