Re: preventing header tag spoofing without crypto
David Nicol <[email protected]> Mon, 29 Mar 2004 21:33:08 -0600
| Newsgroups | gmane.ietf.asrg.filtering |
|---|---|
| Organization | tipjar LLC |
| Message-ID | <[email protected]> |
I like the idea of including a time stamp in a Tagged: header I prefer discouraging rearranging the Tagged and Received headers over declaring that Tagged headers are supposed to copy time stamps from Received headers. There is a lot of information in Received headers. A human being can easily do sane path verification by reading Received headers. I suppose the various path verification proposals are attempting to automate this, but that discussion is off topic for discussion of the Tagged: header. I think it makes sense to leave it positional, just like the received header. From an implementation viewpoint, it is easy to leave them alone. Write your tags, then write the file just like you got it. Received is prepended when a message arrives. Maybe Tagged would get prepended as a message leaves, so it could be above Received in the headers. Above or below, it doesn't matter, but next to the Received header will remove the risk of spoofing. The fake tags would be farther in than we are expecting them. The first tags will be closer to you. Fake tags will be under the real tags. So what if all the garbage gets tagged "not-garbage" when it is sent, the garbage detector will detect and retag. The tag checker starts at the beginning of the message and trusts the first garbage/not-garbage tag it sees, as that will be the one applied by the last garbage detector that the message passed through. Grouping the tagged headers together in a different part of the message and then having to match them up based on identifying a time-stamp seems to me like a contrived alternative. Adding headers at the beginning of the message and leaving the rest of the message alone is very easy to do. Matching lines up based on fields in them is tricky. The only advantage I see in it is that it would raise the implementatino comlpexity of standard compliance, and I do not consider than an advantage, speaking as a lone implementor. -- [email protected]. I know you, junk mail. Gonna miss you when you're gone