RE: CBV
"Seth Goodman" <[email protected]>
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
> From: Tony Finch > Sent: Monday, May 10, 2004 4:06 PM > > > On Fri, 7 May 2004, Seth Goodman wrote: > > > > Nobody wants this, but there is a vulnerability to replay > > attacks. Maybe > > we've given it too much airtime, since the vulnerability only > > really exists > > for promiscuous sales type accounts that send mail to anyone who asks. > > IME, using only an unpublished sender address (not signed, not changing, > valid as a recipient address) I'm very well protected from the hundreds > of virus bounces etc. I get each day. Thank you for this observation. This at least provides anecdotal support for the idea that private bounce addresses can be used for typical email and forum participation without being discovered. Though the final gateway MTA is supposed to put MAIL FROM: into the Return-Path: header, mailing lists and other public services that are not broken don't do this. Unless you have the bad luck to send a message to a broken service or someone gives a spam complaint to a spammer without obfuscating your address, your bounce address will likely remain unknown to spammers. How long have you been using the same unpublished bounce address without having it harvested? -- Seth Goodman