ietf-dkim
[Top] [All Lists]

[ietf-dkim] Issues 1525/1426 (was Re: Restriction to posting by first Author breaks email semantics)

2007-12-21 08:00:46


Eliot Lear wrote:
On the other hand, one could argue that this could be used as a form of
attack - that I Mr. Spammer insert a From line, a Sender line AND a
signature, with my main objective being to get mail in as some OTHER
From (like a bank or Ebay), knowing that a particular UI is only going
to represent (first|last) From.


This presumes that user interface issues are relevant to SSP.

They aren't.

Or, rather, they shouldn't be.

Or rather, if they are, we need to see the empirical basis for making these
choices.

We aren't in a position to make security-related design decisions for user
interfaces.

So that's two ISSUES this design choice factors into.


d/
--

  Dave Crocker
  Brandenburg InternetWorking
  bbiw.net


_______________________________________________
NOTE WELL: This list operates according to http://mipassoc.org/dkim/ietf-list-rules.html

<Prev in Thread] Current Thread [Next in Thread>