Re: DMARC?
Michael Deutschmann <[email protected]> Mon, 20 Aug 2012 20:08:53 -0700 (PDT)
| Newsgroups | gmane.mail.spam.spf.discuss |
|---|---|
| Message-ID | <%[email protected]> |
On Mon, 20 Aug 2012, Ian Eiloart wrote: > On 11 Aug 2012, at 20:54, Michael Deutschmann > <[email protected]> wrote: > > a phisher can freely lie in > > *the address shown to an unsuspicious end user* > > Actually, there's no such thing for many recipients. Outlook 2011 for > OSX (and I think 2010 and earlier for PC), iOS Mail, Yahoo webmail and > Hotmail webmail don't display sender email addresses by default. For those > webmail clients, a mouseover can reveal the From: header address, but for > Outlook and iOS Mail, it's really hard to find the address even when you > know how. So they only show the display name. Well, then the phishers have free reign -- they can evade all technical anti-forgery measures by simply not forging. They just have to use their real domain in all headers including From: Only a display-name anti-forgery protocol can help, and that is problematic. To their credit, DMARC's specification draft at least discusses it, but only to point out they have no idea how to plug the hole, and hope someone else will. Anyhow, it underscores my point that ADSP/DMARC's obsession with protecting only the most visible header (From:) is insane. SPF's forwarding problem is annoying, but only indirectly. I've been publishing -all since 2004 and only once encountered a domain bouncing my mails and blaming SPF. It only hurts because my false negative rate is boosted by cowards who use ?all unnecessarily. But the ADSP/DMARC mailing list problem, which could be trivially avoided by joining SPF in protecting the bounce address instead, is fatal. ---- Michael Deutschmann <[email protected]>