ietf-mxcomp
[Top] [All Lists]

Re: Forged Sender (Resent-From) attacks

2004-08-18 19:00:08


On Aug 18, 2004, at 9:03 PM, Daryl Odnert wrote:

Nate Leon wrote:
> I expect it will take years before all MUAs are updated (and widely
> deployed) to display the PRA, which I do not think is an acceptable
> timeframe to put a serious dent into phishing attacks.

 But HTTP over
SSL wasn't enough to secure the Web.  The lock icon in the browsers
were needed too so users could tell the difference between what is
trustworthy and what is not.

And the lock on the browser came after the SSL standard.
SenderID is the first step, and a necessary step, not an instant cure for all that ails email.

Margaret.