ietf-mailsig
[Top] [All Lists]

Re: epostage, hashcash, callbacks

2005-02-15 17:56:00

When the HELO is within the Signature-domain, there should be no need to
check for account revocation

Now I don't understand your proposal at all.  I was under the impression
that scenario is a that a domain has a lot of users, some of whom may
misbehave, and revocation would be a way to disclaim naughty mail
retroactively.  I see no reason why the naughty users wouldn't be using
the same channel as everyone else.

Only for cases where the HELO and Signature are not coincident

Why do you assume a message from, say, a Comcast user wouldn't be subject
to hostile replay by another Comcast user?

The more I hear about this, the more I see a problem masquerading as a
solution in search of a problem.

Regards,
John Levine, johnl(_at_)iecc(_dot_)com, Primary Perpetrator of "The Internet 
for Dummies",
Information Superhighwayman wanna-be, http://iecc.com/johnl, Mayor
"I dropped the toothpaste", said Tom, crestfallenly.


<Prev in Thread] Current Thread [Next in Thread>