Re: A permission to re-sign header

"John Levine" <[email protected]> 18 Apr 2014 12:37:21 -0000
Newsgroups gmane.ietf.rfc822
Message-ID <[email protected]>
>Even with the local part (marissam) an M-R is not really hard to
>forge, otherwise DKIM-Signature wouldn't have had to include all the
>other tags.  If we worry about replay attacks, we can enhance M-R so
>that it includes them too.  For example, we could make M-R exactly
>like a regular DKIM-Signature, except that it would be a very very
>weak one, something that the MLM won't break.

BTDT.  If we could invent a weak signature that the MLM won't break,
we wouldn't have this problem.  The M-R token is signed so it should
be impossible to forge, and we don't expect anyone to change it in
transit.

I also note that this hack, with or without Ale's changes, does
nothing to solve the send from gmail and WSJ article problems.

R's,
John

_______________________________________________
ietf-822 mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ietf-822