Re: one can re-sign without a permission to re-sign header
"Murray S. Kucherawy" <[email protected]> Mon, 5 May 2014 19:34:27 -0700
| Newsgroups | gmane.ietf.rfc822 |
|---|---|
| Message-ID | <CAL0qLwZ51pKQSOmf=WCiZbLSn3V8khKghgat8i9KRihjzor0dA@mail.gmail.com> |
On Mon, May 5, 2014 at 7:01 PM, John Levine <[email protected]> wrote: > >That would provide some replay protection, especially if the forwarder > >checks for duplicate message-ids (the recipient could also check for > >dupes). Without it, I could see one of your messages on a list, then > >send messages to everyone on the list, pretending to be you. > > You could, but now we're back to whether we believe that list managers > act to keep crud out of their lists. In general, I observe that they > do, so I don't see any point to adding features that assume that > managers will just sit there and allow subscribers to abuse their > lists. > This sounds a lot like what ATPS turned out to be, except that it didn't give much thought to replay protection. Maybe we can build on that instead? -MSK _______________________________________________ ietf-822 mailing list [email protected] https://www.ietf.org/mailman/listinfo/ietf-822