[Top] [All Lists]

[ietf-dkim] Re: Responsibility concerns with Designated Signing Domains

2006-08-26 06:01:34
Stephen Farrell wrote:

But yet again, each form of delegation has its issues.

Right, but those forms where the delegator can delegate
without prior and explicit consent of the delegatee are
beyond my no-nonsense limit.  Ideally "explicit" should
allow receivers to verify this.

If an ISP uses a "we sign everything" strategy, and many
customers belong to botnets, then a "bad actor" could
register eboy (with an "O"), delegate eboy-signing to this
ISP unilaterally, and phish using his zombies with accounts
at this ISP.  SSP shouldn't allow this by design.


NOTE WELL: This list operates according to