[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#207300: tmda: Challenge-response is fundamentally broken



on Thu, Aug 28, 2003 at 08:56:36AM +0200, Rico -mc- Gloeckner (mc@ukeer.de) wrote:
> On Wed, Aug 27, 2003 at 05:40:46PM -0700, Don Armstrong wrote:
> > If possible, perhaps you could consider whitelisting common debian.org
> > address by default? [Things like *@debian.org, *@lists.debian.org,
> > *@bugs.debian.org, etc.]
> 
> And would probably defeat the purpose since spammers would know which
> adresses they have to spoof into the From: Header.
> 
> Furthermore, if spammers got that, it might happen that they use
> debian.org adresses as sensible default for From: Adresses which will
> raise the amount of Bounces to debian.org. That sounds like a great way
> for the Project to shoot itself into the feet.

That would be an example of #0.  With a twist.

Peace.

-- 
Karsten M. Self <kmself@ix.netcom.com>        http://kmself.home.netcom.com/
 What Part of "Gestalt" don't you understand?
   GNU/Linux web browsing mini review:  Galeon.  Kicks ass.
     http://galeon.sourceforge.org/

Attachment: pgp_3MnUogQWP.pgp
Description: PGP signature


Reply to: