ietf-mailsig
[Top] [All Lists]

RE: mailing list software, was What does the mailsig mechanismmean?

2004-11-01 16:57:49

 
On Mon, 2004-11-01 at 15:22 -0500, John Dennis wrote:
On Mon, 2004-11-01 at 14:42, Michael Thomas wrote:
Any breakdown on the different ways that they are mangled?
The things that I know about are:

1) white space insertion
2) adding trailers (generally)
3) adding trailers which are "mime friendly"
4) Mbox mode bogosities (eg ">From ")
5) plain text <--> mime conversion
6) attachment stripping

Of these I've only really encountered #2 and #3 in any great 
quantities.
I'd be happy enough with a solution with works with these 
alone, although I see no harm in handling the others if it's 
easy enough to do.

If a mailing list adds a trailer, it needs to resign the message.  It's
now effectively the originator having added new content.  If this type
of modification is ignored, malicous trailers can be added to the
messages that could include: ads, solicitations, pleas for help
transfering money, etc.

Whitespace and simple transformations can be worked around and a
signature can be preserved.  Trailers can not be supported without
resigning.

Paul


<Prev in Thread] Current Thread [Next in Thread>
  • RE: mailing list software, was What does the mailsig mechanismmean?, Paul Lambert <=