Re: Source routing -- why not?

Tony Finch <[email protected]>
Newsgroups gmane.ietf.mxcomp
Message-ID <[email protected]>
On Tue, 30 Nov 2004, Alex van den Bogaerdt wrote:
> On Tue, Nov 30, 2004 at 10:43:40AM +0000, Tony Finch wrote:
>
> > > After further deliberation about source routing and SPF, I have come
> > > around to the conclusion that Frank is to some degree right, and if
> > > you want to use SPF/Sender-ID, you should use source routes.
> >
> > Source routes require all mail servers to be open relays.
>
> Why?

Source routes don't record the relationship between a@a, b@b, and c@c. In
your scenario the message to c@c would start MAIL FROM:<@b:a@a>. A spammer
who knows that b is a forwarding host can then spam anyone by sending MAIL
FROM:<> RCPT TO:<@b:victim@target>.

This is why SRS has all the cryptography, in order to provide a secure
replacement for the obsolete and unimplemented RFC821 forward and reverse
paths.

Tony.
-- 
f.a.n.finch  <[email protected]>  http://dotat.at/
MALIN HEBRIDES: NORTHEAST 4 OR 5 INCREASING 6. RAIN LATER. GOOD BECOMING
MODERATE.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.