Re: Mailing lists - assumptions
"John R Levine" <[email protected]> 19 Apr 2014 19:15:51 -0400
| Newsgroups | gmane.ietf.rfc822 |
|---|---|
| Message-ID | <[email protected]> |
> 1. I have an account: [email protected]. > 2. Yahoo has a policy of that says to reject if the message says it's "From: > *@yahoo.com" unless: ... > a) it came directly come from a yahoo.com server; or > b) it came from an "example.net" server and it has a token that says it > was sent directly from [email protected] to "[email protected]". From: Pete <[email protected]> Subject: all your crypto are belong to us To: [email protected] Token: [email protected] [email protected] t=now List-ID: kripto.rbn.ru DKIM-Signature: --- d=rbn.ru ... (100% genuine and valid) IESG is saying that all crypto will to use new improved NKVD-1024 algorithm. Mir, Pete How can you tell the Token: is a fake if it's not signed? You can't tie it to the contents of the message, or you've just reinvented the DKIM hash issues. Since most people have no idea what a discussion list looks like, it's just a phish that looks a whole lot like it's from you. R's, John _______________________________________________ ietf-822 mailing list [email protected] https://www.ietf.org/mailman/listinfo/ietf-822
smime.p7s
(application/pkcs7-signature, 2.2 KB) - not displayed