Re: Mailing lists - assumptions

Alessandro Vesely <[email protected]> Sun, 20 Apr 2014 13:02:31 +0200
Newsgroups gmane.ietf.rfc822
Message-ID <[email protected]>
On Sun 20/Apr/2014 01:18:02 +0200 John R Levine wrote:
>> n. John get a message from an example.net server that says it's "From:
>> [email protected]", and it has a cryptographically verified token that
>> indicates that it was sent directly by [email protected] from a yahoo.com
>> server directly to [email protected], even though it was just
>> example.net faking up my address and using a fake token.
> 
> Now I'm really confused.  Untill a few minutes ago I was saying the
> token has to be signed, and you were (as far as I can tell) saying it
> doesn't. Now we seem to agree.

Signed by who?

Let me copy the exemplified token below:

   May-Resign: [email protected]; r=ietf.org; s=foo; a=rsa-sha256; \
      t=1397786669; b=hashhashhash

There is an implied d=yahoo.com there, used to recover the key.  Since
the key is published by yahoo.com, we can regard the token as signed by
them.

Note that using such token (or an equivalent signature) disallows known
tricks such as posting as another subscriber --unless both subscribers
belong to a same domain which allows changing From: liberally.

Ale

_______________________________________________
ietf-822 mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ietf-822