Re: Mailing lists - assumptions

"John R Levine" <[email protected]> 19 Apr 2014 19:15:51 -0400
Newsgroups gmane.ietf.rfc822
Message-ID <[email protected]>
> 1. I have an account: [email protected].
> 2. Yahoo has a policy of that says to reject if the message says it's "From: 
> *@yahoo.com" unless: ...
>    a) it came directly come from a yahoo.com server; or
>    b) it came from an "example.net" server and it has a token that says it 
> was sent directly from [email protected] to "[email protected]".


  From: Pete <[email protected]>
  Subject: all your crypto are belong to us
  To: [email protected]
  Token: [email protected] [email protected] t=now
  List-ID: kripto.rbn.ru
  DKIM-Signature: --- d=rbn.ru ... (100% genuine and valid)

  IESG is saying that all crypto will to use new improved NKVD-1024
  algorithm.

  Mir,
  Pete

How can you tell the Token: is a fake if it's not signed?  You can't tie 
it to the contents of the message, or you've just reinvented the DKIM hash 
issues.

Since most people have no idea what a discussion list looks like, it's 
just a phish that looks a whole lot like it's from you.

R's,
John

_______________________________________________
ietf-822 mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ietf-822
smime.p7s (application/pkcs7-signature, 2.2 KB) - not displayed