ietf-822
[Top] [All Lists]

Re: Understanding response protocols

2004-09-17 17:01:51

Keith Moore wrote:

But there's another wrinkle in that the ability to redirect replies is
arguably a security risk.[*]  Say an attacker forges a message from 
someone's boss that tells its recipient to do something costly and
irreversible.[...]

Alerts are little more than a band-aid -- the real issue is the
need for authentication, avoiding the forgery in the first place.