Re: CBV
Tony Finch <[email protected]>
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 30 Apr 2004, David Woodhouse wrote: > > Yes, there's a replay window. It's short. It has to be about a week, which is plenty long enough for viruses. Although MDAs that know about SSAs will unsign the address before creating the return-path header, there will for a long time be many MDAs out there that don't know about SSAs and therefore leak addresses in a way that allows them to be found by viruses. Thus MXs should have a mechanism for automatically revoking SSAs that get used too much. "Too much" is hard to define: it depends on the number of recipients of the original message (perhaps this should also be encoded in the SSA), the maximum Received: path (there may be a CBV for each hop), and the number of possible DSNs (more than one for each recipient in the case of quota delays, vacation messages, etc.). Unfortunately this requires per-SSA state to be maintained on the MX, which we have been trying to avoid through use of crypto. It's particularly unpleasant for clustered MXs. -- Tony Finch <[email protected]> http://dotat.at/