Re: [ietf-822] one can re-sign without a permission to re-sign header

Paul Smith <paul@pscs.co.uk> Mon, 05 May 2014 08:51 UTC

Return-Path: <paul@pscs.co.uk>
X-Original-To: ietf-822@ietfa.amsl.com
Delivered-To: ietf-822@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 41F851A0043 for <ietf-822@ietfa.amsl.com>; Mon, 5 May 2014 01:51:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.252
X-Spam-Level:
X-Spam-Status: No, score=-3.252 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oXwFjYV07jZ7 for <ietf-822@ietfa.amsl.com>; Mon, 5 May 2014 01:51:01 -0700 (PDT)
Received: from mail.pscs.co.uk (mail.pscs.co.uk [188.65.177.237]) by ietfa.amsl.com (Postfix) with ESMTP id C640A1A0157 for <ietf-822@ietf.org>; Mon, 5 May 2014 01:50:59 -0700 (PDT)
Authentication-Results: mail.pscs.co.uk; spf=none; auth=pass (cram-md5) smtp.auth=paul
Received: from lmail.pscs.co.uk ([82.68.5.206]) by mail.pscs.co.uk ([188.65.177.237] running VPOP3) with ESMTP for <ietf-822@ietf.org>; Mon, 5 May 2014 09:52:41 +0100
Authentication-Results: lmail.pscs.co.uk; spf=none; auth=pass (cram-md5) smtp.auth=paul
Received: from [192.168.57.132] ([217.155.61.158]) by lmail.pscs.co.uk ([192.168.66.70] running VPOP3) with ESMTP for <ietf-822@ietf.org>; Mon, 5 May 2014 09:50:51 +0100
Message-ID: <536750E7.3030009@pscs.co.uk>
Date: Mon, 05 May 2014 09:50:47 +0100
From: Paul Smith <paul@pscs.co.uk>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.5.0
MIME-Version: 1.0
To: ietf-822@ietf.org
References: <20140501195449.68225.qmail@joyce.lan> <5363ACA6.1010203@qti.qualcomm.com> <alpine.BSF.2.00.1405021036010.79573@joyce.lan>
In-Reply-To: <alpine.BSF.2.00.1405021036010.79573@joyce.lan>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Authenticated-Sender: paul
X-Server: VPOP3 Enterprise V6.8 - Registered
X-Organisation: Paul Smith Computer Services
X-Authenticated-Sender: paul
Archived-At: http://mailarchive.ietf.org/arch/msg/ietf-822/kl-yjM54obbZTr0rcUA3EbDTVwE
Subject: Re: [ietf-822] one can re-sign without a permission to re-sign header
X-BeenThere: ietf-822@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Discussion of issues related to Internet Message Format \[RFC 822, RFC 2822, RFC 5322\]" <ietf-822.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf-822>, <mailto:ietf-822-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf-822/>
List-Post: <mailto:ietf-822@ietf.org>
List-Help: <mailto:ietf-822-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf-822>, <mailto:ietf-822-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 May 2014 08:51:03 -0000

On 02/05/2014 15:42, John R Levine wrote:
>> I don't see any replay protection in here at all. Nothing that says 
>> to keep the signature expiration relatively short, and nothing which 
>> a mailing list recipient could not subsequently use to send spam. The 
>> first issue just needs a mention. It's the second issue that needs to 
>> be addressed IMO:
>
> Yeah, that occurred to me about five minutes after I posted it. Here's 
> a tweaked version where the mf tag is now mf=list.domain, with 
> handwaving about how a may-forward signature doesn't count unless 
> there's also a signature from the list domain.  Given lengthy 
> discussions about how little abuse comes from real mailing lists, 
> that'd probably be adequate.
>
> http://datatracker.ietf.org/doc/draft-levine-may-forward/
Could this be 'extended' to include message-ids in the MF signature?

That would provide some replay protection, especially if the forwarder 
checks for duplicate message-ids (the recipient could also check for 
dupes). Without it, I could see one of your messages on a list, then 
send messages to everyone on the list, pretending to be you.



-


Paul Smith Computer Services
Tel: 01484 855800
Vat No: GB 685 6987 53