Re: Security

New Message Reply About this list Date view Thread view Subject view Author view

From: Charles Lindsey (chl@clw.cs.man.ac.uk)
Date: Tue Apr 10 2001 - 05:02:42 CDT


In <20010409085007.A76120@demon.net> "Clive D.W. Feather" <clive@demon.net> writes:
>Oops. In fact, better wording would be:

> The mailbox in the From-content SHOULD be either a valid address,
> belonging to the poster(s) of the article (or person or agent on
> whose behalf the post is being sent - see the Sender header, 6.2),
> or else a syntactically correct string which ends in
> ".invalid" [RFC 2606].

Alternative text noted.

>> However, my main objection is that it is a considerable retreat from our
>> previous stance which was, AIUI:
>>
>> You SHOULD NOT munge.

>I thought we'd already retreated to:

> You SHOULD NOT munge; saying "I'm not telling you" is not munging.

>> Now your wording is weaker than that, insofar as it seems to make having a
>> valid address OR having a munged.invalid address are equally acceptable.
>> Is that what we want to say?

>I believe so, yes.

OK, but I hear no clamour from anyone else since I posted my response to
your earlier message.

>However, I don't consider ".invalid" to be munging; that implies that I'm
>hiding my true address in the munged string. We should be encouraging, or
>at least allowing, things like:

I think we regard any attempt to make the From address not the
originator's true identity as a Bad Thing, even though it might be
conceded to be a regrettable necessity in present circumstances. DRUMS
makes no allowance for the From to be anyone other than the originator.

Of course, I exclude anyone who uses proper anonymizing services. In that
case the originator is, for our purposes, the anonymizing service (and
they have to bear some responsibility to the net for what they do).

-- 
Charles H. Lindsey ---------At Home, doing my own thing------------------------
Tel: +44 161 436 6131 Fax: +44 161 436 6133   Web: http://www.cs.man.ac.uk/~chl
Email: chl@clw.cs.man.ac.uk      Snail: 5 Clerewood Ave, CHEADLE, SK8 3JU, U.K.
PGP: 2C15F1A9      Fingerprint: 73 6D C2 51 93 A0 01 E7 65 E8 64 7E 14 A4 AB A5


New Message Reply About this list Date view Thread view Subject view Author view


This archive was generated by hypermail 2b29.