ietf-asrg
[Top] [All Lists]

Re: [Asrg] DCC and IP checksums

2003-03-10 09:30:00
On Mon, Mar 10, 2003 at 11:08:15AM -0500, Sauer, Damon wrote:
I had the code up and working for about a month. I found that doing an MD5
of the hash result of 5 lines in the middle of the message worked
just fine.


There's exactly one reason why this works: 

It is your very private and not publicly known method.

As soon as spammers get aware of this (and they will since you 
just revealed it on this list), your method won't work anymore,
since it is easy to circumvent once the spammer knows how it works. 


Such methods violate one of the most important rules:
Don't do "security by obscurity".

We need to develop methods which can be used by everyone on the world, 
thus need to remain effective when the spammers learned all details
of the method. Your MD5 method fails to do so.


BTW: How do you handle attachments? 

Hadmut




_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg



<Prev in Thread] Current Thread [Next in Thread>