
Some thoughts on security after ten years of qmail 1.0

. Daniel J. Bernstein Department of Mathematics, Statistics, and Computer Science (M/C 249), University of Illinois at Chicago, Chicago, IL 60607­7045, USA, (November 2007)


The qmail software package is a widely used Internet-mail transfer agent that has been covered by a security guarantee since 1997. In this paper, the qmail author reviews the his- tory and security-relevant architecture of qmail; articulates partitioning standards that qmail fails to meet; analyzes the engineering that has allowed qmail to survive this failure; and draws various conclusions regarding the future of secure programming.

Links and resources



  • @tmalsburg
  • @dblp
@tmalsburg's tags highlighted