spf-discuss
[Top] [All Lists]

RE: RE: Why XML

2004-06-22 11:27:33
[terry(_at_)ashtonwoodshomes(_dot_)com]
Interesting arguments on extensibility.  All valid.  Also all 
valid for SPFv1 due to the fact that SPFv1 is extensible.

I think the whole "exists" thing in SPFv1 is indeed powerful, but a bit
of a hack. Requiring a custom DNS resolver for extensibility seems
dangerous to me. 

Custom resolvers, of which there could be thousands, will also be prone
to security flaws, as are most small, private software projects. Look
how long it took the ISC to straigthen out BIND, for heaven's sake. BIND
is open source and wasn't written by a junior programmer working for
some bureaucratic organization, yet it has had a lot of serious security
flaws exposed. 

Imagine how insecure the custom SPF resolver for the U.S. Department of
Interior will be if SPFv1 catches on!

Regards,
        Ryan


<Prev in Thread] Current Thread [Next in Thread>