Um, how many users use native clients on unencrypted ports as opposed to https based web-clients or TLS?
Um, how many users use native clients on unencrypted ports as opposed to https based web-clients or TLS?
I haven't ran any type of extensive usage statistics but from what I see daily plain-text POP3 (i.e. 110/TCP) is overwhelmingly more popular than anything else. STARTTLS (with both POP3 and IMAP4) is a bit behind that, followed by {POP3,IMAP4}-over-TLS (i.e. 99{5,3}/TCP).
This is probably due to a mostly stable user base that doesn't reconfigure or set up new mail clients often. As new mail clients are installed / configured, they typically use "native TLS" (not STARTTLS) but I think this is likely because of the autoconfig/autodiscovery that most mail clients (especially mobile) support nowadays.
We will hopefully be completely doing away with plain-text mail "soon" but it will require a LOT of reconfiguring of mail clients.
This is why the best thing for most small companies is to just use hosted Google or Microsoft mail.
Encryption at rest is still a difficult UX/UI issue, but encryption during transit seems like something that most mail providers can get behind.
The question of user-level IMAP/POP/SMTP access is different, but I'd expect somewhere in the region of 95+%. Note that the IMAP specification prohibits authentication that sends passwords in the plaintext [1] (although I don't know if the various IMAP servers permit AUTHENTICATE PLAIN before STARTTLS--checking, Outlook doesn't, and the other servers I had access to aren't open on 143 anyways), which means IMAP in practice requires SSL.
[1] The alternative is to use schemes like CRAM-MD5 or SCRAM-SHA-1 which don't send the password in plaintext, although these have become quite rare in practice.
I was certainly surprised by how many users there were when I took over responsibility for such mail systems five years or so ago.
In our case the answer is "thousands" -- and we're relatively small.