Re: antiphishing idea

Paul Smith <[email protected]>
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On 17/11/2011 23:27, Seth wrote:
> Christian Grunfeld<[email protected]>  wrote:
>
>> sorry, I meant both of them ! you are obviously going to get the
>> validation from the evil domail but you also need one from phished
>> domain. The last one is only true if the mail was sent by paypal.com
> No, it's true only if _any_ message was sent by paypal.com with that
> Message-ID.  Copying a Message-ID isn't difficult, nor is getting
> legitimate mail from paypal.
>

So, you put the message-id AND recipient in the source's database

If evil spammer/phisher gets Paypal to send him a message, then reuses 
that message-id in their own messages out, it would work with the 
original idea, but if you add the recipient to the data, you defeat that.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.