Re: Realisticness of header rearrangement

Bill Yerazunis <[email protected]> Tue, 6 Apr 2004 06:34:37 -0400
Newsgroups gmane.ietf.asrg.filtering
Message-ID <[email protected]>
   From: Laird Breyer <[email protected]>

   On Apr 05 2004, david nicol wrote:

   > 
   > And the second use isn't a time stamp any more, therefore its confusing.
   > An explicit event-ID would be clearer (not confusing as a timestamp
   > being
   > used for something other than marking the time something happened))

   The received time stamp is only a hack, but it's the only one that has
   a hope of working. 

Unless each filter is trusted to re-edit timestamps of the incoming
text, recieved time stamps are forgeable.

I'm still puzzled.  It seems to me that the simple solution is to 
work on the assumption that the spammer _CAN_ forge any header;
they just can't remove headers that are already present.

In that case, the obvious solution is to have all prefilters either
say nothing, or say "spam" (and perhaps some quantification of that).

With that doctrine, a spammer -cannot- forge a useful header; they
can only hurt themselves.

It also means that a user won't see a lot of added crud in the headers
for good messages.

Is there any reason (beyond the fact that it means a filter can't say
anything good) that this doctrine has been ignored?

	 -Bill Yerazunis