Re: one can re-sign without a permission to re-sign header

"Murray S. Kucherawy" <[email protected]> Mon, 5 May 2014 19:34:27 -0700
Newsgroups gmane.ietf.rfc822
Message-ID <CAL0qLwZ51pKQSOmf=WCiZbLSn3V8khKghgat8i9KRihjzor0dA@mail.gmail.com>
On Mon, May 5, 2014 at 7:01 PM, John Levine <[email protected]> wrote:

> >That would provide some replay protection, especially if the forwarder
> >checks for duplicate message-ids (the recipient could also check for
> >dupes). Without it, I could see one of your messages on a list, then
> >send messages to everyone on the list, pretending to be you.
>
> You could, but now we're back to whether we believe that list managers
> act to keep crud out of their lists.  In general, I observe that they
> do, so I don't see any point to adding features that assume that
> managers will just sit there and allow subscribers to abuse their
> lists.
>

This sounds a lot like what ATPS turned out to be, except that it didn't
give much thought to replay protection.  Maybe we can build on that instead?

-MSK

_______________________________________________
ietf-822 mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ietf-822