Re: SSL Chains

Sabahattin Gucukoglu <[email protected]> Mon, 11 Apr 2011 02:15:56 +0100
Newsgroups gmane.mail.spam.tmda.user
Message-ID <[email protected]>
On 10 Apr 2011, at 19:25, Kevin Goodsell wrote:
> On Sun, Apr 10, 2011 at 10:59 AM, Sabahattin Gucukoglu
> <[email protected]> wrote:
>> On 10 Apr 2011, at 17:43, Kevin Goodsell wrote:
>>> By the way Sabahattin, you should check your TMDA filters. You are
>>> sending confirmation requests for unexpired dated addresses. It's
>>> somewhat bad form to make me confirm my reply to you.
>> 
>> Worse considering the nature of the request.  Even so, testing at my
>> end, and inspection of my incoming log, reveals that you didn't in
>> fact use the dated address.  If you did, yours is another of a long
>> line of complete mysteries, where people *swear* they hit the reply
>> button, but still get a confirmation.
>> 
>> Are you using Thunderbird as your MUA, by chance?  So far, it's the
>> only link in the chain.
>> 
>> And yes, sorry for the inconvenience!
> 
> I'm using gmail's web interface for the list. I see from the headers of
> my reply that it went to *both* addresses, presumably a result of
> clicking "Reply to all" and not paying close enough attention to the
> addresses that were included.

Okay, yes, I've got two copies of the message, one that triggered a confirm request and one that passed straight through.  Then you confirmed on the request about 10 minutes later, and I now have both.  Very annoying for both of us, and I imagine other similar situations.

> I wonder if TMDA's handling of such a multiply-addressed message is
> broken.

I'm not at all sure what TMDA could do.  It can't monitor incoming messages, because it would have to keep state in order to determine whether messages were related, and it wouldn't be able to guarantee a particular order or number without relying on untrusted information given by the sender in the headers.  (Of course, if it did do that, it could also auto-confirm all pending messages of a given envelope sender when it gets just one confirmation request.)  It can't examine outgoing mail either, because it needs information in the header of incoming mail in order to avoid sending mail to the primary address (although it could "Know" how to handle the special case of TMDA-format addresses).

I think the real fix, unfortunately, is to lobby all MUAs to follow RFC 5322 precisely, so that hitting "Reply to all" has the effect of including the Reply-To: in addition to the To: and CC: and (in Bcc field, the Bcc:), and not the From: person in the recipient list, which may in fact not be where the original sender wants his replies to go.  I suspect this is some sort of workaround for the Reply-To: munging mailing lists do, but it's still incorrect behaviour.

Cheers,
Sabahattin

------------------------------------------------------------------------------
Xperia(TM) PLAY
It's a major breakthrough. An authentic gaming
smartphone on the nation's most reliable network.
And it wants your games.
http://p.sf.net/sfu/verizon-sfdev
_______________________________________________
tmda-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/tmda-users