ietf-mailsig
[Top] [All Lists]

Re: DKIM: Canonicalization

2005-07-20 16:15:23


On Wed, 20 Jul 2005, Arvel Hathcock wrote:

Because each signature data needs to be unique based on hash of the message.

I see, so the headers would not provide a sufficient level of uniqueness in themselves.

Not for purposes of dealing with replay attacks. You simply take existing message header for already received email, add your Resent- fields (if at all) and send it back with new content.

Same as with BATV/SES - you take somebody elses BATV/SES signature (harvested from mail list archive perhaps) and use it in your email
and bounces go the listed address.

If you attach time stamp, then you can reasonable reject the message if say
the signature is 5 days old, but it still leaves those 5 days to reuse the
message signature in another message and this would be used by resourceful
attackers.

--
William Leibzon
Elan Networks
william(_at_)elan(_dot_)net


<Prev in Thread] Current Thread [Next in Thread>