Re: CBV
Mark Shewmaker <[email protected]>
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 2004-04-29 at 18:22, Meng Weng Wong wrote: > On Thu, Apr 29, 2004 at 05:15:07PM -0500, Seth Goodman wrote: > | If what I've said is true, harvesting an SRS or an SES address > | makes you equally vulnerable to spam, though through different mechanism. > | > > If a spammer can get his hands on the return-path, SRS makes the sender > vulnerable to spam directed to that return-path, yes. > > But SES makes the sender vulnerable to spoofing --- a spammer could send > mail *as* that SES address to a bazillion recipients. You'd have to > dynamically invalidate the SES address and hope enough people do CBV. Could the SES address contain a truncated body checksum? If so, and a modifier as discussed earlier today were able to be used by the sender to specify what sort of checksum is included, the actual SES format used, what body headers are included, and so forth, the recipients *could* do body checks. Even a truncated body checksum could help against that sort of replay attack. (Of course, most people here don't like body checks. Having only small domains, I wouldn't mind doing checksum verifications on every incoming email at MTA time, rejecting all mails for which the checksums fail, which I imagine is not the case for many people here. However, I wonder if the dislike of doing body checksum verifications on receipt translates into a dislike of writing checksums on transmission, since most domains will of course send much less mail than they receive.) -- Mark Shewmaker [email protected]