Re: homework, not an experiment, draft-crocker-email-deliveredto
Sam Varshavchik <[email protected]> Tue, 03 Aug 2021 08:25:11 -0400
| Newsgroups | gmane.ietf.smtp |
|---|---|
| Message-ID | <[email protected]> |
Viktor Dukhovni writes: > > On 2 Aug 2021, at 9:34 pm, John Levine <[email protected]> wrote: > > > >> In particular, it is not unreasonable for the LDA to record an encoded > >> HMAC of the recipient address in the localpart, thereby making more > >> difficult abuse of "Delivered-To:" to elicit bounces of the message to > >> the purported envelope sender (because it is then harder for the > >> attacker to predict the magic "Delivered-To:" value). > > > > Huh, interesting point. Do you know of an LDAs that actually do that? If > so we should > > add it to the description of the existing practice if we do a draft. > > > > When I look at Postfix and qmail, they both appear to use the plaintext > > locally rewritten recipient address, which may not make much sense to > > software other than the MTA. > > Some abuse of Delivered-To to trigger bounces has been reported now and > then, and the idea of obfuscated Delivered-To: had been discussed, but > has not yet been implemented. The freedom to do that some day remains. > > https://mailing.postfix.users.narkive.com/RMb6WBxb/delivered-to-message- > header I don't see anything intrinsically wrong with this, by itself. It's better than nothing. But if the actual goal is to prevent proxy DDOSes, this should be addressed directly: no bounce should be sent via SMTP for mail that was accepted via SMTP. _______________________________________________ ietf-smtp mailing list [email protected] https://www.ietf.org/mailman/listinfo/ietf-smtp
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEMWrVnbBKLOeG9ifkazpiviedvyUFAmEJNacACgkQazpivied vyX6mA/+LN6w3GDsIDZRa/BUrLxMoB6HH8IshyIM1BdX9RWsrlxNQMLYA9aAFn/R /qlWzp4bFJKFW14groWpYWJve6DO8dBChf9U5pvGgbkUrwZZkrVF+9jGlA68dEse Dh1OZyM8ojgS5psfZTqVTIe/4LVJHZkljiWkG9IOmIqbkBxuGLc5U/l+hQsUDXaW fMgQr+8bb9A/ndoRWLFntYteFmkz6GiP/yVlYEHyny+ARmKFigWQy4psWEdu3wbx AlIDcS9gmmA7gULh1pHj/600jl9BZBVIi7GVAOr7EvEauq+oJBaySPF+zrlTBAD2 W7pBEvA0IVJ0I12kLEozOgEmNT2hu01CazgKhxu7l4wb+Wj459z7K38ckgiCFIgf BohSAv6jVSGnuBLKZCw1E7uWp+9MyKay4rW8mwPsSg0ik9bZB/WCbEDIhHYEBe5a jkOvRPSi3oohEmBR7L1CGGWZMMr9978iw8iuu2a4KtJXhAELW5RgyYqPkZBtlrbv 7Xt+ahzllqE2sOgXtqK5I0KCWZr/U/QdrWi+4YJB3xt4w0zHPl3HBoLCxO9148sT ISrVvu2v/UKw1ZNjLwWKCuHnhVIBs9gzdSYViQKkGTv28nWd6XwoeWmqrPctlAIz SmVM57+k77P8aAc5ip+WKh/RW9aXx3ALaloe6o5rxeZ4QhLkqc0= =/jS1 -----END PGP SIGNATURE-----