ietf-mailsig
[Top] [All Lists]

Re: Good as the enemy of OK

2005-01-18 00:01:01

People often get upset when one starts talking about a per-message
callback verification lookup, because this imposes the cost of a
joe-job on the victim site.

Seems to me that's a potential cost of any multi-key system.  Even if
you only have, say, two real keys, a bad guy can send out spam with a
different fake key in each message and you'll get a DNS hit from each
one.

Regards,
John Levine, johnl(_at_)taugh(_dot_)com, Taughannock Networks, Trumansburg NY
http://www.taugh.com




<Prev in Thread] Current Thread [Next in Thread>