ietf-mailsig
[Top] [All Lists]

Re: MASS Security Review document

2005-02-15 02:58:37

sender -> isp -> exploder -> millions of people

The ISP no longer has any control over who receives a message after it has
been relayed to its recipients, unless there is some kind of call-back.

Ah, the mailing list scenario.  This still strikes me as a solution in
search of a problem, since this exact scenario has been possible for 20
years and I can't ever remember it being an abuse problem.

We're anticipating that signatures will make new forms of attack more
attractive.

As I said in another message, revocation would be an ideal tool for
spammers to use to pretend that they weren't responsible for their spam.

Revocation allows another attack suggested by Roger Moser, in which one
recipient of a message which was sent to many people spams the
verification server in order to make it believe that abuse is occuring,
so that it revokes the message and prevents others from receiving it.

Tony.
-- 
f.a.n.finch  <dot(_at_)dotat(_dot_)at>  http://dotat.at/
HEBRIDES: VARIABLE 3 OR 4 BECOMING SOUTH OR SOUTHWEST 5 TO 7, PERHAPS GALE 8
LATER. OCCASIONAL RAIN. MODERATE OR GOOD, OCCASIONALLY POOR.


<Prev in Thread] Current Thread [Next in Thread>