ietf-mxcomp
[Top] [All Lists]

Re: Security issue: Minority installed base of compatible MUAs?

2004-08-09 08:43:21

On Sat, 7 Aug 2004, Chris Haynes wrote:

The draft states that "in order to avoid this attack, MUAs will need to start
displaying at least the header that was verified".

My concern is the need for new MUA purchases.

Why can't the server-side check modify the message to display the results
in an MUA-compatible way similar to the way that SpamAssassin modifies
bodies and (optionally) headers today?

-Rand