On Wed, 21 Jul 2010, Gerfried Fuchs wrote:
> I mean that everyone could mail as f...@example.com - and if one is
> out to abuse the system they definitely would choose to use
> f...@example.com as sender address and not b...@domain.com.

Yeah; the point here is that if someone wants to change the
information of f...@example.com, you need to send mail to
f...@example.com asking for confirmation (ideally with some kind of
secret that only you and whoever reads f...@example.com would know; the
message-id would probably be enough.)

[Anyone can change envelope From and header From to be any value.]


Don Armstrong

-- 
The game of science is, in principle, without end. He who decides one
day that scientific statements do not call for any further test, and
that they can be regarded as finally verified, retires from the game.
 -- Sir Karl Popper _The Logic of Scientific Discovery_ ยง11

http://www.donarmstrong.com              http://rzlab.ucr.edu


--
To UNSUBSCRIBE, email to debian-www-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: http://lists.debian.org/20100722034744.ga31...@rzlab.ucr.edu

Reply via email to