Re: Reposted Comments on SCMP ( by Graham Klyne )
John Stracke <[email protected]> Tue, 01 Jun 1999 15:48:51 +0000
| Newsgroups | gmane.ietf.scmp |
|---|---|
| Message-ID | <[email protected]> |
bartley.o'[email protected] wrote: > I suggest that ALL the SCMP header fields should be encapsulated within an > encrypted MIME body part with nothing more than > the minimum MIME headers required for delivery appearing outside the message > body. In particular, no message-id and no from. If it's going by email, it had better have a From:; otherwise email failures won't be reported--plus it's liable to be treated as spam. Leaving off the Message-Id: has similar potentially dire effects on the mail infrastructure, for which reason most MTAs will add a Message-Id: when they forward a message that doesn't have one. If it's going by HTTP, these fields aren't necessary. > The from > is only really needed to provide a human readable > identity for mail applications.) Not so--it's also needed to make sure mail gets delivered smoothly. > An easily readable name gives instant knowledge to an attacker of the existence > of a relationship between the sender and receiver. Yeah, but so does simple traffic monitoring. -- /=============================================================\ |John Stracke | My opinions are my own | S/MIME & HTML OK | |[email protected]|============================================| |Chief Scientist | NT's lack of reliability is only surpassed | |eCal Corp. | by its lack of scalability. -- John Kirch | \=============================================================/