Re: Mailing lists - assumptions
Pete Resnick <[email protected]> Sat, 19 Apr 2014 17:55:16 -0500
| Newsgroups | gmane.ietf.rfc822 |
|---|---|
| Message-ID | <[email protected]> |
On 4/19/14 11:39 AM, John Levine wrote: >>> I'm not seeing where it addresses bad actors posing as mailing lists. >>> >> >> Are you worried about me sending to a bad actor and that bad actor >> re-sending my message plus or minus some modifications to my message? >> That's what I was trying to capture with 4: >> > The bad actor sends a fake message with a fake return address that > pretends to be you, with a fake token and fake everything else. > Nope, still don't get it. You're going to have to give me an example. Let me start you out: 1. I have an account: [email protected]. 2. Yahoo has a policy of that says to reject if the message says it's "From: *@yahoo.com" unless: a) it came directly come from a yahoo.com server; or b) it came from an "example.net" server and it has a token that says it was sent directly from [email protected] to "[email protected]". 3. ... [John inserts steps here] ... n. John get a message from an example.net server that says it's "From: [email protected]", and it has a cryptographically verified token that indicates that it was sent directly by [email protected] from a yahoo.com server directly to [email protected], even though it was just example.net faking up my address and using a fake token. I don't understand how you get there. What does the bad actor do to accomplish this? pr -- Pete Resnick<http://www.qualcomm.com/~presnick/> Qualcomm Technologies, Inc. - +1 (858)651-4478 _______________________________________________ ietf-822 mailing list [email protected] https://www.ietf.org/mailman/listinfo/ietf-822