Re: CBV

Mark Shewmaker <[email protected]>
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
On Thu, 2004-04-29 at 18:22, Meng Weng Wong wrote:
> On Thu, Apr 29, 2004 at 05:15:07PM -0500, Seth Goodman wrote:
> | If what I've said is true, harvesting an SRS or an SES address
> | makes you equally vulnerable to spam, though through different mechanism.
> | 
> 
> If a spammer can get his hands on the return-path, SRS makes the sender
> vulnerable to spam directed to that return-path, yes.
> 
> But SES makes the sender vulnerable to spoofing --- a spammer could send
> mail *as* that SES address to a bazillion recipients.  You'd have to
> dynamically invalidate the SES address and hope enough people do CBV.

Could the SES address contain a truncated body checksum?  If so, and a 
modifier as discussed earlier today were able to be used by the sender
to specify what sort of checksum is included, the actual SES format
used, what body headers are included, and so forth, the recipients
*could* do body checks.

Even a truncated body checksum could help against that sort of replay
attack.

(Of course, most people here don't like body checks.  Having only small
domains, I wouldn't mind doing checksum verifications on every incoming
email at MTA time, rejecting all mails for which the checksums fail,
which I imagine is not the case for many people here.  However, I wonder
if the dislike of doing body checksum verifications on receipt
translates into a dislike of writing checksums on transmission, since
most domains will of course send much less mail than they receive.)

-- 
Mark Shewmaker
[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.