ietf-mxcomp
[Top] [All Lists]

Re: So here it is one year later...

2005-02-01 00:58:33

On Mon, 2005-01-31 at 18:23 -0800, Douglas Otis wrote:
I should also note that BATV does not require any outside service to
address abusive bounce messages.  Although SES is similar, it
introduces some security concerns by way of its syntax.

The syntax of each can be treated as if it's entirely opaque, and SES
without any form of validation at the _receiving_ side is then
indistinguishable from BATV in all but cosmetics, surely?

What are the security concerns of which you speak?

-- 
dwmw2