Re: CBV
wayne <[email protected]>
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
In <[email protected]> "Seth Goodman" <[email protected]> writes: > > The real question here is how easy is it to harvest a signed envelope > address, regardless of the signing protocol? When I originally brought this > up as a possible exploit against SRS to Shevek, his answer was to not send > email to spammers and then they wouldn't have your signed return-path. > Though I groused about it at the time, that really was a pretty good answer. > If you don't send email to spammers, how _would_ someone go about harvesting > signed envelope addresses? When SRS is used by forwarders, they have quite a bit of control over who they send email to. If you uses SES and send email to anyone who requests sales info, or whatever, signed envelope address harvesting is much more of a serious concern. -wayne