funsec mailing list archives

Re: Public Policy and Consumer ISP Hygiene (was Comcastpop-ups)


From: "Larry Seltzer" <larry () larryseltzer com>
Date: Sat, 17 Oct 2009 09:31:08 -0400

With a fully authenticated protocol we could limit the valid source  
addresses of the spam to the one associated with the compromised user.

That reduces it to a trust decision, right? We've had this option for
years with DKIM, at least at the domain level, and it doesn't seem to
have changed things much. Would authenticating down to the sender level
really improve things? (I hate it when I talk defeatist, but that's how
I feel about this issue.)

Larry Seltzer
Contributing Editor, PC Magazine
larry_seltzer () ziffdavis com 
http://blogs.pcmag.com/securitywatch/

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: