4 Aug 1998 22:31
Re: signing headers
Bill Davidsen <davidsen <at> prodigy.com>
1998-08-04 20:31:41 GMT
1998-08-04 20:31:41 GMT
Brad Templeton <brad <at> templetons.com> wrote: > On Mon, Aug 03, 1998 at 02:18:26PM -0400, Bill Davidsen wrote: > > Brad Templeton <brad <at> templetons.com> wrote: > > We add something like that, because we find it easier than trying to > > look up the ID from the posting host. I'm not sure it's a replacement > > for the posting host and *verified* time, since we sometimes have to be > > able to generate more detailed inforation than just what id was used. > > But how far do you go? You want to put the time in there too? With posting-host and a valid time we can use radius logs to verify a connect, and generate a called phone number from that information. >From that a phone company can generate a calling number, even if it's on a POP without caller-id. And people with subpoenas have been known to ask for information like that. > Though with 95% of ISP postings, the IP address of the poster reveals > nothing, simply that they were at one of the ISP's dialups. See above. > > So in addition to "From:" the spammers will forge "Path:" too? A whole > > new header which doesn't have a history of being passed on if present is > > almost certainly going to be more useful. > > The spammer can't forge the path. The injector puts the identity information, > and the injection site-id, into the path.(Continue reading)
>
> We are not saying "do cancel locks and postpone article signing". We are
> saying that it's time to postpone BOTH in the interest of getting some
> progress on the base RFC.
>
> We do NOT have rough consensus on EITHER SCHEME.
>
> We do NOT have working code for EITHER SCHEME.
I think I can side with Henry in sake of unity in the faction.
RSS Feed