ietf-mailsig
[Top] [All Lists]

Re: Most recent sender.

2005-01-14 12:20:22



--On Friday, January 14, 2005 5:17 PM +0000 David Woodhouse <dwmw2(_at_)infradead(_dot_)org> wrote:


OK, let us assume that we've ditched the idea of having a signature on
the From: header which can survive mailing lists, and we're only going
to attempt to authenticate the 'most recent sender'.

I'm suggesting that each hop tell the next hop "the most recent sender", and that we carry that information forward.

In fact, if a hop changes the value of the sender, perhaps as a result of list expansion, it just has to be honest about having done it. This change could be indicated as part of what it signs and passes on.

We could take this a step further and suggest that when a message is first submitted, if the first hop finds the 2822 From does not match the 2821 From, then it too indicates this change.

I don't think we should concern ourselves with why the change occurred. What's important is stating that it was knowingly changed. Let the recipient sort it out later. This would be the value that a reputation system could add, later.

Jim


<Prev in Thread] Current Thread [Next in Thread>