Re: Summary of Issues Raised to date
Philip Miller <[email protected]> Tue, 16 Mar 2004 22:24:47 -0500
| Newsgroups | gmane.ietf.asrg.filtering |
|---|---|
| Message-ID | <[email protected]> |
Laird Breyer wrote: > On Mar 16 2004, Philip Miller wrote: >>I just had a thought: Is there any reason that respondents should want the >>tags to appear in outgoing response messages? Is there any reason that a > > Just for the record (it's obvious, and you probably don't mean that): No, I really do mean what I wrote. To be more blunt: there's no reason one person's tags should be visible to any other person. (with the obvious exception of 'tagging collaboration' between them, which we've not yet dealt with; perhaps 'cooperation in labelling' should become a work item?) > A practical reason? The MUA is probably not aware of the tag in the > subject, certainly not if the message was proxied transparently by > some filter like POPFile. So obviously, the tag is part of the subject > from the MUA pov, and gets copied out again when a reply is sent. If the MUA is using the standardized tags to make a filtering decision on receipt, it should be quite capable of parsing out and removing those same tags on transmission. > In an ideal world, tags should be stripped at the sender end, too, but > that requires getting all the MUAs to do something new. If the filter > strips tags whenever it sees them, you're half way there without > requiring work from other players. If they do it too it's a bonus. I agree 100% with this. Any extra cooperation is a desirable bonus indeed. >>message originator should see how his recipient(s) tagged it? >>I think these 2 cases provide a strong justification for stripping/replacing >>tags at the recipient end, and stripping tags at the sender side. > > You seem to argue more in terms of privacy. That's a good justification for > stripping. Privacy is one justification, but I was thinking foremost in terms of utility: what use does one person have for the tags used by the person they're communicating with? > In fact, your point opens yet another issue: If spammers hijack a relay > and read messages in transit, they can in principle learn what sorts of > tagging is done on messages to and from an organization, and then they > can mass spoof those tags in their own mails. It's debatable whether > that's effective, but it's an attack vector. If spammers hijack a relay trusted by any number of people in an arbitrary role, we have bigger worries than the spammer scanning tags coming through and spoofing them. Philip Miller