ietf-mailsig
[Top] [All Lists]

Re: Rambings on RFC2822 signatures.

2004-09-17 12:18:12


--- David Woodhouse <dwmw2(_at_)infradead(_dot_)org> wrote:

Second, it should be resilient to the common mangling which messages
may
encounter in transit -- in particular the addition of text to the end
of
a mail by mailing lists, by idiotic disclaimers and by
self-advertising
virus checkers.

We should be careful in this requirement.  Poking holes in
authentication means more chances for abusers.  If we were to allow any
content at the end for instance, spammers may be able to figure out how
to replay legit messages and append their phishing information to the
end.

miles


<Prev in Thread] Current Thread [Next in Thread>