Re: one can re-sign without a permission to re-sign header

Hector Santos <[email protected]> Mon, 05 May 2014 23:29:05 -0400
Newsgroups gmane.ietf.rfc822
Organization Santronics Software, Inc.
Message-ID <[email protected]>
IDEA:  do both

On 5/5/2014 10:41 PM, John R Levine wrote:
>>> You could, but now we're back to whether we believe that list managers
>>> act to keep crud out of their lists.  In general, I observe that they
>>> do, so I don't see any point to adding features that assume that
>>> managers will just sit there and allow subscribers to abuse their
>>> lists.
>>
>> This sounds a lot like what ATPS turned out to be, except that it
>> didn't
>> give much thought to replay protection.  Maybe we can build on that
>> instead?
>
> I'd rather stick with the whitelists, since they can solve more
> problems than the various signtature-transit hacks can.


-- 
HLS


_______________________________________________
ietf-822 mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ietf-822