Re: Mailing lists - assumptions
Jim Fenton <[email protected]> Fri, 18 Apr 2014 13:00:45 -0700
| Newsgroups | gmane.ietf.rfc822 |
|---|---|
| Message-ID | <[email protected]> |
On 4/18/14 12:49 PM, Pete Resnick wrote: > On 4/18/14 2:38 PM, Jim Fenton wrote: >> I'm not seeing where it addresses bad actors posing as mailing lists. >> > > Are you worried about me sending to a bad actor and that bad actor > re-sending my message plus or minus some modifications to my message? > That's what I was trying to capture with 4: > >> 4. If an originating site allows its users sending mail to mailing >> lists at all, the site is OK with *any* mailing list re-distributing >> mail from its users. so long as the mailing list received the mail >> directly from the originating user through the originating site. That >> is, originating sites don't care about pre-vetting mailing lists; >> they just care that the mail sent by mailing lists came directly from >> their users. > > So, if you get mail that says "From: [email protected]" and > was sent by "[email protected]", *and it has the > appropriate token*, you know that I sent mail to > [email protected]. Do you think we need to address more > than that? I hadn't fully understood how the token thing worked. That probably addresses the most basic part of my concern (that bad actors could simply invent messages that looked like they were sent to mailing lists). But these days, it's not much of an effort, using malware, for a bad actor to get a user in some domain to send a message to an arbitrary address. Then the bad actor has a token, and can use it for their campaign. That particular attack might be declared out-of-scope, but I want to point it out. -Jim _______________________________________________ ietf-822 mailing list [email protected] https://www.ietf.org/mailman/listinfo/ietf-822