[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#207300: tmda: Challenge-response is fundamentally broken



On Thu, Aug 28, 2003 at 12:35:25PM +0100, Karsten M. Self wrote:
> Thanks to all who've commented on this topic.  Interesting reading.

Likewise, Karsten.  That was a very well written rebuttal to a C-R
systems.  You followed up with suggetions on using C-R only as a last
resort in a mail management tool and only after a modest attempt at
detecting spoofed headers was made.  I think you've hit upon the core of
the issue: no one filtering techniqueue is bullet-proof on its own.  The
author of TMDA acknowledges this on the TMDA website.  It really
shouldn't be used as a sledgehammer solution.

-- 
Chad Walstrom <chewie@wookimus.net>           http://www.wookimus.net/
           assert(expired(knowledge)); /* core dump */

Attachment: pgpK_EvOpjALq.pgp
Description: PGP signature


Reply to: