Re: A permission to re-sign header
"John Levine" <[email protected]> 18 Apr 2014 12:37:21 -0000
| Newsgroups | gmane.ietf.rfc822 |
|---|---|
| Message-ID | <[email protected]> |
>Even with the local part (marissam) an M-R is not really hard to >forge, otherwise DKIM-Signature wouldn't have had to include all the >other tags. If we worry about replay attacks, we can enhance M-R so >that it includes them too. For example, we could make M-R exactly >like a regular DKIM-Signature, except that it would be a very very >weak one, something that the MLM won't break. BTDT. If we could invent a weak signature that the MLM won't break, we wouldn't have this problem. The M-R token is signed so it should be impossible to forge, and we don't expect anyone to change it in transit. I also note that this hack, with or without Ale's changes, does nothing to solve the send from gmail and WSJ article problems. R's, John _______________________________________________ ietf-822 mailing list [email protected] https://www.ietf.org/mailman/listinfo/ietf-822