Re: Mailing lists - assumptions

Pete Resnick <[email protected]> Sat, 19 Apr 2014 17:55:16 -0500
Newsgroups gmane.ietf.rfc822
Message-ID <[email protected]>
On 4/19/14 11:39 AM, John Levine wrote:
>>> I'm not seeing where it addresses bad actors posing as mailing lists.
>>>        
>>
>> Are you worried about me sending to a bad actor and that bad actor
>> re-sending my message plus or minus some modifications to my message?
>> That's what I was trying to capture with 4:
>>      
> The bad actor sends a fake message with a fake return address that
> pretends to be you, with a fake token and fake everything else.
>    

Nope, still don't get it. You're going to have to give me an example. 
Let me start you out:

1. I have an account: [email protected].
2. Yahoo has a policy of that says to reject if the message says it's 
"From: *@yahoo.com" unless:
     a) it came directly come from a yahoo.com server; or
     b) it came from an "example.net" server and it has a token that 
says it was sent directly from [email protected] to "[email protected]".
3. ... [John inserts steps here]
...
n. John get a message from an example.net server that says it's "From: 
[email protected]", and it has a cryptographically verified token that 
indicates that it was sent directly by [email protected] from a yahoo.com 
server directly to [email protected], even though it was just 
example.net faking up my address and using a fake token.

I don't understand how you get there. What does the bad actor do to 
accomplish this?

pr

-- 
Pete Resnick<http://www.qualcomm.com/~presnick/>
Qualcomm Technologies, Inc. - +1 (858)651-4478

_______________________________________________
ietf-822 mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ietf-822