Re: Mailing lists - assumptions

"John R Levine" <[email protected]> 20 Apr 2014 12:14:38 -0400
Newsgroups gmane.ietf.rfc822
Message-ID <[email protected]>
>> Now I'm really confused.  Untill a few minutes ago I was saying the token 
>> has to be signed, and you were (as far as I can tell) saying it doesn't. 
>> Now we seem to agree.
>
> No, you must have misunderstood. I always agreed that the token had to be 
> signed. I only disagreed that there had to be some sort of "re-signing" of 
> the original message, or that anything that the originator sent needs to 
> sent, unmolested, to the list recipients.

Oh, no argument there.  The list (or whatever) signs what it sends, 
including the token.  A sufficiently malicious forwarder could screw it up 
but we appear to agree that either we don't think that it's a problem, or 
it's not a problem we can solve.

If it actually is a problem, we're back to whitelisting mailing lists and 
mailing list like things, and all the other mechanism other than perhaps 
VBR to hint about where to look for the whitelist is superfluous.

R's,
John

_______________________________________________
ietf-822 mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ietf-822