"Everyday you get electricity, water, transportation, food, and general survival are dependant on horrifically outdated software systems that aren't going to be changed any time soon"
I always considered it the best solution to have both: VPN encryption and TLS encryption over the VPN. Different OSI Layers. Different Attack Surfaces.
Not sure if that is a recommended pratice though (see initial remark ;) )
POP3 over stunnel -> SPOP3.
A practical solution, both for legacy components and for the cases when you don't want to deal with implementing TLS natively.
Ultimately, it's very Unix in spirit. Does one specific thing and is composable with others.
The security standard changes/improves over time. With software like stunnel takes care of it, your software could be practically security wise up-to-day forever as long as you or your user keeps their stunnel updated.
The most obvious issue is that if any system is compromised, then the attacker can potentially sniff traffic and they are all effectively compromised. The next one, and it’s really key to TLS, is that the app you are proxying probably has an opinion or desired behavior when things can’t be authenticated or are improper. Someone reading you blog and the cert is a day old? Probably not super risky to let them read it. Logging in to the mail server and the keys are bad? You might want the server to just block that.
For like a home lab situation or kind of toy systems? These tools are great, I’ve used stunned more than a few times to hack things together
Edit: I put stunnel on port 443 and have it connect to port 80 on my Apache webservers, because I like one way of doing TLS.
This guide has been useful for many years in cipher selection:
https://hynek.me/articles/hardening-your-web-servers-ssl-cip...
Just slap an HTTPS proxy on top of an pure HTTP server. It's simpler to debug and understand.
Otherwise you need to learn how to slap SSL onto 10 different HTTP things.
I've found stunnel a godsend for bridging the gap. Granted, I am more of a sysadmin-ey type where a few times I've had to abruptly/quickly get something up and running.