gabriel rosenkoetter on Thu, 6 Sep 2001 14:50:13 +0200


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

SMTP cruft (was: Re: [PLUG] Does restricting partial words weaken passwords?)


On Wed, Sep 05, 2001 at 04:02:14PM -0400, Dave Turner wrote:
> You are looking from a system security standpoint at what I took as a
> mathematical question :)

No cryptography question is only a mathematical question.

> You can do that by checking From rather than Sender.

No, you can't, because a sender can easily spoof a From: address. If
what you're concerned about is that only people who actually do have
permission to post to the mailing list do, you have to rely on the
envelope From address or the Delivered-To headers. Go read the
relevant RFCs, to which you were already kindly referred.

-- 
       ~ g r @ eclipsed.net

Attachment: pgpgREI1Q027t.pgp
Description: PGP signature