[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#207300: tmda: Challenge-response is fundamentally broken



On Fri, Aug 29, 2003 at 03:48:13PM +1000, Craig Sanders wrote:
> the point that you keep on missing is that TMDA and similar programs send
> "confirmation" emails to innocent third-parties who did *NOT* send an email.

Really?

> TMDA and all C-R systems are broken-by-design, just as many stupid end-user
> "autoresponders" and AV-scanners that send notifications back to the forged
> sender address are broken-by-design.

Well, since we're pointing fingers, it's really SMTP that's broken by 
design, and all anti-spam programs (including C-R systems) are merely 
stopgap measures that try to make up for SMTP's shortcomings.

--Adam

-- 
Adam McKenna  <adam@debian.org>  <adam@flounder.net>



Reply to: