On 7 Sep 2004, at 17:38, Yakov Shafranovich wrote:
I think we are going in circles. Validating the bounce address only
prevents false bounces but allows phishing, validating "Sender" does
not stop phishing but allows bounces plus does not take into account
forwarding, validating the "from" headers stops phishing but allows
bounces. Which one of these do we really want?
Validating the "from" headers in no way stops phishing.
It may give us some comfort to think that in some future we might be
able to whitelist "from" headers, with some certainty that they aren't
forged, but that's all it does. A whitelist (or reputation list) does
not stop phishing.
Matt.
______________________________________________________________________
This email has been scanned by the MessageLabs Email Security System.
For more information please visit http://www.messagelabs.com/email
______________________________________________________________________