ietf-dkim
[Top] [All Lists]

Re: Fwd: Re: [ietf-dkim] Re: from'less 2822 messages

2008-01-28 10:19:26
Paul Hoffman wrote:
At 11:54 AM +0000 1/28/08, Charles Lindsey wrote:
I think all you need, as Frank has pointed out, is a security
consideration to the effect that

"Verifiers should be aware that Bad Guys may attempt to subvert the
intentions of SSP by submitting messages that are non-compliant with RFC
2822 (for example by using empty From headers, mutiple From headers, Etc
{i.e. list a few examples, but not too may }).

Unfortuntately, good guys (fsvo "good") do this to. I think we need to
add to this by saying that they should be considered SSP unknown, but
not suspicious or whatever the new phrase that replaces suspicious is.

                MIke
_______________________________________________
NOTE WELL: This list operates according to http://mipassoc.org/dkim/ietf-list-rules.html