Re: Reposted Comments on SCMP ( by Graham Klyne )

Jason Eaton <[email protected]> Wed, 02 Jun 1999 16:19:32 -0700
Newsgroups gmane.ietf.scmp
Message-ID <[email protected]>
At 03:48 PM 6/1/99, John Stracke wrote:
>bartley.o'[email protected] wrote:
>
>> I suggest that ALL the SCMP header fields should be encapsulated within an
>> encrypted MIME body part with nothing more than
>> the minimum MIME headers required for delivery appearing outside the message
>> body. In particular, no message-id and no from.
>
>If it's going by email, it had better have a From:; otherwise email failures 
>won't
>be reported--plus it's liable to be treated as spam.  Leaving off the 
>Message-Id:
>has similar potentially dire effects on the mail infrastructure, for which 
>reason
>most MTAs will add a Message-Id: when they forward a message that doesn't have
>one.
>
>If it's going by HTTP, these fields aren't necessary.

I agree. But shouldn't the draft accommodate the lowest common dominator?

>
>> The from
>> is only really needed to provide a human readable
>> identity for mail applications.)
>
>Not so--it's also needed to make sure mail gets delivered smoothly.
>
>> An easily readable name gives instant knowledge to an attacker of the 
>existence
>> of a relationship between the sender and receiver.
>
>Yeah, but so does simple traffic monitoring.

This information is available elsewhere. I don't think there is a security
issue here.


Jason Eaton			CyberSource Corporation
Phone 408.260.6044		Security Engineering Manager
[email protected]	http://www.cybersource.com