The 2017 Pwnie Nominee For Lamest Vendor Response

Callisto NOMX

Credit: Scott Helme and Alan Woodward / Will and Shawn

Claiming to be the “World’s Most Secure Communications Protocol,” the Calisto NOMX is a secure email appliance built from a Raspberry Pi in a fancy case with hilarious default passwords using self-signed keys from other projects, forking an open source project that has been unmaintained since 2009. True to its name, it makes no MX records, so outbound messages–including some convenient responses to the bug reporters!–are routinely blocked as spam by every other email provider.

We tried to read the vendor’s side of the story at, but found only a conveniently verbose SQL error.

Callisto NOMX