| Newsgroups |
gmane.mail.spam.srs.general |
| Message-ID |
<[email protected]> |
On Thu, 6 May 2004, Seth Goodman wrote:
[RANDOM SNIPPAGE]
> That takes care of mailing lists, but any forwarding system that appends or
> prepends anything to the body would similarly break any check of the message
> body. The simple answer to that is, "don't do that", but changing any
> existing practice is hard. That was a lot of the motivation behind SES in
> the first place, that is, not breaking any existing practice. Fortunately,
> there is an easy fix for forwarding systems that feel the need to prepend
> lines like "Virus-checked by XYZ Company's Fabulous AV Product": put that
> very important information in an X-header, where it belongs. I don't think
> that we have to accept the practice of forwarding machines adding anything
> to message bodies. As long as it is a minority of systems, I think that
> having their outgoing mail rejected will motivate them to find another
> solution.
>
> > Except for being prepared ahead of time for any future SMTP extension
> > that allows body headers to be sent before the rest of DATA, I don't see
> > any advantage in limiting the checksum to body headers.
>
> Now that you've found a solution to the mailing list problem, I completely
> agree with you. We should return the inner hash to covering the message
> body so as to more fully prevent replay attacks.
Surely, at this point, a simpler and easier solution would be only to
accept PGP signed messages from a verifiable source, and possibly include
a set of permissible source addresses in the PKI infrastructure with each
public key.
That's what this starts to sound like.
S.
--
Shevek http://www.anarres.org/
I am the Borg. http://www.gothnicity.org/